Login
Newsletter
Werbung

Sicherheit: Ausführen von Code mit höheren Privilegien in Apport
Aktuelle Meldungen Distributionen
Name: Ausführen von Code mit höheren Privilegien in Apport
ID: USN-2782-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.04, Ubuntu 15.10
Datum: Di, 27. Oktober 2015, 14:32
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1341
Applikationen: Apport

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============6932956462516585701==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="n2SUerGvLSkNeH5rMk5WD59gNbtJpuKt6"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--n2SUerGvLSkNeH5rMk5WD59gNbtJpuKt6
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2782-1
October 27, 2015

apport vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Apport could be made to run programs as an administrator.

Software Description:
- apport: automatically generate crash reports for debugging

Details:

Gabriel Campana discovered that Apport incorrectly handled Python module
imports. A local attacker could use this issue to elevate privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
apport 2.19.1-0ubuntu4

Ubuntu 15.04:
apport 2.17.2-0ubuntu1.7

Ubuntu 14.04 LTS:
apport 2.14.1-0ubuntu3.18

Ubuntu 12.04 LTS:
apport 2.0.1-0ubuntu17.13

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2782-1
CVE-2015-1341

Package Information:
https://launchpad.net/ubuntu/+source/apport/2.19.1-0ubuntu4
https://launchpad.net/ubuntu/+source/apport/2.17.2-0ubuntu1.7
https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18
https://launchpad.net/ubuntu/+source/apport/2.0.1-0ubuntu17.13



--n2SUerGvLSkNeH5rMk5WD59gNbtJpuKt6
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJWL3l2AAoJEGVp2FWnRL6T9owQAKykqYJqWE8Pzr5tbvxvbko0
UTcCn7FN6SeNq1uo5ygaOWIF6QYWKD/6c+W1z5TuoGmAkcCe8Uq83KmjmEqDsXNC
qlD2DGLEiTbYaJIHngRoAOn2YrJeneJmLKr/ZHmwFPrl3frh9LBY4Iim7yLXKh15
Ied+2asXBee7vdk0JHaxBBwcs0fkofQoWmCd8pl/leki3/R/f6zVmKXhklyneGDL
3gASKovm+FVnix9+940u4WLwN//bszXPeTp3m9XlHxRi3k4Z4o8Z2Yqa2BciPvA+
HZkjGCEN+e2YFUG+NFsCSou6U6It47wt0BJKnSYSh+gST3kX6TV250E1lrZuEkFf
oZBHVcKwhkh1YIDCfz3jjkrbUNn5FnEKzTIlVyZflg4vmMQbiYyEyr62u1VXRomf
8jkb9h2lExyVlIUp3zrt6nz2IXQonoLmVq5gVao2mjqz/GB/JMB7n5O/SSl1AhEi
AQtDVD/aSPRlT0pehKnTth2HuLIaNGNAhTyaQDWceJmBk+jCE3D9ZBIgboelBDS1
5WdY35cFD+UMcT/cgkVEFzW8yEg0E5UmAHJ7UhAy33YT7GG7ou9QE1BnLI5RHlby
4kA4MDmuJluHLDw5Dt/83iDgbW9fSC7A9Hiw6y/hZgSnbRJ8eZZBQIhRKBpucr+f
H9XPbaRzhThT9i27YVzC
=BikZ
-----END PGP SIGNATURE-----

--n2SUerGvLSkNeH5rMk5WD59gNbtJpuKt6--


--===============6932956462516585701==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============6932956462516585701==--
Pro-Linux
Gewinnspiel
Neue Nachrichten
Werbung