CVE-2016-1585: AppArmor mount rules grant excessive permissions
Published Apr 22, 2019
·Updated
In all versions of AppArmor mount rules are accidentally widened when compiled.
Affected Software
5 affected componentsFixes available
debian/apparmor<=2.13.6-10, <=3.0.8-3
3.1.7-1
Canonical Apparmor
Canonical Apparmor<2.13.10
Canonical Apparmor>=3.0.0<3.0.12
Canonical Apparmor>=3.1.0<3.1.6
Event History
Apr 22, 2019
CVE Published
via MITRE·03:35 PM
Data Sourced
via MITRE·03:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:29 PM
DescriptionSeverityAffected Software
Sep 25, 2024
Data Sourced
via Ubuntu·11:05 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1585?
CVE-2016-1585 has a moderate severity level due to the accidental widening of mount rules in AppArmor.
2
How do I fix CVE-2016-1585?
To fix CVE-2016-1585, update the AppArmor package to version 3.1.7-1 or higher.
3
What versions of AppArmor are affected by CVE-2016-1585?
CVE-2016-1585 affects all versions of AppArmor prior to 3.1.7-1, including versions up to 2.13.6-10 and 3.0.8-3.
4
Is there a workaround for CVE-2016-1585?
Currently, no official workaround for CVE-2016-1585 is provided, so updating to a fixed version is recommended.
5
What impact does CVE-2016-1585 have on system security?
The widening of mount rules in CVE-2016-1585 may lead to unauthorized access to file systems, hence impacting overall system security.