security advisorycritical issuedebian
A flaw was found in usbguard, an USB device authorization policy framework. When using the usbguard-dbus daemon an unprivileged user could make USBGuard allow all USB devices to be connected in the future. . -------------------------------------------------------------------------Debian LTS Advisory DLA-2979-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany April 11, 2022 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : usbguard Version : 0.6.2+ds1-2+deb9u1 CVE ID : CVE-2019-25058 Debian Bug : 1008026 A flaw was found in usbguard, an USB device authorization policy framework. When using the usbguard-dbus daemon an unprivileged user could make USBGuard allow all USB devices to be connected in the future. For Debian 9 stretch, this problem has been fixed in version 0.6.2+ds1-2+deb9u1. We recommend that you upgrade your usbguard packages. For the detailed security status of usbguard please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/usbguard Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . In light of a vulnerability identified in usbguard, this notice advises users to perform an upgrade to enhance the protection of USB device connections.. Debian LTS, Usbguard Update, Security Advisory, Device Management. . Severity: Important. LinuxSecurity.com Team
Apr 11, 2022
•Important
Debian LTS