-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
===========================================================================
AUSCERT External Security Bulletin Redistribution
ESB-2020.2791.2
USN-4457-1 and -2: Software Properties vulnerability
18 August 2020
===========================================================================
AusCERT Security Bulletin Summary
---------------------------------
Product: Software Properties
Publisher: Ubuntu
Operating System: Ubuntu
Impact/Access: Provide Misleading Information -- Existing Account
Resolution: Patch/Upgrade
CVE Names: CVE-2020-15709
Original Bulletin:
https://usn.ubuntu.com/4457-1/
https://usn.ubuntu.com/4457-2/
Comment: This bulletin contains two (2) Ubuntu security advisories.
Revision History: August 18 2020: Added USN-4457-2 for Ubuntu 14.04 ESM
August 13 2020: Initial Release
- --------------------------BEGIN INCLUDED TEXT--------------------
USN-4457-1: Software Properties vulnerability
12 August 2020
Software Properties could be made to manipulate the display.
Releases
o Ubuntu 20.04 LTS
o Ubuntu 18.04 LTS
o Ubuntu 16.04 LTS
Packages
o software-properties - manage the repositories that you install software
from
Details
Jason A. Donenfeld discovered that Software Properties incorrectly filtered
certain escape sequences when displaying PPA descriptions. If a user were
tricked into adding an arbitrary PPA, a remote attacker could possibly
manipulate the screen.
Update instructions
The problem can be corrected by updating your system to the following package
versions:
Ubuntu 20.04
o python3-software-properties - 0.98.9.2
o software-properties-common - 0.98.9.2
Ubuntu 18.04
o python3-software-properties - 0.96.24.32.14
o software-properties-common - 0.96.24.32.14
Ubuntu 16.04
o python-software-properties - 0.96.20.10
o python3-software-properties - 0.96.20.10
o software-properties-common - 0.96.20.10
In general, a standard system update will make all the necessary changes.
References
o CVE-2020-15709
- --------------------------------------------------------------------------------
USN-4457-2: Software Properties vulnerability
17 August 2020
Software Properties could be made to manipulate the display.
Releases
o Ubuntu 14.04 ESM
Packages
o software-properties - manage the repositories that you install software
from
Details
USN-4457-1 fixed a vulnerability in Software. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Jason A. Donenfeld discovered that Software Properties incorrectly filtered
certain escape sequences when displaying PPA descriptions. If a user were
tricked into adding an arbitrary PPA, a remote attacker could possibly
manipulate the screen.
Update instructions
The problem can be corrected by updating your system to the following package
versions:
Ubuntu 14.04
o python-software-properties - 0.92.37.8ubuntu0.1~esm1
o python3-software-properties - 0.92.37.8ubuntu0.1~esm1
o software-properties-common - 0.92.37.8ubuntu0.1~esm1
In general, a standard system update will make all the necessary changes.
References
o CVE-2020-15709
- --------------------------END INCLUDED TEXT--------------------
You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.
NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members. As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.
NOTE: This is only the original release of the security bulletin. It may
not be updated when updates to the original are made. If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.
Contact information for the authors of the original document is included
in the Security Bulletin above. If you have any questions or need further
information, please contact them directly.
Previous advisories and external security bulletins can be retrieved from:
https://www.auscert.org.au/bulletins/
===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072
Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967
iQIVAwUBXzstfONLKJtyKPYoAQhLlRAAifFOiQOMzoql4z+NG2lhmJkAlFuVkqb7
t+VVuYOf7hpCxQJ9BWwPwq6TJmzPx0OzzsYXruume0+IHiBgEdsmjBdAUuJlUCpH
TAhHsKOa537NMUCwtif/kEftBPIE8/hSVFllSnlxmq41pY0pi7uGkjZ+8+3qvRR0
k9tscr62e9JRub+5re5YrsAb44MVMjSWxGH8WBVp2unNHjKH5Cl0ARnEv/Y6d+a+
mCWzzOfchi9/fd9yvkcduagQnsuNq+4bpkQFtvat8z6Kh0GbMwlJ16Ows9M5hlvs
q1rqv7dJo2XdM9gAWjATc5p78MA4twfGHf0V7zBEC4co8xuQ1lmcLz9qHhrhnCII
Q7M9Qu6hQN5nRY3Gtx82BBMg9lXeA8oIv/8ww2BS3kO2fgqahZ9ow9OrgJbSNJ54
lj8ExWNLWUxve8doOlUk298iTYtsidSZThQH+hW5IuSEA1FkP9fn3+HRBhoDc2ty
Uduk4VFn0fVsfUlE2ATZA2XARH873QOpZilLGdil04wirc5/MdTRrff0y0fQ+1Cb
DhrpWx4H6S5YEGwaJQ6l4R5EU4h3N0C3Mi+hGu6tBF+P4piCZjj3o63vVtAa427R
qSqtvKTNCEnB0xkvrel4ZZCfiUFtPTZ3p6AnciXTXxTN0ZwTZK0y8/u8rMCOJ30p
apzM0PupndQ=
=RCrX
-----END PGP SIGNATURE-----
https://www.malwaredevil.com/2020/08/18/esb-2020-2791-2-update-ubuntu-software-properties-provide-misleading-information-existing-account/?utm_source=rss&utm_medium=rss&utm_campaign=esb-2020-2791-2-update-ubuntu-software-properties-provide-misleading-information-existing-account
No comments:
Post a Comment