[ubuntu/bionic-updates] networkd-dispatcher 1.7-0ubuntu3.4 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Thu Apr 28 16:58:15 UTC 2022


networkd-dispatcher (1.7-0ubuntu3.4) bionic-security; urgency=medium

    * SECURITY UPDATE: Directory traversal
    - debian/patches/CVE-2022-29799.patch: Add allowed admin and
      operational states in networkd-dispatcher and throw exceptions in
      handle_state function if the current state is not one of those.
    - CVE-2022-29799
  * SECURITY UPDATE: Time-of-check-time-of-use race condition
    - debian/patches/CVE-2022-29800-1.patch: Add check_perms function that
      will be invoked in scripts_in_path function before appending a file
      path to the script_list in networkd-dispatcher.
    - debian/patches/CVE-2022-29800-2.patch: Passes os.path.dirname(path)
      when checking for permissions in scripts_in_path function in
      networkd-dispatcher.
    - CVE-2022-29800

Date: 2022-04-28 11:17:10.598974+00:00
Changed-By: Rodrigo Figueiredo Zaiden <rodrigo.zaiden at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/networkd-dispatcher/1.7-0ubuntu3.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list