=========================================================================Ubuntu Security Notice USN-4312-1
March 30, 2020

Timeshift vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.10

Summary:

Timeshift could be made to run programs as an administrator.

Software Description:
- timeshift: System restore utility

Details:

Matthias Gerstner discovered that Timeshift did not securely create temporary
files. An attacker could exploit a race condition in Timeshift and potentially
execute arbitrary commands as root.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.10:
  timeshift                       19.01+ds-2ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4312-1
  CVE-2020-10174

Package Information:
  https://launchpad.net/ubuntu/+source/timeshift/19.01+ds-2ubuntu0.1

Ubuntu 4312-1: Timeshift vulnerability

March 30, 2020
Timeshift could be made to run programs as an administrator.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: timeshift 19.01+ds-2ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4312-1

CVE-2020-10174

Severity
March 30, 2020

Package Information

https://launchpad.net/ubuntu/+source/timeshift/19.01+ds-2ubuntu0.1

Related News