CVE-2017-10600 affects Canonical's ubuntu-image tool, specifically versions prior to 2017-07-07. This vulnerability allows a non-root user creating an image to embed their user ID (UID) into the image's files. Upon booting the image, a local attacker with the same UID as the image creator gains unintended access to sensitive cloud-init and snapd directories. The vulnerability is rated Medium with a CVSS score of 5.9, indicating a local attack vector with low complexity and potential for low impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, and no public exploit code is available through Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:canonical:ubuntu-image:1.0:2017-07-06:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.