=========================================================================Ubuntu Security Notice USN-4595-1
October 20, 2020

grunt vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

Grunt could be made to run programs if it received specially crafted input.

Software Description:
- grunt: JavaScript task runner/build system/maintainer tool

Details:

It was discovered that Grunt did not properly load yaml files. An
attacker could possibly use this to execute arbitrary code. (CVE-2020-7729)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  grunt                           1.0.1-8ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4595-1
  CVE-2020-7729

Package Information:
  https://launchpad.net/ubuntu/+source/grunt/1.0.1-8ubuntu0.1

Ubuntu 4595-1: Grunt vulnerability

October 20, 2020
Grunt could be made to run programs if it received specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: grunt 1.0.1-8ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4595-1

CVE-2020-7729

Severity
October 20, 2020

Package Information

https://launchpad.net/ubuntu/+source/grunt/1.0.1-8ubuntu0.1

Related News