An attacker could trick unattended-upgrades into installing altered packages.. =========================================================================Ubuntu Security Notice USN-2657-1 June 29, 2015 unattended-upgrades vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: An attacker could trick unattended-upgrades into installing altered packages. Software Description: - unattended-upgrades: automatic installation of security upgrades Details: It was discovered that unattended-upgrades incorrectly performed authentication checks in certain configurations. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: unattended-upgrades 0.83.6ubuntu1 Ubuntu 14.10: unattended-upgrades 0.82.8ubuntu0.3 Ubuntu 14.04 LTS: unattended-upgrades 0.82.1ubuntu2.3 Ubuntu 12.04 LTS: unattended-upgrades 0.76ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2657-1 CVE-2015-1330 Package Information: https://launchpad.net/ubuntu/+source/unattended-upgrades/0.83.6ubuntu1 https://launchpad.net/ubuntu/+source/unattended-upgrades/0.82.8ubuntu0.3 https://launchpad.net/ubuntu/+source/unattended-upgrades/0.82.1ubuntu2.3 https://launchpad.net/ubuntu/+source/unattended-upgrades/0.76ubuntu1.1 . Ubuntu Security Notice USN-2568-1 draws attention to a critical vulnerability in the unattended-upgrades system that could result in unauthorized package modifications.. Unattended Upgrades Security, Ubuntu 15.04 Flaw, Package Installation Risk. .LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.