Debian Security Advisory
DSA-3400-1 lxc -- security update
- Date Reported:
- 19 Nov 2015
- Affected Packages:
- lxc
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 800471.
In Mitre's CVE dictionary: CVE-2015-1335. - More information:
-
Roman Fiedler discovered a directory traversal flaw in LXC, the Linux Containers userspace tools. A local attacker with access to a LXC container could exploit this flaw to run programs inside the container that are not confined by AppArmor or expose unintended files in the host to the container.
For the stable distribution (jessie), this problem has been fixed in version 1:1.0.6-6+deb8u2.
We recommend that you upgrade your lxc packages.