CVE-2016-3096 -- ansibleID: oval:org.secpod.oval:def:1900568 | Date: (C)2019-02-27 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
The create_script function in the lxc_container module in Ansible before1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on /opt/.lxc-attach-script, the archived container in the archive_path directory, or the lxc-attach-script.log or lxc-attach-script.errfiles in the temporary directory.
Platform: |
Ubuntu 16.04 |
Ubuntu 14.04 |