Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.04 LTS: USN-1561-1 Moderate Ubiquity-Slideshow Code Inject

ubuntu
Calendar Grey September 10, 2012
Scroller Ubuntu
Unforeseen document exposure may arise during Ubuntu setup linked to a bug in ubiquity-slideshow-ubuntu. Upgrade advised.
ubiquity-slideshow-ubuntu would allow unintended access to files over the network during system installation.

Summary

ubiquity-slideshow-ubuntu would allow unintended access to files over the

network during system installation.

Software Description:

- ubiquity-slideshow-ubuntu: Ubiquity slideshow for Ubuntu

Details:

Paul Mutton discovered that ubiquity-slideshow-ubuntu incorrectly handled

the Twitter feed displayed during system installation. A remote attacker

could use this flaw to inject code into the Twitter feed and read arbitrary

files off the filesystem during system installation. This flaw has been

resolved in the Ubuntu 12.04.1 LTS installation images by disabling the

Twitter feed.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  ubiquity-slideshow-ubuntu       58.2

Use of the Ubuntu 12.04.1 LTS installation images is required to resolve
this issue.

References

https://ubuntu.com/security/notices/USN-1561-1

CVE-2012-0956

September 10, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.