[ubuntu/disco-security] apport 2.20.10-0ubuntu27.1 (Accepted)
alex.murray at canonical.com
Tue Jul 9 00:03:05 UTC 2019
apport (2.20.10-0ubuntu27.1) disco-security; urgency=medium
* SECURITY UPDATE: TOCTOU issue allows local user to read arbitrary
files (LP: #1830858)
- apport/report.py: Avoid TOCTOU issue on users ignore file by
dropping privileges and then opening the file both test for access and
open the file in a single operation, instead of using access() before
reading the file which could be abused by a symlink to cause Apport to
read and embed an arbitrary file in the resulting crash dump.
Date: 2019-07-04 06:24:14.105928+00:00
Changed-By: Alex Murray <alex.murray at canonical.com>
-------------- next part --------------
Sorry, changesfile not available.
More information about the Disco-changes