USN-7064-2: nano vulnerability
USN-7064-1 fixed a vulnerability in nano. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: It was discovered that nano allowed a possible privilege escalation through an insecure temporary file. If nano was killed while editing, the permissions granted to the emergency save file could be used by an attacker to escalate privileges using a malicious symlink.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7064-2?
The severity of USN-7064-2 relates to a privilege escalation vulnerability in the nano text editor.
How do I fix USN-7064-2?
To fix USN-7064-2, ensure that you update nano to version 2.2.6-1ubuntu1+esm1 on Ubuntu 14.04 LTS.
Which Ubuntu versions are affected by USN-7064-2?
USN-7064-2 specifically affects Ubuntu 14.04 LTS.
What vulnerability does USN-7064-2 address?
USN-7064-2 addresses a privilege escalation vulnerability caused by insecure temporary file handling in nano.
Is it safe to use nano after the USN-7064-2 update?
Yes, after applying the USN-7064-2 update, using nano should be safe as it mitigates the reported vulnerability.