Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2017.0167
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2017-0167)
Resumen:The remote host is missing an update for the 'lxc' package(s) announced via the MGASA-2017-0167 advisory.
Descripción:Summary:
The remote host is missing an update for the 'lxc' package(s) announced via the MGASA-2017-0167 advisory.

Vulnerability Insight:
Roman Fiedler discovered a directory traversal flaw in lxc-attach. An
attacker with access to an LXC container could exploit this flaw to
access files outside of the container (CVE-2016-8649).

Jann Horn discovered that LXC incorrectly verified permissions when
creating virtual network interfaces. A local attacker could possibly use
this issue to create virtual network interfaces in network namespaces
that they do not own (CVE-2017-5985).

The lxc package has been updated to version 1.0.10 to fix these issues
and other bugs.

Affected Software/OS:
'lxc' package(s) on Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-8649
94498
http://www.securityfocus.com/bid/94498
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=845465
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1639345
https://bugzilla.redhat.com/show_bug.cgi?id=1398242
https://github.com/lxc/lxc/commit/81f466d05f2a89cb4f122ef7f593ff3f279b165c
https://security-tracker.debian.org/tracker/CVE-2016-8649
Common Vulnerability Exposure (CVE) ID: CVE-2017-5985
BugTraq ID: 96777
http://www.securityfocus.com/bid/96777
https://lists.linuxcontainers.org/pipermail/lxc-devel/2017-March/015535.html
http://www.openwall.com/lists/oss-security/2017/03/09/4
SuSE Security Announcement: openSUSE-SU-2019:1481 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00073.html
http://www.ubuntu.com/usn/USN-3224-1
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.