Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 12.04 ESM: USN-3411-2 Moderate: Bazaar Remote Code Execution

Ubuntu Large Esm H500
Bazaar could be made run programs as your login if it opened a specially crafted URL.
=========================================================================Ubuntu Security Notice USN-3411-2
October 24, 2017

bzr vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Bazaar could be made run programs as your login if it opened a
specially crafted URL.

Software Description:
- bzr: easy to use distributed version control system

Details:

USN-3411-1 fixed a vulnerability in Bazaar. This update
provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Adam Collard discovered that Bazaar did not properly handle host names
 in 'bzr+ssh://' URLs. A remote attacker could use this to construct
 a bazaar repository URL that when accessed could run arbitrary code
 with the privileges of the user.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  bzr                             2.5.1-0ubuntu2.1
  python-bzrlib                   2.5.1-0ubuntu2.1

In general, a standard system update will make all the necessary
changes.

References:
  https://ubuntu.com/security/notices/USN-3411-2
  https://ubuntu.com/security/notices/USN-3411-1
  CVE-2017-14176

Ubuntu 12.04 ESM: USN-3411-2 Moderate: Bazaar Remote Code Execution

ubuntu
Calendar Grey October 24, 2017
Dist Ubuntu Esm H88
A security flaw in the Bazaar system permits execution of unapproved applications on Ubuntu platforms. Make sure to install updates to resolve the vulnerability.
Bazaar could be made run programs as your login if it opened a specially crafted URL.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM:   bzr                             2.5.1-0ubuntu2.1   python-bzrlib                   2.5.1-0ubuntu2.1 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3411-2

  https://ubuntu.com/security/notices/USN-3411-1

  CVE-2017-14176

October 24, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here