Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in LXC (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in LXC (Aktualisierung)
ID: USN-2753-2
Distribution: Ubuntu
Plattformen: Ubuntu 14.04 LTS
Datum: Mi, 30. September 2015, 23:37
Referenzen: Keine Angabe
Applikationen: LXC
Update von: Preisgabe von Informationen in LXC

Originalnachricht


--===============0224780740678123301==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="SUOF0GtieIMvvwua"
Content-Disposition: inline


--SUOF0GtieIMvvwua
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-2753-2
September 30, 2015

lxc regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

USN-2753-1 introduced a regression in LXC.

Software Description:
- lxc: Linux Containers userspace tools

Details:

USN-2753-1 fixed a vulnerability in LXC. The update caused a regression that
prevented some containers from starting. This regression only affected
containers that had an absolute path specified as a bind mount target in their
configuration file. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Roman Fiedler discovered a directory traversal flaw in lxc-start. A local
attacker with access to an LXC container could exploit this flaw to run
programs inside the container that are not confined by AppArmor or expose
unintended files in the host to the container.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
lxc 1.0.7-0ubuntu0.6

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2753-2
http://www.ubuntu.com/usn/usn-2753-1
https://launchpad.net/bugs/1501310

Package Information:
https://launchpad.net/ubuntu/+source/lxc/1.0.7-0ubuntu0.6


--SUOF0GtieIMvvwua
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJWDCi1AAoJENaSAD2qAscKLQAQALN69IV83y5MmzvDlYWOjBSM
SlhyTJjzQNtwAFM+1nNr1yEwY4chThbC2jeQjICBtw2IU2FiGqSfmZX5gI4Re8eo
XoU1qyxflv9q2SRdiv/eh6U+LLwG7gJNjtHPhm55MDNVfrCDKvuIk4YqQcrWqjt7
u0eS0vq+5HTRVYjVOXb6U/XGD9J2QQqlh841rrUjsaDmmmpZg+W8FbE2WMupeha2
UbrJG11AKadCUSX9LtrU7PI930D8yov/gCIch1jjBlKSbXQ316vgt/vS5vaRTTfH
HkcxdaAgfIH7DbDoZ8T6mndiualxk3oZ55dvGu/J+cTYrdJR8W2NWfsEM0kTREqs
2aXCpwLkoEYbV4Fqp59spXrSJcQSYRAo799StbiFQqHxd1OfvjsqZAJxSafxj+su
sxZ1cBzf5w4ASyypcbZE3pI3fnRJI5l49KbC85E/Ds34821tdYXmHvZt+7s4PSmt
8YUiMCujBqbscioh5bfBYZlXzwBOGVRfvM7Sk9l23nOnc8AjDD19dZZ6AmiMB400
3O4H7vOVi+mChOlwex9DJISdY8QvinpwL/DfNVkRTcvgabZ5Ks6rnZKITwJO0cm9
A5zs0ObLsOYk6PCjVK+oIN3Ru3dzWEzgjA1OcKIVaZSwcmlNcPd/aeRU8X7QMqX1
dxS5dMbuQB4BaClDKUer
=DWSJ
-----END PGP SIGNATURE-----

--SUOF0GtieIMvvwua--


--===============0224780740678123301==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============0224780740678123301==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung