DAViCal Andrew's Web Libraries could be made to run programs as your login if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-4539-1 September 24, 2020 awl vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: DAViCal Andrew's Web Libraries could be made to run programs as your login if it received specially crafted input. Software Description: - awl: PHP Utility Libraries Details: Andrew Bartlett discovered that DAViCal Andrew's Web Libraries (AWL) did not properly manage session keys. An attacker could possibly use this issue to impersonate a session. (CVE-2020-11728) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libawl-php 0.60-1+deb10u1ubuntu1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4539-1 CVE-2020-11728 Package Information: https://launchpad.net/ubuntu/+source/awl/0.60-1+deb10u1ubuntu1 . Ubuntu Security Announcement USN-4539-1 discusses a critical flaw concerning Ubuntu 20.04 LTS, which leads to session instability issues.. AWL Vulnerability, Session Impersonation, Ubuntu 20.04, Security Notice. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.