what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Ubuntu Security Notice 768-1

Ubuntu Security Notice 768-1
Posted Apr 29, 2009
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice USN-768-1 - Stephane Chazelas discovered that Apport did not safely remove files from its crash report directory. If Apport had been enabled at some point, a local attacker could remove arbitrary files from the system.

tags | advisory, arbitrary, local
systems | linux, ubuntu
advisories | CVE-2009-1295
SHA-256 | 8fa2e9012d04e758cf0b8c191f63010cc6620ec6d34a72a2749e3139df9d66bd

Ubuntu Security Notice 768-1

Change Mirror Download
===========================================================
Ubuntu Security Notice USN-768-1 April 29, 2009
Apport vulnerability
CVE-2009-1295
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:
apport 0.108.4

Ubuntu 8.10:
apport 0.119.2

Ubuntu 9.04:
apport 1.0-0ubuntu5.2

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

Stephane Chazelas discovered that Apport did not safely remove files from
its crash report directory. If Apport had been enabled at some point, a
local attacker could remove arbitrary files from the system.


Updated packages for Ubuntu 8.04 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_0.108.4.dsc
Size/MD5: 776 84645454e08c3f65d8c52dac74f905be
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_0.108.4.tar.gz
Size/MD5: 188833 f61510a9319ad3fd3a7903d63f8e96d9

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport-gtk_0.108.4_all.deb
Size/MD5: 55292 4bc790aa6618eecfa27e5b8222e5766f
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport-qt_0.108.4_all.deb
Size/MD5: 54048 d1ac561fe9a5c980cc4150a9939cb722
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport-retrace_0.108.4_all.deb
Size/MD5: 63690 a6b693e4cd22e222a052c0818e43eb2b
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_0.108.4_all.deb
Size/MD5: 104590 2a61c23a4fcd822dc148151e8b68c447
http://security.ubuntu.com/ubuntu/pool/main/a/apport/python-apport_0.108.4_all.deb
Size/MD5: 56970 875f5505b1e258eee1c455cfc270c7f9
http://security.ubuntu.com/ubuntu/pool/main/a/apport/python-problem-report_0.108.4_all.deb
Size/MD5: 58658 9f8dc7432955def5e5476d7332ffb725

Updated packages for Ubuntu 8.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_0.119.2.dsc
Size/MD5: 979 6c0cd091b3970e2761751e54aabed459
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_0.119.2.tar.gz
Size/MD5: 198567 8a3f6a81452f815b6755da1d024298e9

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport-gtk_0.119.2_all.deb
Size/MD5: 57796 dd4bd02f893e04497f418840d437402c
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport-qt_0.119.2_all.deb
Size/MD5: 56518 8ec6f3cdf154cd94fd93e77186beb50e
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport-retrace_0.119.2_all.deb
Size/MD5: 67036 651104a20557b07edc065157e2539b79
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_0.119.2_all.deb
Size/MD5: 107536 acaa7af80a1df3c4a87df65fbd772860
http://security.ubuntu.com/ubuntu/pool/main/a/apport/python-apport_0.119.2_all.deb
Size/MD5: 61332 9adc2a89f2ddfa53020a43db0646f713
http://security.ubuntu.com/ubuntu/pool/main/a/apport/python-problem-report_0.119.2_all.deb
Size/MD5: 61382 8db396b5045a9f5fd365572223377e57

Updated packages for Ubuntu 9.04:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_1.0-0ubuntu5.2.diff.gz
Size/MD5: 73978 1036e1541554d50a6b201cf3b9ed2e81
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_1.0-0ubuntu5.2.dsc
Size/MD5: 1236 a8f08f5b1c8e3970e65cfb705bf72de2
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_1.0.orig.tar.gz
Size/MD5: 217793 f9932601045b109fbc487b8fdca0c9fa

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport-gtk_1.0-0ubuntu5.2_all.deb
Size/MD5: 67744 3504cedc5be46644d0174438b9613aeb
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport-qt_1.0-0ubuntu5.2_all.deb
Size/MD5: 66374 f799fa04509e8cdcad100a7ca766bd32
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport-retrace_1.0-0ubuntu5.2_all.deb
Size/MD5: 74134 ea67d398ccf8f7070cbe8a2e2326ba97
http://security.ubuntu.com/ubuntu/pool/main/a/apport/apport_1.0-0ubuntu5.2_all.deb
Size/MD5: 112574 da9a0460879aee9e8ed7a229a87275db
http://security.ubuntu.com/ubuntu/pool/main/a/apport/python-apport_1.0-0ubuntu5.2_all.deb
Size/MD5: 74006 490ed42d9d5f209d5d344ffed151eb5e
http://security.ubuntu.com/ubuntu/pool/main/a/apport/python-problem-report_1.0-0ubuntu5.2_all.deb
Size/MD5: 71878 17406c34e7d0467609e22410f70864ab


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close