You are here
Home > Preporuke > Sigurnosni propust programskog paketa lxd

Sigurnosni propust programskog paketa lxd

  • Detalji os-a: LUB
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2809-1
November 12, 2015

lxd vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 15.10

Summary:

LXD could be made to run programs as an administrator.

Software Description:
– lxd: Container hypervisor based on LXC

Details:

Jeroen Simonetti discovered that LXD incorrectly set socket permissions. A
local attacker could use this issue to escalate privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
lxd 0.20-0ubuntu4.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2809-1
https://launchpad.net/bugs/1515689

Package Information:
https://launchpad.net/ubuntu/+source/lxd/0.20-0ubuntu4.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJWRNRIAAoJEGVp2FWnRL6T+MQP/37vErZ7+jmVoPtYaLyf9myX
07dv6MKt4qW1Z3UeCdq1udPUVneTGyuEba/qJtzhA1G/JNwAxAGyOCHXO0UkbTNk
CMK5ESwF93HwbTWSun1h10zEVvKGzYN8gTiLVh6vFZx+A5uYGCvZh5g7NbUuDIo4
YdbyvV3Zr5JLRr8ds2jcBOu9cHPs4kG0EUQC20dORtJYUN+pf8LS8JnqGCoxWJrx
ctndQdWok4vMtKYT+nrD0eWsY/SQKbhJVfWCJCoaW/uEXWKc5srUoMY6GqjmxRee
DB5UiKtUu8gFdgX4O6WPx5lyI5JF8DkaotMgOG1B8RZq6Vn7mQiDsE7qYjUZ52xP
V/8SHmf27ppVBkKeQpjomQx/jejvpYyHL9wXPfuqU2gp/opfTmsATDdKXIykcDnx
zizq98C0C/s2uKLSwx3nUA6MKSGYLjMxR5ovr/M4R6t8wmdfUQ4kpW98EiRuMa6s
kdGzasa27NCFZ0daleTQlNTIvvD6kW7t5OQwQQlRA/4ugxc+p0ZYqEkLp0WN6+YD
/ZdNWyMFrY8YdvqWwqyfxMOegkJpcer2A4iKngHRnTgPT7fSwqdVTcfDxGjM9xoj
HpMhySACiRhydTuorFXmol+LA17XaMY7D5O+TzbFOqgPDGR2u//Clt5IS66ibjMt
kKsJR6j1NwBTdYfPh88B
=YnPM
—–END PGP SIGNATURE—–

AutorTomislav Protega
Cert idNCERT-REF-2015-11-0005-ADV
ID izvornikaUSN-2809-1
Proizvodlxd
Izvorhttp://www.ubuntu.com
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa wpa_supplicant

Otkriven je sigurnosni nedostatak u programskom paketu wpa_supplicant za Fedoru 23. Otkriveni nedostatak je uzrokovan cjelobrojnim podljevom i potencijalnim udaljenim...

Close