Sync libusbmuxd 1.0.10-3 (main) from Debian unstable (main)

Bug #1590232 reported by Logan Rosen
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libusbmuxd (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync libusbmuxd 1.0.10-3 (main) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
  * SECURITY UPDATE: incorrectly bound listening socket
    - debian/patches/CVE-2016-5104.patch: use INADDR_LOOPBACK in
      common/socket.c.
    - CVE-2016-5104
Fixed in Debian.

Changelog entries since current yakkety version 1.0.10-2ubuntu1:

libusbmuxd (1.0.10-3) unstable; urgency=high

  * [12da77b] Make sure sockets only listen locally.
    Fixes CVE-2016-5104 (Closes: #825554)

 -- Chow Loong Jin <email address hidden> Sun, 05 Jun 2016 09:54:05 +0800

CVE References

Logan Rosen (logan)
Changed in libusbmuxd (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Daniel Holbach (dholbach) wrote :

This bug was fixed in the package libusbmuxd - 1.0.10-3
Sponsored for Logan Rosen (logan)

---------------
libusbmuxd (1.0.10-3) unstable; urgency=high

  * [12da77b] Make sure sockets only listen locally.
    Fixes CVE-2016-5104 (Closes: #825554)

 -- Chow Loong Jin <email address hidden> Sun, 05 Jun 2016 09:54:05 +0800

Changed in libusbmuxd (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.