Revision Date: | 2012-01-18 | Version: | 1 | Title: | CVE-2012-0055 on Ubuntu 14.04 LTS (trusty) - medium. | Description: | Using overlayfs with lxc causes tty problems that can kill X. Overlayfs needs to honor the necessary cgroup permission calls. Andy Whitcroft discovered a that the Overlayfs filesystem was not doing the extended permission checks needed by cgroups and Linux Security Modules (LSMs). A local user could exploit this to by-pass security policy and access files that should not be accessible.
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2012-0055
| Platform(s): | Ubuntu 14.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 14.04 LTS (trusty) is installed. AND Package Information
NOT While related to the CVE in some way, the 'linux' package in trusty is not affected.
OR NOT While related to the CVE in some way, the 'linux-aws' package in trusty is not affected.
OR NOT While related to the CVE in some way, the 'linux-flo' package in trusty is not affected.
OR NOT While related to the CVE in some way, the 'linux-goldfish' package in trusty is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-lts-utopic' package in trusty is not affected.
OR NOT While related to the CVE in some way, the 'linux-lts-vivid' package in trusty is not affected.
OR NOT While related to the CVE in some way, the 'linux-lts-wily' package in trusty is not affected.
OR NOT While related to the CVE in some way, the 'linux-lts-xenial' package in trusty is not affected.
OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
OR NOT While related to the CVE in some way, the 'linux-mako' package in trusty is not affected.
OR NOT While related to the CVE in some way, the 'linux-manta' package in trusty is not affected.
|
|