Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

Ubuntu 23.10: USN-6556-1 moderate: Budgie Extras Access Issues

ubuntu
Calendar Grey December 14, 2023
Dist Ubuntu Esm H88
Numerous security flaws resolved in budgie-extras for Ubuntu, addressing potential access violations and data infiltration threats.
Several security issues were fixed in budgie-extras.

Summary

Several security issues were fixed in budgie-extras.

Software Description:

- budgie-extras: Applet to provide an alternative means to launch applications

Details:

It was discovered that Budgie Extras incorrectly handled certain temporary file paths.

An attacker could possibly use this issue to inject false information or deny

access to the application. (CVE-2023-49342, CVE-2023-49343, CVE-2023-49347)

Matthias Gerstner discovered that Budgie Extras incorrectly handled certain

temporary file paths. A local attacker could use this to inject arbitrary PNG

data in this path and have it displayed on the victim's desktop or deny access

to the application. (CVE-2023-49344)

Matthias Gerstner discovered that Budgie Extras incorrectly handled certain

temporary file paths. A local attacker could use this to inject false information

or deny access to the application. (CVE-2023-49345, CVE-2023-49346)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
  budgie-clockworks-applet        1.7.0-3.0ubuntu1
  budgie-dropby-applet            1.7.0-3.0ubuntu1
  budgie-previews                 1.7.0-3.0ubuntu1
  budgie-takeabreak-applet        1.7.0-3.0ubuntu1
  budgie-weathershow-applet       1.7.0-3.0ubuntu1

Ubuntu 23.04:
  budgie-clockworks-applet        1.6.0-1ubuntu0.1
  budgie-dropby-applet            1.6.0-1ubuntu0.1
  budgie-previews-applet          1.6.0-1ubuntu0.1
  budgie-takeabreak-applet        1.6.0-1ubuntu0.1
  budgie-weathershow-applet       1.6.0-1ubuntu0.1

Ubuntu 22.04 LTS:
  budgie-clockworks-applet        1.4.0-1ubuntu3.1
  budgie-dropby-applet            1.4.0-1ubuntu3.1
  budgie-previews-applet          1.4.0-1ubuntu3.1
  budgie-takeabreak-applet        1.4.0-1ubuntu3.1
  budgie-weathershow-applet       1.4.0-1ubuntu3.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6556-1

CVE-2023-49342, CVE-2023-49343, CVE-2023-49344, CVE-2023-49345,

CVE-2023-49346, CVE-2023-49347

Ubuntu Security Notice USN-6556-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here