[Bug 1617617] [NEW] Firewall configuration can be modified by any logged in user

Launchpad Bug Tracker 1617617 at bugs.launchpad.net
Thu Oct 26 01:49:39 UTC 2017


*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Lucas Kocia (lkocia):

Copying from the Debian bug:

---
The following vulnerability was published for firewalld.

CVE-2016-5410[0]:
Firewall configuration can be modified by any logged in user

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2016-5410
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1360135
[2] http://seclists.org/oss-sec/2016/q3/291
[3] https://github.com/t-woerner/firewalld/commit/0371995a58ec4c777960007b7dbee93933f760cb
---

This only affects firewalld >= 0.3.12 & < 0.4.3.3 (so trusty is not
affected).

** Affects: firewalld (Ubuntu)
     Importance: Low
         Status: Fix Released

** Affects: firewalld (Ubuntu Xenial)
     Importance: Low
         Status: Fix Released

** Affects: firewalld (Debian)
     Importance: Unknown
         Status: Fix Released

-- 
Firewall configuration can be modified by any logged in user
https://bugs.launchpad.net/bugs/1617617
You received this bug notification because you are a member of Ubuntu Sponsors Team, which is subscribed to the bug report.



More information about the Ubuntu-sponsors mailing list