Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 12.04 ESM: USN-3411-2 Moderate: Bazaar Remote Code Execution

ubuntu
Calendar Grey October 24, 2017
Scroller Ubuntu
A security flaw in the Bazaar system permits execution of unapproved applications on Ubuntu platforms. Make sure to install updates to resolve the vulnerability.
Bazaar could be made run programs as your login if it opened a specially crafted URL.

Summary

Bazaar could be made run programs as your login if it opened a

specially crafted URL.

Software Description:

- bzr: easy to use distributed version control system

Details:

USN-3411-1 fixed a vulnerability in Bazaar. This update

provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Adam Collard discovered that Bazaar did not properly handle host names

 in 'bzr+ssh://' URLs. A remote attacker could use this to construct

 a bazaar repository URL that when accessed could run arbitrary code

 with the privileges of the user.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  bzr                             2.5.1-0ubuntu2.1
  python-bzrlib                   2.5.1-0ubuntu2.1

In general, a standard system update will make all the necessary
changes.

References

  https://ubuntu.com/security/notices/USN-3411-2

  https://ubuntu.com/security/notices/USN-3411-1

  CVE-2017-14176

October 24, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.