Login
Newsletter
Werbung

Sicherheit: Überschreiben von Dateien in tmpreaper
Aktuelle Meldungen Distributionen
Name: Überschreiben von Dateien in tmpreaper
ID: USN-4077-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
Datum: Mo, 29. Juli 2019, 23:35
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3461
https://launchpad.net/ubuntu/+source/tmpreaper/1.6.13+nmu1+deb9u1build0.18.04.1
https://launchpad.net/ubuntu/+source/tmpreaper/1.6.13+nmu1+deb9u1build0.16.04.1
Applikationen: tmpreaper

Originalnachricht


--===============3530732291393440717==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-M9Qj8xPrFcN0uD8OvYLn"


--=-M9Qj8xPrFcN0uD8OvYLn
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4077-1
July 29, 2019

tmpreaper vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

tmpreaper could be made to overwrite files as the administrator.

Software Description:
- tmpreaper: cleans up files in directories based on their age

Details:

It was discovered that tmpreaper incorrectly handled certain mount operations.
A
local attacker could possibly use this issue to create arbitrary files, leading
to privilege escalation.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
tmpreaper 1.6.13+nmu1+deb9u1build0.18.04.1

Ubuntu 16.04 LTS:
tmpreaper 1.6.13+nmu1+deb9u1build0.16.04.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4077-1
CVE-2019-3461

Package Information:

https://launchpad.net/ubuntu/+source/tmpreaper/1.6.13+nmu1+deb9u1build0.18.04.1

https://launchpad.net/ubuntu/+source/tmpreaper/1.6.13+nmu1+deb9u1build0.16.04.1

--=-M9Qj8xPrFcN0uD8OvYLn
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEECtyyz6azUy6AZBzSkGeI6zGnN/8FAl0/L9oACgkQkGeI6zGn
N/8BuA//b5iEBO/33cN+ZzI+B65hB2SaEe/8Lq2hh2rVETYejJAdVUEfH4SAqBs3
3Vk/OOfJpO8jBR0grBQZAKs9xuqX1GEpUR2uqlXZV9VY5yqK0FUCcR2s8ZkDL9oC
T58QnicuXprkEBDgndyoeO85lqQzDydTCmqHmda8D/oHsPR95cM5TXz7k8PYRMpB
QqO1ydcGa2T7MZlT6a1D/5DjuHGTCiSA2vRz5e1dZYseczlZ7Aryowh17QGQJ+03
wB0UMHM9q/RxId3wQkirZ5M//ep/gSOajK5UzDxq0Zc5MGpLBakfo/GzshInvmCf
2uwpEnVY9j29Bu6rMgE2UcovjNKe2iocdMrSzbrnIX9ApLywnc8MrkjLxy6GtMoq
eYb1rO9/PS7bn8GzoANKmricD4KM3lagybEQGkao5rDqirydoTZhWJxSx41MLVUe
X7NMp+j0HX61UWIFjsk/2EvRl5neX3vocEWI5zp1Jydby/F9OVX32AbV4LihyTI6
acneDMFC7Hm8sSwjmPa2mdjjOjEYD1D77Bx1HOf2WXRVL4Z4DwHu26EegbvAxCLY
bsXL4upztPpGA4J/h0UZmXR6iSgqzu7YXZkN7wO9vQmYfa6UvGggjKAI0sACPg3Q
A30ZMYsgeYCPaqkRYFwggYSybLQPh51b9xCz3APM/tA7kM5CwDE=
=oRSb
-----END PGP SIGNATURE-----

--=-M9Qj8xPrFcN0uD8OvYLn--



--===============3530732291393440717==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============3530732291393440717==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung