Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in AppArmor
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in AppArmor
ID: USN-3247-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 16.10
Datum: Mi, 29. März 2017, 00:00
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6507
Applikationen: AppArmor

Originalnachricht


--===============1705816392250603656==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="IS0zKkzwUGydFO0o"
Content-Disposition: inline


--IS0zKkzwUGydFO0o
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inlin
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-3247-1
March 28, 2017

apparmor vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

AppArmor could remove the confinement from some programs.

Software Description:
- apparmor: Linux security system

Details:

Stéphane Graber discovered that AppArmor incorrectly unloaded some profiles
when restarted or upgraded, contrary to expected behavior.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
apparmor 2.10.95-4ubuntu5.3

Ubuntu 16.04 LTS:
apparmor 2.10.95-0ubuntu2.6

Ubuntu 14.04 LTS:
apparmor 2.10.95-0ubuntu2.6~14.04.1

Ubuntu 12.04 LTS:
apparmor 2.7.102-0ubuntu3.11

After a standard system update you need to reboot your computer to make
all the necessary changes.

A new utility, called aa-remove-unknown, was added to assist with profiles that
would have been previously unloaded when AppArmor was restarted or upgraded.

References:
http://www.ubuntu.com/usn/usn-3247-1
CVE-2017-6507

Package Information:
https://launchpad.net/ubuntu/+source/apparmor/2.10.95-4ubuntu5.3
https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6
https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1
https://launchpad.net/ubuntu/+source/apparmor/2.7.102-0ubuntu3.11


--IS0zKkzwUGydFO0o
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJY2rhaAAoJENaSAD2qAscKCmsQAJbWYrG2iPCX8me28Hkbqqhc
hbOP7yVc2L80ItSsATFTONpYO4ezhWMUf/fhGADz6H+P0vQKab/zqFgdi+3wXsWp
8REClAkGhYhaDYL5bw0tiaeeiwYFZ8M6yF6rtjrdMvhtS4+yJXh7HhBoV1sfHtLR
BabJWofqfNQObDq28OPVTKpvmTsDavpckr8eZWh0eYFjZLpGY2TaNxrPeQtk48g9
t8fN8hP7tNxj2HrkzOpM5La/JQ+rEznx4R1TOrkHWniPnwJwvs6X7G74TfEaonkp
BrhtJPgDH7tPggZRxbxxARTiU0mP+1MfBwksQHitKJLWC9tnWvqhMv1UEoRLReyj
tR9WoLixHZKWVFtmyCeIbqw+7rFdYJHyazrKqGUDCm7EEjW0HQCzQLDd1I4U/WYc
S8I2q7snFZ4VG9zDN3Ic3l2QwLaPK7I3EFOQbZV34LFD6Jy+vt9PntSeZzYXNDLg
nmaHHIsJYP2crizrYn6VTRrDwvd3rzljVMPWPQ2Ow9wVVBwNQD0ca5PxnxfwJXzw
GETtOrIi0fdktceS0ryB5QPL/K2+deNv1n19qIEMQSMCDa813dL6sbSunW6PIDbR
hprQzdwLBhd5TdcFu+IJyS2h5iW1edlmca62WZ+eMPf+zfQIMm3un08eFbeOGAvZ
s8zwGlPw9XV0NyFpTlVA
=4OGO
-----END PGP SIGNATURE-----

--IS0zKkzwUGydFO0o--


--===============1705816392250603656==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============1705816392250603656==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung