Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Ubuntu 2576-2 Critical: usb-creator Privilege Escalation Risk

Ubuntu Large Esm H500
usb-creator could be tricked into running programs as an administrator.
=========================================================================Ubuntu Security Notice USN-2576-2
April 23, 2015

usb-creator vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:


Summary:

usb-creator could be tricked into running programs as an administrator.

Software Description:

Details:

USN-2576-1 fixed a vulnerability in usb-creator. This update provides the
corresponding fix for Ubuntu 15.04.

Original advisory details:

 Tavis Ormandy discovered that usb-creator was missing an authentication
 check. A local attacker could use this issue to gain elevated privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2576-2
  https://ubuntu.com/security/notices/USN-2576-1
  https://bugs.launchpad.net/ubuntu/+source/usb-creator/+bug/1447396

Package Information:


Ubuntu 2576-2 Critical: usb-creator Privilege Escalation Risk

ubuntu
Calendar Grey April 23, 2015
Dist Ubuntu Esm H88
Critical security flaw in usb-creator impacts Ubuntu versions; update needed for protection.
usb-creator could be tricked into running programs as an administrator.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2576-2

https://ubuntu.com/security/notices/USN-2576-1

https://bugs.launchpad.net/ubuntu/+source/usb-creator/+bug/1447396

Severity
critical
Lowest
Low
Medium
High
Critical

April 23, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here