Ubuntu Security Notice USN-3816-1

Discussion in 'News Aggregator' started by Packet Storm, 13 Nov 2018.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3816-1 - Jann Horn discovered that unit_deserialize incorrectly handled status messages above a certain length. A local attacker could potentially exploit this via NotifyAccess to inject arbitrary state across re-execution and obtain root privileges. Jann Horn discovered a race condition in chown_one. A local attacker could potentially exploit this by setting arbitrary permissions on certain files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...