apport 2.17.3-0ubuntu1 source package in Ubuntu

Changelog

apport (2.17.3-0ubuntu1) wily; urgency=medium

  * New upstream release:
    - SECURITY UPDATE: When /proc/sys/fs/suid_dumpable is enabled, crashing a
      program that is suid root or not readable for the user would create
      root-owned core files in the current directory of that program. Creating
      specially crafted core files in /etc/logrotate.d or similar could then
      lead to arbitrary code execution with root privileges.
      Now core files do not get written for these kinds of programs, in
      accordance with the intention of core(5).
      Thanks to Sander Bos for discovering this issue!
      (CVE-2015-1324, LP: #1452239)
    - SECURITY UPDATE: When writing a core dump file for a crashed packaged
      program, don't close and reopen the .crash report file but just rewind
      and re-read it. This prevents the user from modifying the .crash report
      file while "apport" is running to inject data and creating crafted core
      dump files. In conjunction with the above vulnerability of writing core
      dump files to arbitrary directories this could be exploited to gain root
      privileges.
      Thanks to Philip Pettersson for discovering this issue!
      (CVE-2015-1325, LP: #1453900)
    - apportcheckresume: Fix "occured" typo, thanks Matthew Paul Thomas.
      (LP: #1448636)
    - signal_crashes test: Fix test_crash_setuid_* to look at whether
      suid_dumpable was enabled.
    - test/run: Run UI tests under dbus-launch, newer GTK versions require this
      now.

 -- Martin Pitt <email address hidden>  Wed, 20 May 2015 16:58:35 +0200

Upload details

Uploaded by:
Martin Pitt
Uploaded to:
Wily
Original maintainer:
Martin Pitt
Architectures:
all
Section:
utils
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Wily: [FULLYBUILT] amd64

Downloads

File Size SHA-256 Checksum
apport_2.17.3.orig.tar.gz 1.2 MiB 4ea043d3d8c80429b0afca6d97ddfe0a5d35587c6a8288166e9e6c150adb35af
apport_2.17.3-0ubuntu1.diff.gz 141.6 KiB b482e5eba2ae8c25082987ba86e63cc23fc0f0c92820c1a21a5804a7b6b0cb88
apport_2.17.3-0ubuntu1.dsc 2.8 KiB c5fd102c179997e558aeca3dda39e9e1e3448586b12e14c35b4e28b268200e4c

Available diffs

View changes file

Binary packages built by this source

apport: No summary available for apport in ubuntu wily.

No description available for apport in ubuntu wily.

apport-gtk: No summary available for apport-gtk in ubuntu wily.

No description available for apport-gtk in ubuntu wily.

apport-kde: No summary available for apport-kde in ubuntu wily.

No description available for apport-kde in ubuntu wily.

apport-noui: No summary available for apport-noui in ubuntu wily.

No description available for apport-noui in ubuntu wily.

apport-retrace: No summary available for apport-retrace in ubuntu wily.

No description available for apport-retrace in ubuntu wily.

apport-valgrind: No summary available for apport-valgrind in ubuntu wily.

No description available for apport-valgrind in ubuntu wily.

dh-apport: No summary available for dh-apport in ubuntu wily.

No description available for dh-apport in ubuntu wily.

python-apport: No summary available for python-apport in ubuntu wily.

No description available for python-apport in ubuntu wily.

python-problem-report: No summary available for python-problem-report in ubuntu wily.

No description available for python-problem-report in ubuntu wily.

python3-apport: No summary available for python3-apport in ubuntu wily.

No description available for python3-apport in ubuntu wily.

python3-problem-report: No summary available for python3-problem-report in ubuntu wily.

No description available for python3-problem-report in ubuntu wily.