Ubuntu Security Notice USN-2908-2

Discussion in 'News Aggregator' started by Packet Storm, 23 Feb 2016.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 2908-2 - halfdog discovered that OverlayFS, when mounting on top of a FUSE mount, incorrectly propagated file attributes, including setuid. A local unprivileged attacker could use this to gain privileges. halfdog discovered that OverlayFS in the Linux kernel incorrectly propagated security sensitive extended attributes, such as POSIX ACLs. A local unprivileged attacker could use this to gain privileges. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...