VDB

MAGEIA-2016-163

MAGEIA-2016-163 PUBLISHED

Updated ansible package fixes security vulnerability: A vulnerability in lxc_container, ansible module, was found allowing to get root inside the container. The problem is in the create_script function, which tries to write to /opt/.lxc-attach-script inside of the container. If the attacker can write to /opt/.lxc-attach-script before that, he can overwrite arbitrary files or execute commands as root (CVE-2016-3096).

Affected Products

VendorProductVersions
Mageiaansible0, 1.9.6-1.mga5

Timeline

  • May 5, 2016 CVE Updated
  • May 5, 2016 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›