drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in Apport
Name: |
Mehrere Probleme in Apport |
|
ID: |
USN-4720-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10 |
|
Datum: |
Di, 2. Februar 2021, 22:39 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25682
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25683
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25684 |
|
Applikationen: |
Apport |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============4005630193964606768== Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="IUsRZivG6mBv2W9L487N9L87ZRGlBCh9B"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --IUsRZivG6mBv2W9L487N9L87ZRGlBCh9B Content-Type: multipart/mixed; boundary="wSXRp6IDnXNNDJ9kPXWIrBRwLjxu7E57X"; protected-headers="v1" From: Marc Deslauriers <marc.deslauriers@canonical.com> Reply-To: Ubuntu Security <security@ubuntu.com> To: "ubuntu-security-announce@lists.ubuntu.com" <ubuntu-security-announce@lists.ubuntu.com> Message-ID: <18286354-44c7-0d7d-ae1a-87406661bb02@canonical.com> Subject: [USN-4720-1] Apport vulnerabilities
--wSXRp6IDnXNNDJ9kPXWIrBRwLjxu7E57X Content-Type: text/plain; charset=utf-8 Content-Language: en-C Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-4720-1 February 02, 2021
apport vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Apport.
Software Description: - apport: automatically generate crash reports for debugging
Details:
Itai Greenhut discovered that Apport incorrectly parsed certain files in the /proc filesystem. A local attacker could use this issue to escalate privileges and run arbitrary code. (CVE-2021-25682, CVE-2021-25683)
Itai Greenhut discovered that Apport incorrectly handled opening certain special files. A local attacker could possibly use this issue to cause Apport to hang, resulting in a denial of service. (CVE-2021-25684)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.10: apport 2.20.11-0ubuntu50.5 python3-apport 2.20.11-0ubuntu50.5
Ubuntu 20.04 LTS: apport 2.20.11-0ubuntu27.16 python3-apport 2.20.11-0ubuntu27.16
Ubuntu 18.04 LTS: apport 2.20.9-0ubuntu7.23 python-apport 2.20.9-0ubuntu7.23 python3-apport 2.20.9-0ubuntu7.23
Ubuntu 16.04 LTS: apport 2.20.1-0ubuntu2.30 python-apport 2.20.1-0ubuntu2.30 python3-apport 2.20.1-0ubuntu2.30
In general, a standard system update will make all the necessary changes.
References: https://usn.ubuntu.com/4720-1 CVE-2021-25682, CVE-2021-25683, CVE-2021-25684
Package Information: https://launchpad.net/ubuntu/+source/apport/2.20.11-0ubuntu50.5 https://launchpad.net/ubuntu/+source/apport/2.20.11-0ubuntu27.16 https://launchpad.net/ubuntu/+source/apport/2.20.9-0ubuntu7.23 https://launchpad.net/ubuntu/+source/apport/2.20.1-0ubuntu2.30
--wSXRp6IDnXNNDJ9kPXWIrBRwLjxu7E57X--
--IUsRZivG6mBv2W9L487N9L87ZRGlBCh9B Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature"
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmAZowcACgkQZWnYVadE vpNWDg/6AvYxy4KKKfQ8ZAs476hWuFuknp9t9mK20mlHkCSBxDC0q2EDGxr9ZwPJ EVg7Mzog3STaRVb8/cE4mzhlSzb4AasP6oPwJRX7cEpj5+acFq+IRojA3PLRZSbT 72T/4XDfjuctq9xbLIOPHkUlvwXM0ryk93l/rslDFtCwbZDAG7ZH+LfNCrTBcaQ1 Ad5ZkbwfWfp+p8iAfQ+ERvwb094hvJmPzj4qNWvb3j+XdSF/zL+AUMDmjlRwdMtV kfyLr5f7Dref8ecNUm1r29+Nst/pKxFZ0rHkL49sbotB/8z2wK3DMUFx6xSjiN/A n5dRY2GZfqEtQI7HHhHqLw6W9bDkRCJTtrYNYXZozLMVcTG9LccUK5ECTQTLY7iD pjGGmViLvEPt+zyRGNOBxNyrkNfhBQ36OEZPz9HzutgY4bJJLGu2sTprsV21Xizw edJZrIr1ZX+bb2RdStzdKlyjbz0Dl9QxEc9H4HpgFgHjbUzaWYnpp8MdsU3c0OHd GgMYzsE2Zoso5tqymngaT39eQY5wsygr6sdRY/3lr84jqbOxCOgKNtY/tH4kFYMp 8TdLZ/4uQAchDGczwZZYSTpRJcTqiJT6JVSyyfl/khtzdExOatx3g3i/ChM/GYqZ s42IAYsmGSyoPvZChhwHLmycZTG8pJSxbviE5urQ1jfbQyOBa0o= =YWCk -----END PGP SIGNATURE-----
--IUsRZivG6mBv2W9L487N9L87ZRGlBCh9B--
--===============4005630193964606768== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK
--===============4005630193964606768==--
|
|
|
|