Ubuntu alert USN-2813-1 (lxcfs)
From: | Marc Deslauriers <marc.deslauriers@canonical.com> | |
To: | ubuntu-security-announce@lists.ubuntu.com | |
Subject: | [USN-2813-1] LXCFS vulnerabilities | |
Date: | Tue, 17 Nov 2015 13:32:21 -0500 | |
Message-ID: | <564B72B5.1040909@canonical.com> |
========================================================================== Ubuntu Security Notice USN-2813-1 November 17, 2015 lxcfs vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 15.04 Summary: Several security issues were fixed in LXCFS. Software Description: - lxcfs: FUSE based filesystem for LXC Details: It was discovered that LXCFS incorrectly enforced directory escapes. A local attacker could use this issue to possibly escalate privileges. (CVE-2015-1342) It was discovered that LXCFS incorrectly checked certain permissions. A local attacker could use this issue t possibly escalate privileges. (CVE-2015-1344) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: lxcfs 0.10-0ubuntu2.1 Ubuntu 15.04: lxcfs 0.7-0ubuntu4.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2813-1 CVE-2015-1342, CVE-2015-1344 Package Information: https://launchpad.net/ubuntu/+source/lxcfs/0.10-0ubuntu2.1 https://launchpad.net/ubuntu/+source/lxcfs/0.7-0ubuntu4.1 -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security...