Ubuntu Security Notice USN-2797-1

Discussion in 'News Aggregator' started by Packet Storm, 6 Nov 2015.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 2797-1 - It was discovered that the Linux kernel did not check if a new IPv6 MTU set by a user space application was valid. A remote attacker could forge a route advertisement with an invalid MTU that a user space daemon like NetworkManager would honor and apply to the kernel, causing a denial of service. It was discovered that in certain situations, a directory could be renamed outside of a bind mounted location. An attacker could use this to escape bind mount containment and gain access to sensitive information. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...