Ubuntu Security Notice 3411-2 - USN-3411-1 fixed a vulnerability in Bazaar. This update provides the corresponding update for Ubuntu 12.04 ESM. A Adam Collard discovered that Bazaar did not properly handle host names A in 'bzr+ssh://' URLs. A remote attacker could use this to construct A a bazaar repository URL that when accessed could run arbitrary code A with the privileges of the user. Various other issues were also addressed.
d2232a8ccd4ab791bae18f23bd07111564d267f8de4f31375381fb47c7d63efd
==========================================================================
Ubuntu Security Notice USN-3411-2
October 24, 2017
bzr vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
Bazaar could be made run programs as your login if it opened a
specially crafted URL.
Software Description:
- bzr: easy to use distributed version control system
Details:
USN-3411-1 fixed a vulnerability in Bazaar. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
A Adam Collard discovered that Bazaar did not properly handle host names
A in 'bzr+ssh://' URLs. A remote attacker could use this to construct
A a bazaar repository URL that when accessed could run arbitrary code
A with the privileges of the user.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 ESM:
A bzrA A A A A A A A A A A A A A A A A A A A A A A A A A A A A 2.5.1-0ubuntu2.1
A python-bzrlibA A A A A A A A A A A A A A A A A A A 2.5.1-0ubuntu2.1
In general, a standard system update will make all the necessary
changes.
References:
A https://www.ubuntu.com/usn/usn-3411-2
A https://www.ubuntu.com/usn/usn-3411-1
A CVE-2017-14176