========================================================================== Ubuntu Security Notice USN-3623-1 April 09, 2018 ubuntu-release-upgrader vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: ubuntu-release-upgrader incorrectly opened as browser as an administrator. Software Description: - ubuntu-release-upgrader: manage release upgrades Details: It was discovered that ubuntu-release-upgrader did not correctly drop permissions before opening a browser to view the release notes. This update fixes the issue. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10: python3-distupgrade 1:17.10.11 Ubuntu 16.04 LTS: python3-distupgrade 1:16.04.25 Ubuntu 14.04 LTS: python3-distupgrade 1:0.220.10 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/usn/usn-3623-1 https://launchpad.net/bugs/1174007 Package Information: https://launchpad.net/ubuntu/+source/ubuntu-release-upgrader/1:17.10.11 https://launchpad.net/ubuntu/+source/ubuntu-release-upgrader/1:16.04.25 https://launchpad.net/ubuntu/+source/ubuntu-release-upgrader/1:0.220.10