MGASA-2015-0304
Dashboard / Vulnerabilities / MGASA-2015-0304
Summary: Updated lxc package fixes security vulnerability
Details: Roman Fiedler discovered that LXC had a directory traversal flaw when creating lock files. A local attacker could exploit this flaw to create an arbitrary file as the root user (CVE-2015-1331). Roman Fiedler discovered that LXC incorrectly trusted the container's proc filesystem to set up AppArmor profile changes and SELinux domain transitions. A local attacker could exploit this flaw to run programs inside the container that are not confined by AppArmor or SELinux (CVE-2015-1334).
References: https://advisories.mageia.org/MGASA-2015-0304.html, https://bugs.mageia.org/show_bug.cgi?id=16443, http://www.ubuntu.com/usn/usn-2675-1
Affected packages
Package
Name: lxc
Purl: pkg:rpm/mageia/lxc?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
