USN-2618-1: python-dbusmock vulnerability

Publication date

21 May 2015

Overview

python-dbusmock could be tricked into running arbitrary programs.


Packages

Details

It was discovered that python-dbusmock incorrectly handled template
loading from shared directories. A local attacker could possibly use this
issue to execute arbitrary code.

It was discovered that python-dbusmock incorrectly handled template
loading from shared directories. A local attacker could possibly use this
issue to execute arbitrary code.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
15.04 vivid python-dbusmock –  0.14-1ubuntu2
python3-dbusmock –  0.14-1ubuntu2
14.10 utopic python-dbusmock –  0.11.4-1ubuntu1
python3-dbusmock –  0.11.4-1ubuntu1
14.04 trusty python-dbusmock –  0.10.1-1ubuntu1
python3-dbusmock –  0.10.1-1ubuntu1

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›