You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa lxc

Sigurnosni nedostatak programskog paketa lxc

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3224-1
March 09, 2017

lxc vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.10
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS

Summary:

LXC could be made to create arbitrary virtual network interfaces as an
administrator.

Software Description:
– lxc: Linux Containers userspace tools

Details:

Jann Horn discovered that LXC incorrectly verified permissions when creating
virtual network interfaces. A local attacker could possibly use this issue to
create virtual network interfaces in network namespaces that they do not own.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
lxc-common 2.0.7-0ubuntu1~16.10.2

Ubuntu 16.04 LTS:
lxc-common 2.0.7-0ubuntu1~16.04.2

Ubuntu 14.04 LTS:
lxc 1.0.9-0ubuntu3

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-3224-1
CVE-2017-5985

Package Information:
https://launchpad.net/ubuntu/+source/lxc/2.0.7-0ubuntu1~16.10.2
https://launchpad.net/ubuntu/+source/lxc/2.0.7-0ubuntu1~16.04.2
https://launchpad.net/ubuntu/+source/lxc/1.0.9-0ubuntu3

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJYwYYgAAoJENaSAD2qAscKn5MQAMIMnnHKLXWGizHGRYG6qV4U
Y1jpGhXJNCYri5FxDRLr30Q07RR6WWWBL+X3lls4lZk54nUw4FjIj28yJE72TjY6
P5R5qiGt/O2pp02OCd5zreTQsVxruGCc9oqQ/WD0yp0RsO91GR1ueQEvs/khyS9u
jfRGKmRX/3OdZ2Ha1y2dVS77Q/OZ4QrtJqDNmcdrsa3EGCS1fuTVv6i8urQwjHZA
ZFfQh7Vx3pbZBYg4gVGboOjHVTrLK4Z5gfXPq7bS6bnWenIWzlJiQPmM1XF2Xw5j
nYgzNsF/mlwHMq0YUu2M0b7moSFgVsyGMNn0fGR19QTcshNK/kdxFmHGwy0Zuxi4
jOUXjY7KvCv2evUSOo0R5/1PfuioDEg7oT71+Z6tZLmE/yET3jqYbd6/zDifiWvM
xgy4TuUzKV2TgoOSUQXPxoycbUtvLmm63Jp1OBkJJMx3xd0hF9Uq23HSGTkRAdLT
cgXwnTrg4HqrVhQuNN48z8fXYZD+EuQoUNoXYSXp05Hf7N+ZG9mjrpAoUCPX5IyJ
J01VMAYQ6c2GlArIcrO0wafPlf3OHQhiVqljeIGMUIro9OaWUjPw8vlKRds8EHBN
hXHc8od0gbD2vSXTqRl1fSR979meF5b7E7lZo85u3KWq57ApnabmgIFqq61txt6W
PA0+ZonQ2vYZ9ovPtfds
=V3x9
—–END PGP SIGNATURE—–

AutorTomislav Protega
Cert idNCERT-REF-2017-03-0067-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa firefox-esr

Otkriveni su sigurnosni nedostaci u programskom paketu firefox-esr za Debian. Zahvaćene su razne komponente web preglednika, a ovisno o tipu...

Close