[ubuntu/eoan-security] pulseaudio 1:13.0-1ubuntu1.2 (Accepted)
Jamie Strandboge
jamie at ubuntu.com
Tue May 12 18:07:19 UTC 2020
pulseaudio (1:13.0-1ubuntu1.2) eoan-security; urgency=medium
* SECURITY UPDATE: stop snaps from loading and unloading modules, to
prevent bypass of audio recording restriction (LP: #1877102). Patch thanks
to James Henstridge
- d/p/0407-access-Add-access-control-hooks.patch: make sure access
hook IDs are non-zero.
- d/p/0700-modules-add-snappy-policy-module.patch: Prevent snaps from
controlling modules, terminating the daemon, or disconnecting clients.
- CVE-2020-11931
* debian/control: Build-Depends on libsnapd-glib-dev (>= 1.49)
Date: 2020-05-11 20:24:14.643721+00:00
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
https://launchpad.net/ubuntu/+source/pulseaudio/1:13.0-1ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Eoan-changes
mailing list