==========================================================================
Ubuntu Security Notice USN-4077-1
July 29, 2019
tmpreaper vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
Summary:
tmpreaper could be made to overwrite files as the administrator.
Software Description:
– tmpreaper: cleans up files in directories based on their age
Details:
It was discovered that tmpreaper incorrectly handled certain mount operations. A
local attacker could possibly use this issue to create arbitrary files, leading
to privilege escalation.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
tmpreaper 1.6.13+nmu1+deb9u1build0.18.04.1
Ubuntu 16.04 LTS:
tmpreaper 1.6.13+nmu1+deb9u1build0.16.04.1
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4077-1
CVE-2019-3461
Package Information:
https://launchpad.net/ubuntu/+source/tmpreaper/1.6.13+nmu1+deb9u1build0.18.04.1
https://launchpad.net/ubuntu/+source/tmpreaper/1.6.13+nmu1+deb9u1build0.16.04.1
—–BEGIN PGP SIGNATURE—–
iQIzBAABCgAdFiEECtyyz6azUy6AZBzSkGeI6zGnN/8FAl0/L9oACgkQkGeI6zGn
N/8BuA//b5iEBO/33cN+ZzI+B65hB2SaEe/8Lq2hh2rVETYejJAdVUEfH4SAqBs3
3Vk/OOfJpO8jBR0grBQZAKs9xuqX1GEpUR2uqlXZV9VY5yqK0FUCcR2s8ZkDL9oC
T58QnicuXprkEBDgndyoeO85lqQzDydTCmqHmda8D/oHsPR95cM5TXz7k8PYRMpB
QqO1ydcGa2T7MZlT6a1D/5DjuHGTCiSA2vRz5e1dZYseczlZ7Aryowh17QGQJ+03
wB0UMHM9q/RxId3wQkirZ5M//ep/gSOajK5UzDxq0Zc5MGpLBakfo/GzshInvmCf
2uwpEnVY9j29Bu6rMgE2UcovjNKe2iocdMrSzbrnIX9ApLywnc8MrkjLxy6GtMoq
eYb1rO9/PS7bn8GzoANKmricD4KM3lagybEQGkao5rDqirydoTZhWJxSx41MLVUe
X7NMp+j0HX61UWIFjsk/2EvRl5neX3vocEWI5zp1Jydby/F9OVX32AbV4LihyTI6
acneDMFC7Hm8sSwjmPa2mdjjOjEYD1D77Bx1HOf2WXRVL4Z4DwHu26EegbvAxCLY
bsXL4upztPpGA4J/h0UZmXR6iSgqzu7YXZkN7wO9vQmYfa6UvGggjKAI0sACPg3Q
A30ZMYsgeYCPaqkRYFwggYSybLQPh51b9xCz3APM/tA7kM5CwDE=
=oRSb
—–END PGP SIGNATURE—–
—