[ubuntu/yakkety-updates] flatpak 0.6.11-1ubuntu0.16.10.0 (Accepted)
Ubuntu Archive Robot
cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Fri Feb 10 01:58:15 UTC 2017
flatpak (0.6.11-1ubuntu0.16.10.0) yakkety-security; urgency=medium
* SECURITY UPDATE: bubblewrap escape via TIOCSTI ioctl (LP: #1657357)
- Fixed in d/p/Use-seccomp-to-filter-out-TIOCSTI-ioctl.patch:
Add patch from upstream 0.8.1 to prevent contained apps from using
TIOCSTI ioctl. This would let the app inject commands into the
terminal from which it was invoked. Prevent the attack here
by using seccomp to filter out TIOCSTI ioctl.
- CVE-2017-5226
* SECURITY UPDATE: Prevent writing to per-user installed fonts and
Flatpak extensions (typically locales)
- Fixed in d/p/Make-sure-all-mounted-sources-are-read-only.patch:
Add patch from upstream 0.8.2
Date: 2017-02-07 07:15:14.548555+00:00
Changed-By: Jeremy Bicha <jeremy at bicha.net>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/flatpak/0.6.11-1ubuntu0.16.10.0
-------------- next part --------------
Sorry, changesfile not available.
More information about the Yakkety-changes
mailing list