Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Apport
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Apport
ID: USN-4965-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10, Ubuntu 21.04
Datum: Di, 25. Mai 2021, 21:35
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32550
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32553
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32556
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32555
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32554
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32547
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32551
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32548
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32549
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32552
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32557
Applikationen: Apport

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============3512594605023678696==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="qedgIiBaFK0BN86eF4AcqHeES1udWtNH2"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--qedgIiBaFK0BN86eF4AcqHeES1udWtNH2
Content-Type: multipart/mixed;
boundary="rU8POTbG9n2PjVAITk5BjzV62vJtn5y9t";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <5a6d5dc6-388b-adc9-d8ec-4a7162efc1ef@canonical.com>
Subject: [USN-4965-1] Apport vulnerabilities

--rU8POTbG9n2PjVAITk5BjzV62vJtn5y9t
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4965-1
May 25, 2021

apport vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.04
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in Apport.

Software Description:
- apport: automatically generate crash reports for debugging

Details:

Maik MÃŒnch discovered that Apport incorrectly handled certain information
gathering operations. A local attacker could use these issues to read and
write arbitrary files as an administrator, and possibly escalate
privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.04:
apport 2.20.11-0ubuntu65.1
python3-apport 2.20.11-0ubuntu65.1

Ubuntu 20.10:
apport 2.20.11-0ubuntu50.7
python3-apport 2.20.11-0ubuntu50.7

Ubuntu 20.04 LTS:
apport 2.20.11-0ubuntu27.18
python3-apport 2.20.11-0ubuntu27.18

Ubuntu 18.04 LTS:
apport 2.20.9-0ubuntu7.24
python-apport 2.20.9-0ubuntu7.24
python3-apport 2.20.9-0ubuntu7.24

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4965-1
CVE-2021-32547, CVE-2021-32548, CVE-2021-32549, CVE-2021-32550,
CVE-2021-32551, CVE-2021-32552, CVE-2021-32553, CVE-2021-32554,
CVE-2021-32555, CVE-2021-32556, CVE-2021-32557

Package Information:
https://launchpad.net/ubuntu/+source/apport/2.20.11-0ubuntu65.1
https://launchpad.net/ubuntu/+source/apport/2.20.11-0ubuntu50.7
https://launchpad.net/ubuntu/+source/apport/2.20.11-0ubuntu27.18
https://launchpad.net/ubuntu/+source/apport/2.20.9-0ubuntu7.24


--rU8POTbG9n2PjVAITk5BjzV62vJtn5y9t--

--qedgIiBaFK0BN86eF4AcqHeES1udWtNH2
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmCtPU8ACgkQZWnYVadE
vpMAkRAAo+2dy82zJHGozGP5QDHeC53TQ8tASUVujcVTrVfXiff3XxOlU1gACNU2
JM0vRaa7SFV6sryGLjTUKgNoN5KRxZlhX0NZFIpL/TuJmskZIUr0tz1YT5jzDX+r
CPlE5BR9ZnrQz+t1FmCryoLiSK7kbj8STN6sHymqn8LqVBwBrkf9MEfucFSY+oqx
U1NhtEkKKgDfsyKyBm0dbgCwgS5Y/cAiicy9EbNDCl0n/CSl60m+GWqT0q9hvy02
B/XCVTDXroxOz/Dp02dXCUJCo+d3uXaaCgWSb6hAOyXA1434hXC8TbPY9OpoOWsI
T4Nprue5A2vnLk5oioQgIlVt2aAmWbjRFtY1qIE9KFOKC3frR5i3bBH/yy7OhDfg
h3qpok/TBCsz/9xBHAbslVpNpOsLls7EEU4j03kGEYVFXTVmvwlum+vMxNnTDBab
v6IDpEB5XRb3q6gemz1pge5aYGt9hfmEHyduA0hqlwvhBePmsSoVYk9XiM+TnnIy
uFvCuukBhYeRKlwBXSd4UCh/bSLBljGXe1xVj+ZvSdbFsPZnnq108X2UkViQYOpq
rE9ITB5btkg81sNhAnsRK+qG+SmNAufeo8OGGJt2fgTTtEzYIRKUVoNvD1JEaz1q
YkA8S6/Ut5hLI0mKZWWc1WsovPuFeL5jQC9wW5WwkokAJjbJezs=
=wUpz
-----END PGP SIGNATURE-----

--qedgIiBaFK0BN86eF4AcqHeES1udWtNH2--


--===============3512594605023678696==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============3512594605023678696==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung