A vulnerability in vzctl might allow attackers to gain control over ploop containers.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201701-30 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: vzctl: Security bypass Date: January 11, 2017 Bugs: #560522 ID: 201701-30 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in vzctl might allow attackers to gain control over ploop containers. Background ========= vzctl is a set of control tools for the OpenVZ server virtualization solution. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-cluster/vzctl < 4.9.4 > = 4.9.4 Description ========== It was discovered that vzctl determined the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory. This allows local simfs container (CT) root usersto change the root password for arbitrary ploop containers. This is demonstrated by a symlink attack on the ploop container root.hdd file which can then be used to access a control panel. Impact ===== An attacker with root privileges, in a simfs-based container, could gain control over ploop-based containers. Workaround ========= There is no known workaround at this time. Resolution ========= All vzctl users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-cluster/vzctl-4.9.4" References ========= [ 1 ] CVE-2015-6927 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6927 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201701-30 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
It was discovered that vzctl, a set of control tools for the OpenVZ server virtualisation solution, determined the storage layout of containers based on the presense of an XML file inside the container. An attacker with local root privileges in a simfs-based container . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3357-1
Get the latest Linux and open source security news straight to your inbox.