Security-related upstream update fwbuilder 3.0.7 is now available

Bug #434837 reported by Vadim Kurland
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
fwbuilder (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

Binary package hint: fwbuilder

This new upstream release fixes security issue with temporary file handling in the generated iptables script that affects only Linux systems where Firewall Builder is used to generate static routing configuration. The problem could cause privileges escalation on the machine where generated script was used because the script has to run with root privileges in order to be able to load iptables policy.

the problem affects Firewall Builder v3.0.4, 3.0.5, 3.0.6 and is fixed in 3.0.7

Updated version has been submitted to Debian unstable couple of days ago. http://packages.debian.org/unstable/net/fwbuilder

Ubuntu Karmic has 3.0.5 and needs to be updated. Package that ships with Jaunty (v3.0.2) is not affected and I do not think this warrants stable release update.

Revision history for this message
Vadim Kurland (vadim-fwbuilder) wrote :

Sorry, I forgot to add, update of the fwbuilder package requires coordinated update of libfwbuilder package to the same version.

visibility: private → public
Changed in fwbuilder (Ubuntu):
status: New → Confirmed
importance: Undecided → Medium
Revision history for this message
Sylvestre Ledru (sylvestre) wrote :

This bug is fixed in the Debian package

Revision history for this message
Vadim Kurland (vadim-fwbuilder) wrote :

Ubuntu maintainers,

do you think this security update is going to make it into Karmic ? Its been a while since the fix was released and this bug opened but Karmic still has wrong package. Do you plan to release Karmic with this security issue ?

Thanks
Vadim

Revision history for this message
Ilya Barygin (randomaction) wrote :

Lucid already has 3.0.7, so I'm closing this bug.
Please see https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for information on fixing this in Karmic.

Changed in fwbuilder (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.