You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa whoopsie

Sigurnosni nedostatak programskog paketa whoopsie

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4170-1
October 30, 2019

whoopsie vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.10
– Ubuntu 19.04
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

Whoopsie could be made to crash, expose sensitive information or run
programs if it processed a specially crafted crash report.

Software Description:
– whoopsie: Ubuntu error tracker submission

Details:

Kevin Backhouse discovered Whoopsie incorrectly handled very large crash
reports. A local attacker could possibly use this issue to cause a denial
of service, expose sensitive information or execute code as the whoopsie
user.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.10:
libwhoopsie0 0.2.66ubuntu0.1
whoopsie 0.2.66ubuntu0.1

Ubuntu 19.04:
libwhoopsie0 0.2.64ubuntu0.2
whoopsie 0.2.64ubuntu0.2

Ubuntu 18.04 LTS:
libwhoopsie0 0.2.62ubuntu0.2
whoopsie 0.2.62ubuntu0.2

Ubuntu 16.04 LTS:
libwhoopsie0 0.2.52.5ubuntu0.2
whoopsie 0.2.52.5ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4170-1
CVE-2019-11484

Package Information:
https://launchpad.net/ubuntu/+source/whoopsie/0.2.66ubuntu0.1
https://launchpad.net/ubuntu/+source/whoopsie/0.2.64ubuntu0.2
https://launchpad.net/ubuntu/+source/whoopsie/0.2.62ubuntu0.2
https://launchpad.net/ubuntu/+source/whoopsie/0.2.52.5ubuntu0.2
—–BEGIN PGP SIGNATURE—–

iQEzBAEBCgAdFiEEiOlTC8vdwgBRe16w9JjS2d59rZwFAl25FVcACgkQ9JjS2d59
rZwlHgf/ZlE9Nf3S4EuadLGChMp13vd3vFZ/bsC65ASk2xfiqjLXBi97WyDqEaS8
Xd5FnezzC2ilrx4Lhb0A1aa5XIuMnZgNfZH0HBwI5nuWmef62FG6K4PIn8o4x1wn
mIwbT3Nc8G65838F0O0BBgb/7kd8ojjG5pQ+YLef7Lpv8IdtAvBT6+qjNOzIdNGJ
hLrM64ojRT2vLIjU9B/oRAuvqgd0tat/ECqh0a4e8iszw5q2RZegRbblc6t/8KQ4
Gqh5sHvYh1s2jhh1lWMpYGuYC7ZS3zlGFRfDfQQG5NlaWJi29zqUkZKFivkp33k1
JAQNK7bfP+E6qcYF0htsHgyuT2HxKA==
=297T
—–END PGP SIGNATURE——-

AutorToni Vugdelija
Cert idNCERT-REF-2019-10-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programske biblioteke libarchive

Otkriven je sigurnosni nedostatak programske biblioteke libarchive za operacijski sustav Ubuntu. Otkriveni nedostatak potencijalnim udaljenim napadačima omogućuje izazivanje DoS stanja...

Close