Vulnerability Bulletins

DSA-3357 vzctl - security update

   
Affected software Debian
 
It was discovered that vzctl, a set of control tools for the OpenVZserver virtualisation solution, determined the storage layout ofcontainers based on the presence of an XML file inside the container.An attacker with local root privileges in a simfs-based containercould gain control over ploop-based containers. Further information onthe prerequisites of such an attack can be found atsrc.openvz.org.

More info:

https://www.debian.org/security/2015/dsa-3357