First published: Thu Apr 23 2015(Updated: )
Tavis Ormandy discovered that usb-creator was missing an authentication check. A local attacker could use this issue to gain elevated privileges.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/usb-creator-common | <0.2.62ubuntu0.3 | 0.2.62ubuntu0.3 |
Ubuntu gir1.2-packagekitglib-1.0 | =14.10 | |
All of | ||
ubuntu/usb-creator-common | <0.2.56.3ubuntu0.1 | 0.2.56.3ubuntu0.1 |
Ubuntu gir1.2-packagekitglib-1.0 | =14.04 | |
All of | ||
ubuntu/usb-creator-common | <0.2.38.3ubuntu0.1 | 0.2.38.3ubuntu0.1 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-2576-1 is classified as high due to the potential for local privilege escalation.
To fix USN-2576-1, upgrade the usb-creator-common package to the recommended version specific to your Ubuntu release.
USN-2576-1 affects Ubuntu versions 14.10, 14.04, and 12.04 with specific versions of usb-creator-common.
The vulnerability in USN-2576-1 was discovered by Tavis Ormandy.
A local attacker could exploit USN-2576-1 to gain elevated privileges on the affected systems.