==========================================================================
Ubuntu Security Notice USN-4537-1
September 24, 2020
aptdaemon vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 20.04 LTS
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
Summary:
Aptdaemon could be made to expose sensitive information.
Software Description:
– aptdaemon: transaction based package management service
Details:
Vaisha Bernard discovered that Aptdaemon incorrectly handled the Locale
property. A local attacker could use this issue to test for the presence of
local files.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
aptdaemon 1.1.1+bzr982-0ubuntu32.2
Ubuntu 18.04 LTS:
aptdaemon 1.1.1+bzr982-0ubuntu19.4
Ubuntu 16.04 LTS:
aptdaemon 1.1.1+bzr982-0ubuntu14.4
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://usn.ubuntu.com/4537-1
CVE-2020-15703
Package Information:
https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu32.2
https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu19.4
https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu14.4
—–BEGIN PGP SIGNATURE—–
iQIyBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl9ssG8ACgkQZWnYVadE
vpNpOg/49ciT1pe/fjkuiMgNMmyzZaqphdy5boX3xMbCD/hvquLixCtno2QoIHXA
hDpPvtovDl5gD1giefiqtZGaZozMI0xvd81g4KlCoE2fEYNnrzGKm3HhM50x1pBv
a8xpCe8ACLz1w5ONEHTLwbxayeyUO2CBFMb8R5RUYnHNsCrv9RRoYAJbyPJFUell
3+VkWB6KmbhHRNEYCKrPO90Fdt4yELW5OUHQH5qS0o7gQny1GRp80+PAkW3++QHq
kFzBgPL/Ux3rkP5XT6ZZ5bqHrv/SNqP2DHuPgelEXke1+1DvMAGem6NsfR/yuLrr
GMJ06QQLLpvLxqpiWOfsvfXxZ2wTvN9AIMzvmg0rImvvQpVKlBXqWHdDYgxEDQkH
pNu6NN/ZPFx0qWl+uKy9hiRbDLNLsXWJ0RnCQJNoDGs4ZRMX/adbQvAlj9h92teo
kU+IlBrNPVgR8iD+muqpzxu8ChWqu8ShPT/D5rTqOsfSvtcsnxl8yRJG/mlfLo+e
+ypBFOVkbTGeC1cyUtE3smenpm2KI9GT8IOkWcIYrNCIWleyvTDhf+HBfaOJnYMx
S7iToNTWdZ/8V86OaJNpdLyLUv9jjw9SJslu0LkwMeENemtlQLexhV0XjM+1hR7R
TPEI6/3Ga5VnpE9z1aYDEkmdNterb8GuEfvo/yFOOVXE1nodAw==
=OxN6
—–END PGP SIGNATURE—–
—