|
|
Log in / Subscribe / Register

Ubuntu alert USN-4589-1 (containerd)

From:  Paulo Flabiano Smorigo <pfsmorigo@canonical.com>
To:  security@ubuntu.com, ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-4589-1] containerd vulnerability
Date:  Thu, 15 Oct 2020 17:40:40 -0300
Message-ID:  <20201015204040.jsionbu4verrurwi@morty>

========================================================================== Ubuntu Security Notice USN-4589-1 October 15, 2020 containerd vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: containerd could be made to expose sensitive information over the network. Software Description: - containerd: daemon to control containers Details: It was discovered that containerd could be made to expose sensitive information when processing URLs in container image manifests. A remote attacker could use this to trick the user and obtain the user's registry credentials. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: containerd 1.2.6-0ubuntu1~16.04.4 After a standard system update you need to restart containerd to make all the necessary changes. References: https://usn.ubuntu.com/4589-1 CVE-2020-15157 Package Information: https://launchpad.net/ubuntu/+source/containerd/1.2.6-0ub... -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security...


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds