USN-3276-2: shadow regression
Severity
Medium
Vendor
Canonical Ubuntu
Versions Affected
- Canonical Ubuntu 14.04
Description
USN-3276-1 intended to fix a vulnerability in su. The solution introduced a regression in su signal handling. This update modifies the security fix. We apologize for the inconvenience.
Original advisory details:
Sebastian Krahmer discovered integer overflows in shadow utilities. A local attacker could possibly cause them to crash or potentially gain privileges via crafted input. (CVE-2016-6252)
Tobias Stöckmann discovered a race condition in su. A local attacker could cause su to send SIGKILL to other processes with root privileges. (CVE-2017-2616)
Affected Cloud Foundry Products and Versions
Severity is medium unless otherwise noted.
- Cloud Foundry BOSH stemcells are vulnerable, including:
- 3263.x versions prior to 3263.26
- 3312.x versions prior to 3312.26
- 3363.x versions prior to 3363.24
- All other stemcells not listed.
- All versions of Cloud Foundry cflinuxfs2 prior to 1.121.0
Mitigation
OSS users are strongly encouraged to follow one of the mitigations below:
- The Cloud Foundry project recommends upgrading the following BOSH stemcells:
- Upgrade 3263.x versions to 3263.26 or later
- Upgrade 3312.x versions to 3312.26 or later
- Upgrade 3363.x versions to 3363.24 or later
- All other stemcells should be upgraded to the latest version.
- The Cloud Foundry project recommends that Cloud Foundry deployments run with cflinuxfs2 version 1.121.0 or later.