Ubuntu Advantage Desktop Daemon could be made to expose sensitive information.
Software Description:
- - ubuntu-advantage-desktop-daemon: Daemon to allow access to
ubuntu-advantage via D-Bus
Details:
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon leaked
the Pro token to unprivileged users by passing the token as an argument
in plaintext. An attacker could use this issue to gain unauthorized access
to an Ubuntu Pro subscription. (CVE-2024-6388)
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
ubuntu-advantage-desktop-daemon 1.11ubuntu0.1
Ubuntu 22.04 LTS
ubuntu-advantage-desktop-daemon 1.10.ubuntu0.22.04.2
Ubuntu 20.04 LTS
ubuntu-advantage-desktop-daemon 1.10.ubuntu0.20.04.1
Ubuntu 18.04 LTS
ubuntu-advantage-desktop-daemon 1.10.ubuntu0.18.04.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
ubuntu-advantage-desktop-daemon 1.10.ubuntu0.16.04.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.https://ubuntu.com/security/notices/USN-7063-1
CVE-2024-6388
Get the latest Linux and open source security news straight to your inbox.