[Bug 1661447] Re: Arbitrary code execution in centos template

2020-02-10 Thread Gianni Tedesco
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-18641 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1661447 Title: Arbitrary code execution in centos template To manage notificati

[Bug 1661447] Re: Arbitrary code execution in centos template

2020-02-06 Thread Gianni Tedesco
Great, thanks again for all the hard work! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1661447 Title: Arbitrary code execution in centos template To manage notifications about this bug go to: htt

[Bug 1661447] Re: Arbitrary code execution in centos template

2020-02-05 Thread Stéphane Graber via ubuntu-bugs
Yeah, we were originally considering fixing all of the individual templates but frankly it was just too much of a mess of bad patterns from a variety of different authors with no real consistency. Instead what we came up with is distrobuilder (https://github.com/lxc/distrobuilder) which has now

[Bug 1661447] Re: Arbitrary code execution in centos template

2020-02-05 Thread Stéphane Graber via ubuntu-bugs
We're marking this issue as "Fix Released" for LXC due to the removal of all those scripts from the standard LXC distribution, instead relying on distrobuilder for our users to generate custom LXC images (which can then be consumed by the lxc-local template). -- You received this bug notification