You are here
Home > Preporuke > Ranjivosti programskog paketa lxc

Ranjivosti programskog paketa lxc

  • Detalji os-a: LUB
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2675-1
July 22, 2015

lxc vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 15.04
– Ubuntu 14.10
– Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in LXC.

Software Description:
– lxc: Linux Containers userspace tools

Details:

Roman Fiedler discovered that LXC had a directory traversal flaw when creating
lock files. A local attacker could exploit this flaw to create an arbitrary
file as the root user. (CVE-2015-1331)

Roman Fiedler discovered that LXC incorrectly trusted the container’s proc
filesystem to set up AppArmor profile changes and SELinux domain transitions. A
local attacker could exploit this flaw to run programs inside the container
that are not confined by AppArmor or SELinux. (CVE-2015-1334)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
liblxc1 1.1.2-0ubuntu3.1
lxc 1.1.2-0ubuntu3.1

Ubuntu 14.10:
liblxc1 1.1.0~alpha2-0ubuntu3.3
lxc 1.1.0~alpha2-0ubuntu3.3

Ubuntu 14.04 LTS:
liblxc1 1.0.7-0ubuntu0.2
lxc 1.0.7-0ubuntu0.2

In general, a standard system update will make all the necessary changes. You
will need to restart your previously running LXC containers in Ubuntu 15.04 due
to bug that causes containers to be stopped on during lxc package installation
(https://launchpad.net/bugs/1476691).

References:
http://www.ubuntu.com/usn/usn-2675-1
CVE-2015-1331, CVE-2015-1334

Package Information:
https://launchpad.net/ubuntu/+source/lxc/1.1.2-0ubuntu3.1
https://launchpad.net/ubuntu/+source/lxc/1.1.0~alpha2-0ubuntu3.3
https://launchpad.net/ubuntu/+source/lxc/1.0.7-0ubuntu0.2

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJVr7J2AAoJENaSAD2qAscKezAP+wQYHAMoexfjfMwbLbOfTV9l
fksGxRL4lChVQQy7ZH/ylIqzANjfEBEIwFNXKvQii835CW/fyvk5aitR92NKtUHG
UmCrE5eEn37URdnr2Qf7ziBYsTMCZ5+ksqcZf8Xmqo31whe/Y9eyIR59gOhY2R67
A79LyaL/SXTysvOkzg+HXamTG8DtERWkQHDa/e9J+/T1JBXDYMvebnvsgUVn+7pf
sOGVH+3rn4ZdPxo11eZkF/iRdjtqt+8uIbcFAcQnWhzDQIce2Xijc3h7bJcQR4+O
+tJ24hRYcz2B40YSVpnSGvLZ+s72VpvnCEAgJt7d2eLSHyJY/a1+48aexa3z4pSq
Okm9RuQ6R0bu5g5uCZ6V4WOGiqXayi1/fBlWfEuDA5VE9XIbS/UKxJPlvv9BSiKf
PXPYZiQCijcaWqcmHetkpGtrv8D75kQ9QIcgh9eBBDyX9UXb+M3N+2jYestZvLcn
pBG6T1Ek5ovXfof+cxQmanX6TvGhZNrfRl7n/e4lF5npGPw2mHWvc6cPMm9c9LRA
SUnn/2i5GJJzNMJM2y/iopgFG8wDyuASkQdaCmgkTb3OzTvgTFx6ujdaYFnAvb0b
Jo+thi1RyYg5KEsCAUb3xZ9OsByLrWE7yctZhfE7WmAQ/A05SWqraCZNGz47Zs7v
eJfVc6C90ckSLlkZujwa
=0GhC
—–END PGP SIGNATURE—–

AutorTomislav Protega
Cert idNCERT-REF-2015-07-0033-ADV
CveCVE-2015-1331 CVE-2015-1334
ID izvornikaUSN-2675-1
Proizvodlxc
Izvorhttp://www.ubuntu.com
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa bind

Otkriven je sigurnosni nedostatak u programskom paketu bind za RHEL 6. Otkriveni nedostatak uzrokovan je neispravnom obradom određenih podataka zone...

Close