First published: Tue Jul 09 2019(Updated: )
USN-4051-1 fixed a vulnerability in apport. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Kevin Backhouse discovered a race-condition when reading the user's local Apport configuration. This could be used by a local attacker to cause Apport to include arbitrary files in a resulting crash report.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python-apport | <2.14.1-0ubuntu3.29+esm1 | 2.14.1-0ubuntu3.29+esm1 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/python3-apport | <2.14.1-0ubuntu3.29+esm1 | 2.14.1-0ubuntu3.29+esm1 |
Ubuntu OpenSSH Client | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-4051-2 addresses a race condition vulnerability that could allow a local attacker to exploit the user's Apport configuration.
To fix USN-4051-2, upgrade the python-apport and python3-apport packages to version 2.14.1-0ubuntu3.29+esm1 on Ubuntu 14.04.
USN-4051-2 particularly affects Ubuntu 14.04 systems that have the python-apport and python3-apport packages installed.
The vulnerability in USN-4051-2 was discovered by researcher Kevin Backhouse.
No, USN-4051-2 is specifically relevant only to Ubuntu 14.04 ESM.