Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 11.10: 1284-1 Critical Update Manager File Overwrite Risk

ubuntu
Calendar Grey November 28, 2011
Scroller Ubuntu
Severe flaws found in Ubuntu's Software Updater could lead to unauthorized file replacements and security breaches. Upgrade immediately!
Update Manager could be made to overwrite files as the administrator.

Summary

Update Manager could be made to overwrite files as the administrator.

Software Description:

- update-manager: GNOME application that manages apt updates

- update-notifier: Daemon which notifies about package updates

Details:

David Black discovered that Update Manager incorrectly extracted the

downloaded upgrade tarball before verifying its GPG signature. If a remote

attacker were able to perform a man-in-the-middle attack, this flaw could

potentially be used to replace arbitrary files. (CVE-2011-3152)

David Black discovered that Update Manager created a temporary directory

in an insecure fashion. A local attacker could possibly use this flaw to

read the XAUTHORITY file of the user performing the upgrade.

(CVE-2011-3154)

This update also adds a hotfix to Update Notifier to handle cases where the

upgrade is being performed from CD media.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  update-manager                  1:0.152.25.5

Ubuntu 11.04:
  update-manager                  1:0.150.5.1
  update-notifier                 0.111ubuntu2.1

Ubuntu 10.10:
  update-manager                  1:0.142.23.1
  update-notifier                 0.105ubuntu1.1

Ubuntu 10.04 LTS:
  auto-upgrade-tester             1:0.134.11.1
  update-notifier                 0.99.3ubuntu0.1

Ubuntu 8.04 LTS:
  update-manager                  1:0.87.31.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1284-1

CVE-2011-3152, CVE-2011-3154

Severity
critical
Lowest
Low
Medium
High
Critical

November 28, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.