Candidate: CVE-2016-3096 PublicDate: 2016-06-03 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3096 https://bugzilla.redhat.com/show_bug.cgi?id=1322925 https://sources.debian.net/src/ansible/2.0.1.0-1/lib/ansible/modules/extras/cloud/lxc/lxc_container.py/?hl=523#L523 Description: The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=819676 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_ansible: upstream: https://github.com/ansible/ansible-modules-extras/commit/7c3999a92a1cd856ff9bc8913a93ff1aee8bffc3 upstream_ansible: released (2.0.1.0-2) precise_ansible: DNE precise/esm_ansible: DNE trusty_ansible: ignored (out of standard support) trusty/esm_ansible: not-affected (code not present) vivid/stable-phone-overlay_ansible: DNE vivid/ubuntu-core_ansible: DNE wily_ansible: ignored (reached end-of-life) xenial_ansible: released (2.0.0.2-2ubuntu1.3) yakkety_ansible: not-affected (2.0.2.0-1) zesty_ansible: not-affected (2.0.2.0-1) artful_ansible: not-affected (2.0.2.0-1) bionic_ansible: not-affected (2.0.2.0-1) cosmic_ansible: not-affected (2.0.2.0-1) disco_ansible: not-affected (2.0.2.0-1) devel_ansible: not-affected (2.0.2.0-1)