-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSaWPPAAoJEGVp2FWnRL6TymQQAKylrPlPberaO0oXjbU0C2xj
VMiG0WeijeSxucQ5siYMyOLCrm23fd1SbuYDM8StrZOfr6rdIn5mroQ0BCRPBOww
pGt2dokokyPUc6GmOeZyzAQdP1ENPf2qq5y3vc3Nh2NwQmIg6r/2BLFuZ7N1DczJ
K2edPMs5RF/HWkv1QS4FbcNLGYypmX9JKElcvUakKP2ib4nXjfE3/7ZaeW7Dl6ie
4aXjggoBl4B1JjZbYSN/YpzPmrW6n+72zUVquUEQcLz2yve9VXt9YgoICzW1w7KX
hNUTAidHoqZbiJ9IFFqzq5p/8oWep4DSg3u00aAjk5Z1B+WhAt7HN4Or3siCgeqj
qhBdAAQRi0zLxoiDxLG4mTQVXTKPENPQ7VQvUwZcvdjcQJyL7F5n+W1vCBOqrh6p
8Z0IglV3dg++Q1KjJ7U5I8Vkr6IIDRH5bkQSrHwUKysI1h/SF2Osf3lRrWCAFPnR
8qov0ndNJnKWz3Or97h5/8EiZfBv6cBjJFUHay20JMAK/4+hJ0JPp0f+juqzVBnI
iDmzeObRt5p76irvz4e+GIzYv9OfC0cnGWscAzRaWe5N3IbFPa2sRyq4YvkKAUxc
ofu/uB6OOcU9qk6mDNPzs94l7T0mhK++BBpVVZO1bBfYZw546ir00G6Wg9xI6txg
Q6Q2OYvWTvTUiNHK6vOf
=caf5
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2008-1
October 24, 2013
suds vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Suds could be made to overwrite files.
Software Description:
- suds: Lightweight SOAP client for Python
Details:
Ralph Loader discovered that Suds incorrectly handled temporary files. A
local attacker could possibly use this issue to overwrite arbitrary files.
In the default installation of Ubuntu, this should be prevented by the Yama
link restrictions.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
python-suds 0.4.1-5ubuntu0.13.04.1
Ubuntu 12.10:
python-suds 0.4.1-5ubuntu0.12.10.1
Ubuntu 12.04 LTS:
python-suds 0.4.1-2ubuntu1.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2008-1
CVE-2013-2217
Package Information:
https://launchpad.net/ubuntu/+source/suds/0.4.1-5ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/suds/0.4.1-5ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/suds/0.4.1-2ubuntu1.1
No comments:
Post a Comment