[ubuntu/xenial-security] pulseaudio 1:8.0-0ubuntu3.15 (Accepted)
Avital Ostromich
avital.ostromich at canonical.com
Mon Nov 23 15:43:18 UTC 2020
pulseaudio (1:8.0-0ubuntu3.15) xenial-security; urgency=medium
* SECURITY UPDATE: don't rely on SCM_CREDENTIALS to detect snap confined
clients (LP: #1895928)
- d/p/0418-pa-client-peer-apparmor-label.patch: records AppArmor label
in pa_client struct for native connections using aa_getpeercon.
- d/p/0452-add-snappy-policy-module.patch: use the AppArmor
label in the pa_client rather than looking it up via the process ID
from SCM_CREDENTIALS.
- CVE-2020-16123
* Don't block classic snaps from module loading/unloading (LP: #1886854)
- d/p/0452-add-snappy-policy-module.patch: replace
deny_to_snaps_hook with a version that allows classic snaps.
Date: 2020-11-19 16:22:15.523502+00:00
Changed-By: James Henstridge <james.henstridge at canonical.com>
Signed-By: Avital Ostromich <avital.ostromich at canonical.com>
https://launchpad.net/ubuntu/+source/pulseaudio/1:8.0-0ubuntu3.15
-------------- next part --------------
Sorry, changesfile not available.
More information about the Xenial-changes
mailing list