The createscript function in the lxccontainer module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:redhat:ansible:2.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "2.0"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "22"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "23"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "24"
}
],
"source": "CPE_FIELD"
}
]
}{
"cpe": [
"cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:ansible:2.0.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.6"
},
{
"last_affected": "2.0.1"
}
],
"source": "CPE_FIELD"
}