[ubuntu/focal-updates] multipath-tools 0.8.3-1ubuntu2.1 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Thu Nov 17 14:28:49 UTC 2022
multipath-tools (0.8.3-1ubuntu2.1) focal-security; urgency=medium
* SECURITY UPDATE: symlink attack
- debian/patches/CVE-2022-41973.patch: use /run instead of /dev/shm in
.gitignore, Makefile.inc, libmultipath/defaults.h,
multipath/Makefile, multipath/multipath.rules.in,
multipath/tmpfiles.conf.in.
- debian/multipath-tools.install, debian/multipath-udeb.install:
install tmpfiles.d/multipath.conf.
- debian/rules: copy udev rule after build.
- CVE-2022-41973
* SECURITY UPDATE: authorization bypass
- debian/patches/CVE-2022-41974.patch: ignore duplicated multipathd
command keys in multipathd/main.c, multipathd/cli.c.
- CVE-2022-41974
Date: 2022-10-31 20:47:14.620089+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/multipath-tools/0.8.3-1ubuntu2.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Focal-changes
mailing list