MGASA-2016-0163

Source
https://advisories.mageia.org/MGASA-2016-0163.html
Import Source
https://advisories.mageia.org/MGASA-2016-0163.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0163
Related
Published
2016-05-05T16:26:44Z
Modified
2016-05-05T16:19:28Z
Summary
Updated ansible packages fix CVE-2016-3096
Details

Updated ansible package fixes security vulnerability:

A vulnerability in lxccontainer, ansible module, was found allowing to get root inside the container. The problem is in the createscript function, which tries to write to /opt/.lxc-attach-script inside of the container. If the attacker can write to /opt/.lxc-attach-script before that, he can overwrite arbitrary files or execute commands as root (CVE-2016-3096).

References
Credits

Affected packages

Mageia:5 / ansible

Package

Name
ansible
Purl
pkg:rpm/mageia/ansible?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.6-1.mga5

Ecosystem specific

{
    "section": "core"
}