Описание
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| lxc-templates | unfixed | package | ||
| lxc | fixed | 1:3.0.3-1 | package | |
| lxc | no-dsa | stretch | package | |
| lxc | ignored | jessie | package |
Примечания
LXC 3.0.2 split the templates out to separate lxc-templates.
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1661447
Some of the templates were switched to fetch the pacakges over HTTPS, cf.
https://github.com/lxc/lxc/pull/1371 for the lxc-fedora template.
No security commitments from upstream and lxc-ltemplates deprecated in favour of
distrobuilder.
Связанные уязвимости
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.