[ubuntu/xenial-updates] ubuntu-advantage-desktop-daemon 1.10.ubuntu0.16.04.1~esm1 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Wed Oct 16 17:58:12 UTC 2024


ubuntu-advantage-desktop-daemon (1.10.ubuntu0.16.04.1~esm1) xenial-security; urgency=medium

  * SECURITY UPDATE: Pro client is called with attach parameter in plain text,
    allowing for potentially leak of private information. (LP: #2068944)
    - debian/patches/CVE-2024-6388.patch: Use a temporary file with 400
      permissions instead. 
      https://github.com/canonical/ubuntu-advantage-desktop-daemon/pull/24/
    - CVE-2024-6388

Date: 2024-10-09 00:28:10.963790+00:00
Changed-By: Chris Kim <chris.kim at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/ubuntu-advantage-desktop-daemon/1.10.ubuntu0.16.04.1~esm1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list