Login
Newsletter
Werbung

Sicherheit: Ausführen von Code mit höheren Privilegien in eCryptfs
Aktuelle Meldungen Distributionen
Name: Ausführen von Code mit höheren Privilegien in eCryptfs
ID: USN-2876-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.04, Ubuntu 15.10
Datum: Mi, 20. Januar 2016, 18:21
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1572
Applikationen: eCryptfs

Originalnachricht


--===============7074923855457442187==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="aM3YZ0Iwxop3KEKx"
Content-Disposition: inline


--aM3YZ0Iwxop3KEKx
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-2876-1
January 20, 2016

ecryptfs-utils vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

mount.ecryptfs_private could be used to run programs as an administrator.

Software Description:
- ecryptfs-utils: eCryptfs cryptographic filesystem utilities

Details:

Jann Horn discovered that mount.ecryptfs_private would mount over certain
directories in the proc filesystem. A local attacker could use this to escalate
their privileges. (CVE-2016-1572)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
ecryptfs-utils 108-0ubuntu1.1

Ubuntu 15.04:
ecryptfs-utils 107-0ubuntu1.3

Ubuntu 14.04 LTS:
ecryptfs-utils 104-0ubuntu1.14.04.4

Ubuntu 12.04 LTS:
ecryptfs-utils 96-0ubuntu3.5

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2876-1
CVE-2016-1572

Package Information:
https://launchpad.net/ubuntu/+source/ecryptfs-utils/108-0ubuntu1.1
https://launchpad.net/ubuntu/+source/ecryptfs-utils/107-0ubuntu1.3
https://launchpad.net/ubuntu/+source/ecryptfs-utils/104-0ubuntu1.14.04.4
https://launchpad.net/ubuntu/+source/ecryptfs-utils/96-0ubuntu3.5


--aM3YZ0Iwxop3KEKx
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJWn6nFAAoJENaSAD2qAscKdp4P/j8oXoO5sJaPDk3vKbr6ogwX
/7M2gD1FluFnTxkYyKH3rJde7thzLpzWJfuZrpCNxGEOcFZcyQGWZcXmDcISPKgs
ftSRvRNM4u6jnvzOK35Xq3HYnv+sVzOELTwUqCsx0TLpBOJHK1WrEoyYUYuu6n8Q
nKTEGQMDa58e6a6BdFam8l07pjCRJ4DEH8wSEwSGUyRUVo6B0v4W/Af/RJP7PBpM
ulAF/iDWDo6gIfM+D9wGUSUX74KLB91q5/ebfF1jvDO1xL/JabDctE8kO5dvnXTP
+p5Cp0QwckSMGsDMxx49y1UHWxuoSz3QHP+Ew85kk2ZODPfh7arympPuR8WuWo9w
7JLjCXsRm4rEggeb4AG3r7PwCZVme7xcFX5vu5E1F9SyY7yUcqmIdR+Ma3o6bzcO
M0B0aeKDuoSbPpIZ6nhFaBPuNKKJcrvZ5JCydRMbwnh385CoDc+Y0PeJjYhKllVA
AqVOi300hrFcIkktTz9Q93dX/h2TbTLf7rzIlsKCZ9H1/CuFiwtsFPVFrBMmtLVZ
z34mGOJvoxxfpxJl4Jz3atziKzCjKfBKxOB1wN5u0YJtVa9I///yMfPnnz0Q8w0V
CfDjth4Y1Vc4Ie4cMLv/FkuZaSqxO+/MpEW62ncbqgftSUS7TalWdybJ3A7F0DRV
kNOx3Q9cY85zvyqbj182
=g+El
-----END PGP SIGNATURE-----

--aM3YZ0Iwxop3KEKx--


--===============7074923855457442187==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============7074923855457442187==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung