tmpreaper could be made to overwrite files as the administrator.. =========================================================================Ubuntu Security Notice USN-4077-1 July 29, 2019 tmpreaper vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: tmpreaper could be made to overwrite files as the administrator. Software Description: - tmpreaper: cleans up files in directories based on their age Details: It was discovered that tmpreaper incorrectly handled certain mount operations. A local attacker could possibly use this issue to create arbitrary files, leading to privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: tmpreaper 1.6.13+nmu1+deb9u1build0.18.04.1 Ubuntu 16.04 LTS: tmpreaper 1.6.13+nmu1+deb9u1build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4077-1 CVE-2019-3461 Package Information: https://launchpad.net/ubuntu/+source/tmpreaper/1.6.13+nmu1+deb9u1build0.18.04.1 https://launchpad.net/ubuntu/+source/tmpreaper/1.6.13+nmu1+deb9u1build0.16.04.1 . Ubuntu Security Advisory USN-4078-2 highlights vulnerabilities in tmpwatch which could lead to data loss and unauthorized access problems.. tmpreaper security, ubuntu tmpreaper update, file overwrite issue, privilege escalation vulnerability. . Severity: Critical. LinuxSecurity.com Team
It was discovered that tmpreaper, a program that cleans up files in directories based on their age, is vulnerable to a race condition. This vulnerability might be exploited by local attackers to perform privilege escalation. . Package : tmpreaper Version : 1.6.13+nmu1+deb8u1 CVE ID : CVE-2019-3461 Debian Bug : 918956 It was discovered that tmpreaper, a program that cleans up files in directories based on their age, is vulnerable to a race condition. This vulnerability might be exploited by local attackers to perform privilege escalation. For Debian 8 "Jessie", this problem has been fixed in version 1.6.13+nmu1+deb8u1. We recommend that you upgrade your tmpreaper packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . tmpreaper release 1.6.13+nmu1+deb8u1 has been modified to address potential privilege elevation vulnerabilities arising from race conditions.. tmpreaper security, Debian update, race condition threat, privilege escalation fix. . LinuxSecurity.com Team
Stephen Roettger discovered a race condition in tmpreaper, a program that cleans up files in directories based on their age, which could result in local privilege escalation. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4365-1
Get the latest Linux and open source security news straight to your inbox.