[ubuntu/xenial-updates] ubuntu-advantage-desktop-daemon 1.10.ubuntu0.16.04.1~esm1 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Wed Oct 16 17:58:12 UTC 2024
ubuntu-advantage-desktop-daemon (1.10.ubuntu0.16.04.1~esm1) xenial-security; urgency=medium
* SECURITY UPDATE: Pro client is called with attach parameter in plain text,
allowing for potentially leak of private information. (LP: #2068944)
- debian/patches/CVE-2024-6388.patch: Use a temporary file with 400
permissions instead.
https://github.com/canonical/ubuntu-advantage-desktop-daemon/pull/24/
- CVE-2024-6388
Date: 2024-10-09 00:28:10.963790+00:00
Changed-By: Chris Kim <chris.kim at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/ubuntu-advantage-desktop-daemon/1.10.ubuntu0.16.04.1~esm1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Xenial-changes
mailing list