Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in LXC
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in LXC
ID: USN-3224-1
Distribution: Ubuntu
Plattformen: Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 16.10
Datum: Do, 9. März 2017, 18:26
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5985
Applikationen: LXC

Originalnachricht


--===============1142331404008890234==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="azLHFNyN32YCQGCU"
Content-Disposition: inline


--azLHFNyN32YCQGCU
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-3224-1
March 09, 2017

lxc vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

LXC could be made to create arbitrary virtual network interfaces as an
administrator.

Software Description:
- lxc: Linux Containers userspace tools

Details:

Jann Horn discovered that LXC incorrectly verified permissions when creating
virtual network interfaces. A local attacker could possibly use this issue to
create virtual network interfaces in network namespaces that they do not own.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
lxc-common 2.0.7-0ubuntu1~16.10.2

Ubuntu 16.04 LTS:
lxc-common 2.0.7-0ubuntu1~16.04.2

Ubuntu 14.04 LTS:
lxc 1.0.9-0ubuntu3

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-3224-1
CVE-2017-5985

Package Information:
https://launchpad.net/ubuntu/+source/lxc/2.0.7-0ubuntu1~16.10.2
https://launchpad.net/ubuntu/+source/lxc/2.0.7-0ubuntu1~16.04.2
https://launchpad.net/ubuntu/+source/lxc/1.0.9-0ubuntu3


--azLHFNyN32YCQGCU
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJYwYYgAAoJENaSAD2qAscKn5MQAMIMnnHKLXWGizHGRYG6qV4U
Y1jpGhXJNCYri5FxDRLr30Q07RR6WWWBL+X3lls4lZk54nUw4FjIj28yJE72TjY6
P5R5qiGt/O2pp02OCd5zreTQsVxruGCc9oqQ/WD0yp0RsO91GR1ueQEvs/khyS9u
jfRGKmRX/3OdZ2Ha1y2dVS77Q/OZ4QrtJqDNmcdrsa3EGCS1fuTVv6i8urQwjHZA
ZFfQh7Vx3pbZBYg4gVGboOjHVTrLK4Z5gfXPq7bS6bnWenIWzlJiQPmM1XF2Xw5j
nYgzNsF/mlwHMq0YUu2M0b7moSFgVsyGMNn0fGR19QTcshNK/kdxFmHGwy0Zuxi4
jOUXjY7KvCv2evUSOo0R5/1PfuioDEg7oT71+Z6tZLmE/yET3jqYbd6/zDifiWvM
xgy4TuUzKV2TgoOSUQXPxoycbUtvLmm63Jp1OBkJJMx3xd0hF9Uq23HSGTkRAdLT
cgXwnTrg4HqrVhQuNN48z8fXYZD+EuQoUNoXYSXp05Hf7N+ZG9mjrpAoUCPX5IyJ
J01VMAYQ6c2GlArIcrO0wafPlf3OHQhiVqljeIGMUIro9OaWUjPw8vlKRds8EHBN
hXHc8od0gbD2vSXTqRl1fSR979meF5b7E7lZo85u3KWq57ApnabmgIFqq61txt6W
PA0+ZonQ2vYZ9ovPtfds
=V3x9
-----END PGP SIGNATURE-----

--azLHFNyN32YCQGCU--


--===============1142331404008890234==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============1142331404008890234==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung