| Reported on: | 20131002 |
|---|---|
| Published on: | 20131021 |
| Fixed on: | 20131021 |
| Reported by: | Sebastian Krahmer |
|---|---|
| Patched by: | Daniel Berrange |
The virt-login-shell binary is a setuid program to connect to LXC containers. It fails to sanitize its environment in a number of places allowing it to be used to elevate privileges of the invoking user by overwriting files
An unprivileged user can overwrite arbitrary files on the host leading to an elevation of privileges.
Remove the setuid bit from the virt-login-shell binary