========================================================================== Ubuntu Security Notice USN-4312-1 March 30, 2020 Timeshift vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 Summary: Timeshift could be made to run programs as an administrator. Software Description: - timeshift: System restore utility Details: Matthias Gerstner discovered that Timeshift did not securely create temporary files. An attacker could exploit a race condition in Timeshift and potentially execute arbitrary commands as root. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: timeshift 19.01+ds-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/4312-1 CVE-2020-10174 Package Information: https://launchpad.net/ubuntu/+source/timeshift/19.01+ds-2ubuntu0.1