Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in File Roller (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in File Roller (Aktualisierung)
ID: USN-4332-2
Distribution: Ubuntu
Plattformen: Ubuntu 20.04 LTS
Datum: Mo, 27. April 2020, 22:47
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11736
Applikationen: File Roller
Update von: Preisgabe von Informationen in File Roller

Originalnachricht


--===============1711931845054405529==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="PNTmBPCT7hxwcZjr"
Content-Disposition: inline


--PNTmBPCT7hxwcZjr
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4332-2
April 27, 2020

file-roller vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

File Roller could be made to expose sensitive information.

Software Description:
- file-roller: archive manager for GNOME

Details:

USN-4332-1 fixed vulnerabilities in File Roller. This update provides
the corresponding update for Ubuntu 20.04 LTS.

Original advisory details:

It was discovered that File Roller incorrectly handled symlinks.
An attacker could possibly use this issue to expose sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
file-roller 3.36.1-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4332-2
https://usn.ubuntu.com/4332-1
CVE-2020-11736

Package Information:
https://launchpad.net/ubuntu/+source/file-roller/3.36.1-1ubuntu0.1

--PNTmBPCT7hxwcZjr
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAl6nN8MACgkQRbznW4QL
H2nojxAAjxqGLn0b6dccHCdJ7FzUazQRkcBBppIIHV+rOmXPYsAPrvFSUek/QIO/
7qGcIqZKMJJlh2M0GYSpeSQqmKoApp/ctaGYBdDKLI565+Ry8ksi96F2db1kxQxq
oYEes7QwMOpKZ5MzcuppYsttjtpsOSVIoF0OiJcX2cy22+0WQtf+M687UpAkAF1r
C8WKP92qSWs715zKhyjNkz3O3Z9FMGwUjfMiB+D5Th5RYxeMIfWx+pR36SIrq2qs
M2eRD3NT5Xd95hibof6hWzLnZxlbKR8oavh4HhDwuje+leeog3vRDwyxU9vncT8u
5ml4MbiIRKQu6ggT9e5RnD/5NhwYn9RpTwx+U+VD9if1t1uNFMbgBWUIBksrYu74
QSaW6AcpFlkiv5EqTcmsjVLvdGeaCnRdavY01aWkC3+yv1lAwxrRhnNVStKRm/dW
GNQc1KwhyDshJWkMLR/jaTcqtCRd5V8u8ZL09UpGwLmCRRcfzHzo3kYvek+3nmEi
dGV527Rhc+ZrABSTm/Y+WSUaUav5v770gZI39WgSnbkKUZdLK6oqYgqAZoQ5FRMw
rPs73KbrKJC/vTj7IfDrU0KVWHmPUH4q9ZCWPB6tW7GKVO7XEH+EwD9ztuPhYIQn
anTj7HT9TT/lXMSMSe09R/DbQf2wYkfJad3djD+OCoU7hb+EZ6s=
=sNEg
-----END PGP SIGNATURE-----

--PNTmBPCT7hxwcZjr--


--===============1711931845054405529==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung