← Back

CVE-2015-6927

nvd nist
Published: Sep 28, 2015Modified: May 6, 2026

JSON object

Loading...
3.6
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:P
Exploitability: 3.9 / Impact: 4.9
Source: NVD

Description

vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containers, as demonstrated by a symlink attack on the ploop container root.hdd file and then access a control panel.

Affected (1)

Products: Openvz: Vzctl
1 product
Vzctl
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.9.3

References (8)

Timeline

No history available yet.