DSA-3400-1 lxc -- security update

Related Vulnerabilities: CVE-2015-1335  

Roman Fiedler discovered a directory traversal flaw in LXC, the Linux Containers userspace tools. A local attacker with access to a LXC container could exploit this flaw to run programs inside the container that are not confined by AppArmor or expose unintended files in the host to the container. For the stable distribution (jessie), this problem has been fixed in version 1:1.0.6-6+deb8u2. We recommend that you upgrade your lxc packages.

Debian Security Advisory

DSA-3400-1 lxc -- security update

Date Reported:
19 Nov 2015
Affected Packages:
lxc
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 800471.
In Mitre's CVE dictionary: CVE-2015-1335.
More information:

Roman Fiedler discovered a directory traversal flaw in LXC, the Linux Containers userspace tools. A local attacker with access to a LXC container could exploit this flaw to run programs inside the container that are not confined by AppArmor or expose unintended files in the host to the container.

For the stable distribution (jessie), this problem has been fixed in version 1:1.0.6-6+deb8u2.

We recommend that you upgrade your lxc packages.