Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Aptdaemon.. =========================================================================Ubuntu Security Notice USN-4664-1 December 08, 2020 aptdaemon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Aptdaemon. Software Description: - aptdaemon: transaction based package management service Details: Kevin Backhouse discovered that Aptdaemon incorrectly handled certain properties. A local attacker could use this issue to test for the presence of local files. (CVE-2020-16128) Kevin Backhouse discovered that Aptdaemon incorrectly handled permission checks. A local attacker could possibly use this issue to cause a denial of service. (CVE-2020-27349) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: aptdaemon 1.1.1+bzr982-0ubuntu34.1 Ubuntu 20.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu32.3 Ubuntu 18.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu19.5 Ubuntu 16.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu14.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4664-1 CVE-2020-16128, CVE-2020-27349 Package Information: https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu34.1 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu32.3 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu19.5 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu14.5 . Ubuntu security bulletin concerning Aptdaemon vulnerabilities that may allow for local file exposure and possible denial ofservice scenarios.. Aptdaemon vulnerabilities, Ubuntu update, local file access issues. . Severity: Important. LinuxSecurity.com Team
Aptdaemon could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-4537-1 September 24, 2020 aptdaemon vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Aptdaemon could be made to expose sensitive information. Software Description: - aptdaemon: transaction based package management service Details: Vaisha Bernard discovered that Aptdaemon incorrectly handled the Locale property. A local attacker could use this issue to test for the presence of local files. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu32.2 Ubuntu 18.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu19.4 Ubuntu 16.04 LTS: aptdaemon 1.1.1+bzr982-0ubuntu14.4 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4537-1 CVE-2020-15703 Package Information: https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu32.2 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu19.4 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu14.4 . The Aptdaemon tool on Ubuntu systems may inadvertently reveal confidential data; a necessary update is advised to thwart potential local vulnerabilities.. Aptdaemon, Ubuntu Security, Local Exploit. . LinuxSecurity.com Team
Aptdaemon could be made to expose sensitive information, or allow file access as the administrator.. =========================================================================Ubuntu Security Notice USN-2648-1 June 16, 2015 aptdaemon vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Aptdaemon could be made to expose sensitive information, or allow file access as the administrator. Software Description: - aptdaemon: transaction based package management service Details: Tavis Ormandy discovered that Aptdeamon incorrectly handled the simulate dbus method. A local attacker could use this issue to possibly expose sensitive information, or perform other file access as the root user. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: aptdaemon 1.1.1+bzr982-0ubuntu3.1 Ubuntu 14.10: aptdaemon 1.1.1+bzr980-0ubuntu1.1 Ubuntu 14.04 LTS: aptdaemon 1.1.1-1ubuntu5.2 Ubuntu 12.04 LTS: aptdaemon 0.43+bzr805-0ubuntu10 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2648-1 CVE-2015-1323 Package Information: https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu3.1 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr980-0ubuntu1.1 https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1-1ubuntu5.2 https://launchpad.net/ubuntu/+source/aptdaemon/0.43+bzr805-0ubuntu10 . Aptdaemon security notice issued for Ubuntu iterations reveals confidential data or enables file reach. Immediate upgrade recommended!. Aptdaemon Vulnerability, Ubuntu Security, Sensitive Information Risk. . Severity:Critical. LinuxSecurity.com Team
Aptdaemon could be tricked into installing arbitrary PPA GPG keys.. =========================================================================Ubuntu Security Notice USN-1666-1 December 17, 2012 aptdaemon vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 Summary: Aptdaemon could be tricked into installing arbitrary PPA GPG keys. Software Description: - aptdaemon: transaction based package management service Details: It was discovered that Aptdaemon incorrectly validated PPA GPG keys when importing from a keyserver. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to install altered package repository GPG keys. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: aptdaemon 0.43+bzr805-0ubuntu7 Ubuntu 11.10: aptdaemon 0.43+bzr697-0ubuntu1.3 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1666-1 CVE-2012-0962 Package Information: https://launchpad.net/ubuntu/+source/aptdaemon/0.43+bzr805-0ubuntu7 https://launchpad.net/ubuntu/+source/aptdaemon/0.43+bzr697-0ubuntu1.3 . A vulnerability in Aptdaemon found in Ubuntu may enable the installation of any arbitrary PPA GPG keys, heightening security concerns.. Aptdaemon Vulnerability, Ubuntu Security Advisory, PPA Key Exploit, Man-in-the-Middle Attack, Package Management Risk. . Severity: Critical. LinuxSecurity.com Team
An attacker could trick Aptdaemon into installing altered packages.. =========================================================================Ubuntu Security Notice USN-1414-1 April 02, 2012 aptdaemon vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 Summary: An attacker could trick Aptdaemon into installing altered packages. Software Description: - aptdaemon: transaction based package management service Details: It was discovered that Aptdaemon incorrectly handled installing packages without performing a transaction simulation. An attacker could possibly use this flaw to install altered packages. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: python-aptdaemon 0.43+bzr697-0ubuntu1.2 Ubuntu 11.04: python-aptdaemon 0.41+bzr661-0ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1414-1 CVE-2012-0944 Package Information: https://launchpad.net/ubuntu/+source/aptdaemon/0.43+bzr697-0ubuntu1.2 https://launchpad.net/ubuntu/+source/aptdaemon/0.41+bzr661-0ubuntu0.2 . Address Aptdaemon vulnerability affecting package management in Ubuntu versions 11.10 and 11.04. Ensure your system is updated immediately.. Aptdaemon Security, Ubuntu Update, Package Management Issue. . Severity: Critical. LinuxSecurity.com Team
Sergey Nizovtsev discovered that Aptdaemon incorrectly filtered certain arguments when using its D-Bus interface. A local attacker could use this flaw to bypass security restrictions and view sensitive information by reading arbitrary files. [More...]. ==========================================================Ubuntu Security Notice USN-1068-1 February 22, 2011 aptdaemon vulnerability CVE-2011-0725 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 10.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 10.10: python-aptdaemon 0.31+bzr506-0ubuntu6.1 In general, a standard system update will make all the necessary changes. Details follow: Sergey Nizovtsev discovered that Aptdaemon incorrectly filtered certain arguments when using its D-Bus interface. A local attacker could use this flaw to bypass security restrictions and view sensitive information by reading arbitrary files. Updated packages for Ubuntu 10.10: Source archives: Size/MD5: 528226 b4bab52268bb2d5265519c41b507f465 Size/MD5: 2121 dfe8afa421c97dae75ef5401240bfcbd Size/MD5: 441337 272889c346728f050dd439b48f1041a7 Architecture independent packages: Size/MD5: 35990 318e9d8d17fc010ba43840b06bb31e8b Size/MD5: 197602 a052006f8f9addc05244a2a9f7ba8143 Size/MD5: 64802 b8a33f9e2e8c53679a2b6bfe9768bab2 . A vulnerability in Aptdaemon permits local attackers to circumvent security measures and gain access to confidential data.. Aptdaemon Vulnerabilities, Local Security Issues, Ubuntu Security Advisory, Information Disclosure. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.