-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/
iQIcBAEBCgAGBQJSC9NNAAoJEGVp2FWnRL6ThdgP/igbWWGXgjNwGBR2avlvsg8l
sXM90+HmRueqcMXch17vTlFFH47ZPoRiQrJkAsPuMQwji/CedGV3gMuYejYITH6J
dLI4+oRqP1f8GtRvz2NxV8hPZKeeBO1nBLKAkRMR7dQnLpf/Vzw6otXh4nE5VAXB
d6cWG+KBGe8ikugA9M8cvZ4Of8PZBukGGrFDJfEyzdrPf2s188cYQa5CH5AvMHTv
w67NQ3scI/JyY8WC3mh3joDkLBGAIfJDEQWYhi2ZbGL2/1rebnyxiWq3Pf0NwF2L
pafRxz95kowBAZMDvwXYQI1KhZ67mSsm/7xCWecTy5qykmUvShYzYFpwgNbznz+k
vTbSGoz7eiI3SkunegultXjz8CpopHM/Ob98f3tsAd27SFPoHbG4h4nsTTG9BqfS
RW8+VNnZpjE14vc2ZLPyWBLj8Gq9Eagto9l4fr4KdBwXpHX0EwLwNbwtDJ7mnVyA
etGKR3MgoYV6IjB6rQ/Isc0tL/MEdgV5iSBGImPGXEKi4y/CEINzJ3jJigl67FNe
bk6jNco3Qy7GNB8dk2TxncPdsTHxrsHQiPnr+xodd3HxxEZLAg4Kg1+k5mVKwcfm
CLWJRyja3tToDvC/9cdDqYWweo0A0EVauGmlkFG52XZW1ShsYFmqKF/MjQP4+fOP
+e+vObQXtNyCOaTgb3/N
=oIU+
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1927-1
August 14, 2013
libimobiledevice vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
Summary:
libimobiledevice could be made to overwrite files as the administrator, or
access device keys.
Software Description:
- libimobiledevice: Library for communicating with iPhone and iPod Touch devices
Details:
Paul Collins discovered that libimobiledevice incorrectly handled temporary
files. A local attacker could possibly use this issue to overwrite
arbitrary files and access device keys. In the default Ubuntu installation,
this issue should be mitigated by the Yama link restrictions.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
libimobiledevice3 1.1.4-1ubuntu6.2
Ubuntu 12.10:
libimobiledevice3 1.1.4-1ubuntu3.2
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1927-1
CVE-2013-2142
Package Information:
https://launchpad.net/ubuntu/+source/libimobiledevice/1.1.4-1ubuntu6.2
https://launchpad.net/ubuntu/+source/libimobiledevice/1.1.4-1ubuntu3.2
No comments:
Post a Comment