MGASA-2017-0167

Source
https://advisories.mageia.org/MGASA-2017-0167.html
Import Source
https://advisories.mageia.org/MGASA-2017-0167.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0167
Related
Published
2017-06-12T07:42:23Z
Modified
2017-06-12T06:48:02Z
Summary
Updated lxc packages fix security vulnerabilities
Details

Roman Fiedler discovered a directory traversal flaw in lxc-attach. An attacker with access to an LXC container could exploit this flaw to access files outside of the container (CVE-2016-8649).

Jann Horn discovered that LXC incorrectly verified permissions when creating virtual network interfaces. A local attacker could possibly use this issue to create virtual network interfaces in network namespaces that they do not own (CVE-2017-5985).

The lxc package has been updated to version 1.0.10 to fix these issues and other bugs.

References
Credits

Affected packages