Login
Newsletter
Werbung

Sicherheit: Überschreiben von Dateien in GNOME Autoar
Aktuelle Meldungen Distributionen
Name: Überschreiben von Dateien in GNOME Autoar
ID: USN-4937-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10
Datum: Do, 6. Mai 2021, 23:48
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28650
Applikationen: GNOME Autoar

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============7509734178936385469==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="3ns8BsoXi3DsnO5XcLJByIJWL7k0HUOJw"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--3ns8BsoXi3DsnO5XcLJByIJWL7k0HUOJw
Content-Type: multipart/mixed;
boundary="6Rpc93j6en0wTaYu8adW8WiHugWglkN7x";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <83b23afb-8ea7-c7fd-1209-e0ec8596fbe5@canonical.com>
Subject: [USN-4937-1] GNOME Autoar vulnerability

--6Rpc93j6en0wTaYu8adW8WiHugWglkN7x
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4937-1
May 06, 2021

gnome-autoar vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

GNOME Autoar could be made to overwrite files.

Software Description:
- gnome-autoar: Archive integration support for GNOME

Details:

Ondrej Holy discovered that GNOME Autoar could extract files outside of the
intended directory. If a user were tricked into extracting a specially
crafted archive, a remote attacker could create files in arbitrary
locations, possibly leading to code execution.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
libgnome-autoar-0-0 0.2.4-2ubuntu0.3
libgnome-autoar-gtk-0-0 0.2.4-2ubuntu0.3

Ubuntu 20.04 LTS:
libgnome-autoar-0-0 0.2.3-2ubuntu0.3
libgnome-autoar-gtk-0-0 0.2.3-2ubuntu0.3

Ubuntu 18.04 LTS:
libgnome-autoar-0-0 0.2.3-1ubuntu0.3
libgnome-autoar-gtk-0-0 0.2.3-1ubuntu0.3

After a standard system update you need to restart your session to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4937-1
CVE-2021-28650

Package Information:
https://launchpad.net/ubuntu/+source/gnome-autoar/0.2.4-2ubuntu0.3
https://launchpad.net/ubuntu/+source/gnome-autoar/0.2.3-2ubuntu0.3
https://launchpad.net/ubuntu/+source/gnome-autoar/0.2.3-1ubuntu0.3


--6Rpc93j6en0wTaYu8adW8WiHugWglkN7x--

--3ns8BsoXi3DsnO5XcLJByIJWL7k0HUOJw
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmCT4gAACgkQZWnYVadE
vpNTtRAAulUpVa7rw0Eyp5J/cwY7B3LHkJBjvup3jbcmuqaVtQdYKBfESE2FXX+4
SfXyK5j4tSBRySft1uyVWq0lrWbtRnJM0VUQ+nN13eIcxMFXrDsi3GmRwcO3bZbw
LAVsOsmP2Zibd8ZUqUEb2nK1VsArdNouHYDTQjsKXFjFWQdieaKJZMpTk8pTnyHX
FpXuDCGZH3HJardThCPmtL52MT8RFejNpL7n9BAJNzi8QkdaqUe4GGGSoSm9+zdO
0Phh6+nhjlPZEZS3fsWln0zlVNJlnbd7feuGAgjgnocVjnR/vIqiWftzFx9qWYVI
dwRSNhLhHW6oG9dGoq6OzqnJzr2Zpu6smA4gmxPLtK3sgKZUn6oM+5XUc3gDsYEg
rlbDCK9PeqRjEInpPM+ymm7T0sRrosoIqHiFGF6SGSdr6KYEzpGKN9LeSLgf5s3S
0CxbJLj3ewaoz0A6BoI2ZJ6MCdZtqzYQ1uqdYFsIC1GxDBIHtjJG41jGNNy1nD/r
Ueq9pdDe0rPBLGbF/ta/nKlOfsAnX+XO1QyfetLfQiXrZnEa4g9Sy+UZnZdEQfJl
a5bg2C4CNwDDiu30wFZXx9xilNwr7IouMl14iIhzPh/uceiPrzci+igd1KJPzslt
r1Hh9pRf9UjcrK4f6ifLr0Jbhz1s4LqmuzYfxDk1szbCewwVoDI=
=CncH
-----END PGP SIGNATURE-----

--3ns8BsoXi3DsnO5XcLJByIJWL7k0HUOJw--


--===============7509734178936385469==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============7509734178936385469==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung