[ubuntu/saucy-proposed] software-properties 0.92.26 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Wed Sep 18 17:57:11 UTC 2013


software-properties (0.92.26) saucy; urgency=low

  * SECURITY UPDATE: possible privilege escalation via policykit UID lookup
    race.
    - softwareproperties/dbus/SoftwarePropertiesDBus.py: pass
      system-bus-name as a subject instead of pid so policykit can get the
      information from the system bus.
    - CVE-2013-1061

Date: Wed, 18 Sep 2013 13:17:35 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Michael Vogt <michael.vogt at ubuntu.com>
https://launchpad.net/ubuntu/saucy/+source/software-properties/0.92.26
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 18 Sep 2013 13:17:35 -0400
Source: software-properties
Binary: python-software-properties python3-software-properties software-properties-common software-properties-gtk software-properties-kde
Architecture: source
Version: 0.92.26
Distribution: saucy
Urgency: low
Maintainer: Michael Vogt <michael.vogt at ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 python-software-properties - manage the repositories that you install software from
 python3-software-properties - manage the repositories that you install software from
 software-properties-common - manage the repositories that you install software from (common)
 software-properties-gtk - manage the repositories that you install software from (gtk)
 software-properties-kde - manage the repositories that you install software from (kde)
Changes: 
 software-properties (0.92.26) saucy; urgency=low
 .
   * SECURITY UPDATE: possible privilege escalation via policykit UID lookup
     race.
     - softwareproperties/dbus/SoftwarePropertiesDBus.py: pass
       system-bus-name as a subject instead of pid so policykit can get the
       information from the system bus.
     - CVE-2013-1061
Checksums-Sha1: 
 d7f248a7f41ed2430c2aeba540328b09c612b543 2061 software-properties_0.92.26.dsc
 4a21524b6f0033b442e1c57ec5e8122883e04ace 759657 software-properties_0.92.26.tar.gz
Checksums-Sha256: 
 b14d8b3889154d5cdae0abf2dad379121380b5523d8889feda2f3206d830705c 2061 software-properties_0.92.26.dsc
 28e9ceffdf4b6c86d2f609032b03b770d45c7045345493eef17a9dd796c4330e 759657 software-properties_0.92.26.tar.gz
Files: 
 f7ecb5907a7e3a685dc365cbc94b066e 2061 admin optional software-properties_0.92.26.dsc
 6816a0e1f2baeceb5f3dac5b2e7a05fb 759657 admin optional software-properties_0.92.26.tar.gz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)

iQIcBAEBCgAGBQJSOeLeAAoJEGVp2FWnRL6TlukP/AqtlAKcLsGneG+HkNXc1WIU
zPS/2bXKluw/HfoCVkGHPKqUnKBHOPxCeV8vXdLFvPJw9hTcq1KPVmB26Plp0pJZ
/aVnYCWWNczKN4ep49UmslNnFPKfsxdlP1NAsM6g7CkXkrw4EGtZBPVaXS/hqA8/
5XwrB9/u7Orm2w8kJX/sLd4qg9P4FdFXyStIxAXPePx1iKqry+4dbuzEAEIoaSek
uCzjt0SnP3HBkSXdG6mYXOdjCYXUjSuFIzk2JjkrM6hk/5ikwrD326zUiMDQoAWv
dQcopC3EYX7mUb5xb3A8+ZCWSJxX9l88e6BcbXAVqUv09BTC6e5LY3wcTR/cKQZM
SYMZT3gBNoDXWta8BgEQA+f4fmW1o6cK36mH7A/dRpgnu3L/MD7aXUGQUy9QmP9x
YZ4UvLCPOwEz36hoZDh0SypfrwiQvhMjLjxTIL0wUUJfA4el5x2ydHTwtW56N9Oe
0Meh38xLQ75OJyCmYgoeXaz+6suXZyWDHrv6EZn1rzWKHij8Gdhy4xmxd0fZSXF4
V9+Pq1m74L+3vJN7jeHI4vcd1UedglQIzBwlQPh5DVA7FrAJvY+fdWtM8kL83sv+
dftudl+vTcK8de1XxTu84ND+FwojUA4E51UN1rMHwrkwmCEwSZyY5lemg3K3rYW3
LbT+Xn1PQGErBe3JpiUv
=QYJx
-----END PGP SIGNATURE-----


More information about the Saucy-changes mailing list