OpenVZ Local Security Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
OpenVZ <042stab090. 5
OpenVZ
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68171
CVE (CAN) ID: CVE-2014-3519
OpenVZ is a system-level virtualization technology based on Linux kernel and operating system.
OpenVZ 042stab090. 5. The open_by_handle_at () function of earlier versions allows the process to access files in the file_handle structure attached to the file system. This structure tests inode numbers to differentiate files, local attackers can exploit this vulnerability to bypass certain security restrictions and perform unauthorized operations.
Complete HyperVM installation Tutorial: Use HyperVM to manage OpenVZ architecture virtual machines
Install and configure OpenVZ in CentOS 6
Install OpenVZ on Ubuntu 10.04
Install and use OpenVZ on CentOS 5.5 Server
CentOS 5.4 + OpenVZ + Vtonf self-built VPS Server
<* Source: Michal Grzedzicki
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
OpenVZ
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://openvz.org/Main_Page
This article permanently updates the link address: