Dit bericht is nog niet vertaald

[USN-572-1] apt-listchanges vulnerability

Ubuntu Security Notice USN-572-1           January 18, 2008
apt-listchanges vulnerability
CVE-2008-0302
Kwetsbare Ubuntu versies:

Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 7.04
apt-listchanges 2.72ubuntu6.1
Ubuntu 7.10
apt-listchanges 2.74ubuntu3.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

Felipe Sateler discovered that apt-listchanges did not use safe paths when importing additional Python libraries. A local attacker could exploit this and execute arbitrary commands as the user running apt-listchanges.