Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Debian: DSA-3357-1 Moderate: Vzctl Local Root Access Threat

debian
Calendar Grey September 13, 2015
Debian Logo
Debian Security Update DSA-3358-1 concerns a vulnerability in vzctl impacting container configurations and potentially allowing local administrative access.
It was discovered that vzctl, a set of control tools for the OpenVZ server virtualisation solution, determined the storage layout of containers based on the presense of an XML file...

Summary

It was discovered that vzctl, a set of control tools for the OpenVZ
server virtualisation solution, determined the storage layout of
containers based on the presense of an XML file inside the container.
An attacker with local root privileges in a simfs-based container
could gain control over ploop-based containers. Further information on
the prerequites of such an attack can be found at


The oldstable distribution (wheezy) is not affected.

For the stable distribution (jessie), this problem has been fixed in
version 4.8-1+deb8u2. During the update existing configurations are
automatically updated.

For the testing distribution (stretch), this problem has been fixed
in version 4.9.4-2.

For the unstable distribution (sid), this problem has been fixed in
version 4.9.4-2.

We recommend that you upgrade your vzctl packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: vzctl
CVE ID: not yet available

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here