Ausführen von Code mit höheren Privilegien in Apport
ID: | USN-2782-1 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.04, Ubuntu 15.10 |
Datum: | Di, 27. Oktober 2015, 14:32 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1341 |
Applikationen: | Apport |
Originalnachricht |
|
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============6932956462516585701== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="n2SUerGvLSkNeH5rMk5WD59gNbtJpuKt6" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --n2SUerGvLSkNeH5rMk5WD59gNbtJpuKt6 Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-2782-1 October 27, 2015 apport vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 15.04 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Apport could be made to run programs as an administrator. Software Description: - apport: automatically generate crash reports for debugging Details: Gabriel Campana discovered that Apport incorrectly handled Python module imports. A local attacker could use this issue to elevate privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: apport 2.19.1-0ubuntu4 Ubuntu 15.04: apport 2.17.2-0ubuntu1.7 Ubuntu 14.04 LTS: apport 2.14.1-0ubuntu3.18 Ubuntu 12.04 LTS: apport 2.0.1-0ubuntu17.13 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2782-1 CVE-2015-1341 Package Information: https://launchpad.net/ubuntu/+source/apport/2.19.1-0ubuntu4 https://launchpad.net/ubuntu/+source/apport/2.17.2-0ubuntu1.7 https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18 https://launchpad.net/ubuntu/+source/apport/2.0.1-0ubuntu17.13 --n2SUerGvLSkNeH5rMk5WD59gNbtJpuKt6 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJWL3l2AAoJEGVp2FWnRL6T9owQAKykqYJqWE8Pzr5tbvxvbko0 UTcCn7FN6SeNq1uo5ygaOWIF6QYWKD/6c+W1z5TuoGmAkcCe8Uq83KmjmEqDsXNC qlD2DGLEiTbYaJIHngRoAOn2YrJeneJmLKr/ZHmwFPrl3frh9LBY4Iim7yLXKh15 Ied+2asXBee7vdk0JHaxBBwcs0fkofQoWmCd8pl/leki3/R/f6zVmKXhklyneGDL 3gASKovm+FVnix9+940u4WLwN//bszXPeTp3m9XlHxRi3k4Z4o8Z2Yqa2BciPvA+ HZkjGCEN+e2YFUG+NFsCSou6U6It47wt0BJKnSYSh+gST3kX6TV250E1lrZuEkFf oZBHVcKwhkh1YIDCfz3jjkrbUNn5FnEKzTIlVyZflg4vmMQbiYyEyr62u1VXRomf 8jkb9h2lExyVlIUp3zrt6nz2IXQonoLmVq5gVao2mjqz/GB/JMB7n5O/SSl1AhEi AQtDVD/aSPRlT0pehKnTth2HuLIaNGNAhTyaQDWceJmBk+jCE3D9ZBIgboelBDS1 5WdY35cFD+UMcT/cgkVEFzW8yEg0E5UmAHJ7UhAy33YT7GG7ou9QE1BnLI5RHlby 4kA4MDmuJluHLDw5Dt/83iDgbW9fSC7A9Hiw6y/hZgSnbRJ8eZZBQIhRKBpucr+f H9XPbaRzhThT9i27YVzC =BikZ -----END PGP SIGNATURE----- --n2SUerGvLSkNeH5rMk5WD59gNbtJpuKt6-- --===============6932956462516585701== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce --===============6932956462516585701==-- |