Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in Flatpak
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in Flatpak
ID: USN-4951-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10
Datum: Mi, 12. Mai 2021, 08:15
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21381
Applikationen: Flatpak

Originalnachricht


--===============4164376682679923669==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="niXOLaNNN0dUqxao"
Content-Disposition: inline


--niXOLaNNN0dUqxao
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4951-1
May 12, 2021

flatpak vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

A Flatpak application could access files that it would not normally
be permitted to access.

Software Description:
- flatpak: Application deployment framework for desktop apps

Details:

Anton Lydike discovered that Flatpak did not properly handle special tokens
in desktop files. An attacker could use this to specially craft a Flatpak
application that could escape sandbox confinement.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
flatpak 1.8.2-1ubuntu0.2
libflatpak0 1.8.2-1ubuntu0.2

Ubuntu 20.04 LTS:
flatpak 1.6.5-0ubuntu0.3
libflatpak0 1.6.5-0ubuntu0.3

Ubuntu 18.04 LTS:
flatpak 1.0.9-0ubuntu0.3
libflatpak0 1.0.9-0ubuntu0.3

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4951-1
CVE-2021-21381

Package Information:
https://launchpad.net/ubuntu/+source/flatpak/1.8.2-1ubuntu0.2
https://launchpad.net/ubuntu/+source/flatpak/1.6.5-0ubuntu0.3
https://launchpad.net/ubuntu/+source/flatpak/1.0.9-0ubuntu0.3


--niXOLaNNN0dUqxao
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAmCbZhUACgkQLwmejQBe
gfRJchAAkIIbqZJtr0LQIhiq23i+kRo7pDE99/czqMiSljZt0YARsYltZgXQpUdc
n1Fm+VZZSwl2Q03mnk4SVD6/mavFAxvZUz/M4E1FIFgSxJgivKCdwzYXevmu4nR8
wDoWZ9nqqM0geMsy39AzRBJv054J/khP2J6JJ5/IS2nggEs96QKNVkG445fCaXRn
tbu306fabtYE1ah9k3j0OEJZVgNLuJzHg2Sr/np4TeX2d7Wjz8fDw4Ao3RJ1ndDO
Bdn3UOIlDIDdwmmh7mtJ6Zjx1AsapIfnA9AKJEysYcI+TIxT4uXtP0S7BJPviyVE
3iJZSTAMu2XH0u3s/VcAQwKgha5DMaGo92w5/BRwaoylWgJUj7RMoKocTTSHVMKX
Chpcpw7avxQMuzGJSHdG1HNxCUXkDD8JKV86xiMLy5i0umk1vS0Rl5YZItMeOcgC
JGf2GqluU/iwadMao9xmRQQKb9wr2m1e2YZgjImwAZKjRt2WrQR6b8lB8FV04NdT
8h45Sc2JPe7HmCM7Rqsqk3AzgPg6geriK6aPsiLOEWw6rBwAJb8PjC+rKq04G7XX
wQ4FUFni6l+v3pb79aqVKhmOvY/IipFXIFD1OqD9ELzjK+1/F+hqgGDbx1OSm72s
AeaT/4gsfvpN/AnpttpwLo/yJ9Aw/63stosuo5rl/OAn1juiux8=
=p+vS
-----END PGP SIGNATURE-----

--niXOLaNNN0dUqxao--


--===============4164376682679923669==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung