drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in man-db
Name: |
Ausführen beliebiger Kommandos in man-db |
|
ID: |
USN-5334-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 16.04 ESM |
|
Datum: |
Do, 17. März 2022, 23:37 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1336
https://ubuntu.com/security/notices/USN-5334-1 |
|
Applikationen: |
man-db |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============1097751755984607745== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------5cGFdqQwZFkBr7MXZM6uwZVE"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------5cGFdqQwZFkBr7MXZM6uwZVE Content-Type: multipart/mixed; boundary="------------090jXr4RhxiXxk9Xb0AVTlLK"; protected-headers="v1" From: Camila Camargo de Matos <camila.camargodematos@canonical.com> Reply-To: security@ubuntu.com To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <3e78289d-5d68-92c1-fead-ec8032d4ceba@canonical.com> Subject: [USN-5334-1] man-db vulnerability References: <20220317124654.79E3C26C2777@lillypilly.canonical.com> In-Reply-To: <20220317124654.79E3C26C2777@lillypilly.canonical.com>
--------------090jXr4RhxiXxk9Xb0AVTlLK Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-5334-1 March 17, 2022
man-db vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 ESM
Summary:
man-db could be made to overwrite file and directory permissions.
Software Description: - man-db: on-line manual pager
Details:
It was discovered that man-db incorrectly handled permission changing operations in its daily cron job, and was therefore affected by a race condition. An attacker could possibly use this issue to escalate privileges and execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04 ESM: man-db 2.7.5-1ubuntu0.1~esm1
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-5334-1 CVE-2015-1336
|
|
|
|