WALinuxAgent could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-3907-1 March 12, 2019 walinuxagent vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: WALinuxAgent could be made to expose sensitive information. Software Description: - walinuxagent: Windows Azure Linux Agent Details: It was discovered that WALinuxAgent created swap files with incorrect permissions. A local attacker could possibly use this issue to obtain sensitive information from the swap file. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10: walinuxagent 2.2.32-0ubuntu1~18.10.2 Ubuntu 18.04 LTS: walinuxagent 2.2.32-0ubuntu1~18.04.2 Ubuntu 16.04 LTS: walinuxagent 2.2.32-0ubuntu1~16.04.2 Ubuntu 14.04 LTS: walinuxagent 2.2.32-0ubuntu1~14.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3907-1 CVE-2019-0804 Package Information: https://launchpad.net/ubuntu/+source/walinuxagent/2.2.32-0ubuntu1~18.10.2 https://launchpad.net/ubuntu/+source/walinuxagent/2.2.32-0ubuntu1~18.04.2 https://launchpad.net/ubuntu/+source/walinuxagent/2.2.32-0ubuntu1~16.04.2 https://launchpad.net/ubuntu/+source/walinuxagent/2.2.32-0ubuntu1~14.04.2 . The WALinuxAgent is susceptible to local exploits, which could lead to the leakage of confidential data. Take immediate action to update and fortify your system!. WALinuxAgent, Ubuntu Security Notice, Information Exposure, Security Update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.