You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa apt

Sigurnosni nedostatak programskog paketa apt

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4359-2
May 28, 2020

apt vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 ESM
– Ubuntu 12.04 ESM

Summary:

APT could be made to crash if it opened a specially crafted file.

Software Description:
– apt: Advanced front-end for dpkg

Details:

USN-4359-1 fixed a vulnerability in APT. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.

Original advisory details:

It was discovered that APT incorrectly handled certain filenames during
package installation. If an attacker could provide a specially crafted
package to be installed by the system administrator, this could cause APT
to crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
apt 1.0.1ubuntu2.24+esm1

Ubuntu 12.04 ESM:
apt 0.8.16~exp12ubuntu10.29

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4359-2
https://usn.ubuntu.com/4359-1
CVE-2020-3810
—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAl7QF3cACgkQRbznW4QL
H2lNsBAAqXgs0KtZjD1h31q75tXl6y1CIwOEUOD7X2J3HHSgBHOiX+qZyPaPIbCN
wW+rZQwdKofqPWFVw2Zbb5oIT9hDtWod9amGzQ0SGdOkaLE49IKurHAX1WaNiREu
UvJpeEtjrKWR4hKMKDnEgHy99SzBfqPDPHPGMO93uX9Wdo6E4rpmdRQ3cGF9HH7l
tyN/xDkFVcKRzrPUCcTm+AFFWaikq92eAxDfhuCsg1hkSllAsFzaOGYrEAlSfkeS
/8yAYe5UMkcIYt8j40AcDdQEW070gFtmAUj24WMFQosJuDeTGz3Jx7Sq0SC1Qxjz
QOvLIFaO4cw60KhsZUn1uYvURkpESeFV9UZY1L0hBI+rX23yDmH3oBBbFQN+f0bq
FohMNu4UCAasOEuZ1GGSVYEeQCIlERAsbORQ8AS0T22WfsSVBa34vINcbe4pHXWb
NZHr0WGzZpXHIjGcokULgEtZhAHuHJW7WvqHCvcCq3ombA/x8h7sMfyN6mdlljZd
4typrcGxMfpxST0WKSUk7ugzBE7noTdkCaIMYRGlAt/VAJocIdGUuiPGenHApTpL
clWPKQR3R5pbAB6xA76z03XEjw/XwrU7VxEbcyGJhn11a6B4BnODxV7PnO6z0s2p
238+YYYsbzVu3mjwb1gduZUbLa6GBjVDg51NMo0tzrTVR8moO0g=
=fTai
—–END PGP SIGNATURE—–

AutorToni Vugdelija
Cert idNCERT-REF-2020-05-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa json-c

Otkriven je sigurnosni nedostatak u programskom paketu json-c za operacijski sustav Ubuntu. Otkriveni nedostatak potencijalnim udaljenim napadačima omogućuje izvršavanje proizvoljnog...

Close