==========================================================================
Ubuntu Security Notice USN-3994-1
May 27, 2019
gnome-desktop3 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 19.04
– Ubuntu 18.10
– Ubuntu 18.04 LTS
Summary:
gnome-desktop could be made to escape the thumbnailer sandbox.
Software Description:
– gnome-desktop3: Introspection data for GnomeDesktop
Details:
It was discovered that gnome-desktop incorrectly confined thumbnailers. If
a user were tricked into downloading a malicious image file, a remote
attacker could possibly combine this issue with another vulnerability to
escape the sandbox and execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 19.04:
libgnome-desktop-3-17 3.32.1-1ubuntu1.1
Ubuntu 18.10:
libgnome-desktop-3-17 3.30.1-1ubuntu1.1
Ubuntu 18.04 LTS:
libgnome-desktop-3-17 3.28.2-0ubuntu1.3
After a standard system update you need to restart your session to make all
the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3994-1
CVE-2019-11460
Package Information:
https://launchpad.net/ubuntu/+source/gnome-desktop3/3.32.1-1ubuntu1.1
https://launchpad.net/ubuntu/+source/gnome-desktop3/3.30.1-1ubuntu1.1
https://launchpad.net/ubuntu/+source/gnome-desktop3/3.28.2-0ubuntu1.3
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlzsAgkACgkQZWnYVadE
vpPc7RAAgdq9i86Y98dPA1sZfpAXmOq80Wga161CEIlq3wkHC21YL05npxW8T+no
fPlUuse+iNy3cuESpb2yb9bGycpnqu7ZwVsZr3n0F75+AhIZmVDTrgZvIwLYp7ZS
dwcmoI5LrFAbQZN4wMMCq/pHr1XudK1YRldUyLkXhmQRhamMdwBcF/xroTG4p7cg
tFDUfs52J40XfaVDuUuN8xuo4xTYTP2MgWGsgw/c/RsRUMMzE9yHN6Ax9d2TJaEn
t3k/W8uiM8WJHAJewR+fTVsms6/kXZ6xNMD6ebXPVZez0uZYUiH4QY/Q0U/e6zD5
ChIs6T219MbvzySN4nCUgStbWzSBEmeQQJxAQFK3e9RvGq2RLZRCqv0OcetXLhol
ye9hbQAGowQD4Kj8GauDhB5tQr4IWfXaTwi99YYbgeo1vcPxISaWogpvWx1Hzeja
ho/w0ZVjn41bd4Mn5h4xl1Z8t7SgfETvGo+8EHbga1AEZly7jr/4+o4tnT8McgN0
gImo08NUZz1fG9I1Itz7YkNxgmDItN4oI0AoPqEgDzsIWybzshmBiZ7Ja+Wa1FzG
EaY1GRJ2bpwUeCehehtpyqRI5fh2UFBkTbNX3J4ZZgjxZpACNESco9cnXqoMYHbI
3SNLfMiErA5ebib0I0OrIDn2Rs3M3eCY0K8jr+jucRhzsVUcK2w=
=/4Xz
—–END PGP SIGNATURE—–
—