=========================================================================Ubuntu Security Notice USN-4457-2
August 17, 2020

software-properties vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM

Summary:

Software Properties could be made to manipulate the display.

Software Description:
- software-properties: manage the repositories that you install software from

Details:

USN-4457-1 fixed a vulnerability in Software. This update provides
the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

 Jason A. Donenfeld discovered that Software Properties incorrectly filtered
 certain escape sequences when displaying PPA descriptions. If a user were
 tricked into adding an arbitrary PPA, a remote attacker could possibly
 manipulate the screen.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
  python-software-properties      0.92.37.8ubuntu0.1~esm1
  python3-software-properties     0.92.37.8ubuntu0.1~esm1
  software-properties-common      0.92.37.8ubuntu0.1~esm1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4457-2
  https://ubuntu.com/security/notices/USN-4457-1
  CVE-2020-15709

Ubuntu 4457-2: Software Properties vulnerability

August 17, 2020
Software Properties could be made to manipulate the display.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: python-software-properties 0.92.37.8ubuntu0.1~esm1 python3-software-properties 0.92.37.8ubuntu0.1~esm1 software-properties-common 0.92.37.8ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4457-2

https://ubuntu.com/security/notices/USN-4457-1

CVE-2020-15709

Severity
August 17, 2020

Package Information

Related News