ubuntu-core-launcher 1.0.28 source package in Ubuntu

Changelog

ubuntu-core-launcher (1.0.28) yakkety; urgency=medium

  * SECURITY UPDATE: delayed attack snap data theft and privilege escalation
    when using Snappy on traditional Ubuntu (classic) systems (LP: #1576699)
    - src/main.c: remove glob code and hardcode /snap/ubuntu-core/current
      instead. The glob code both used an improper glob and performed an
      incorrect check due to a typo which allowed a snap named ubuntu-core-...
      to be bind mounted into application runtimes instead of the ubuntu-core
      OS snap. Ubuntu Core removed .<origin> and .sideload from the SNAP path
      so the glob can simply be dropped.
    - CVE-2016-1580
  * debian/usr.bin.ubuntu-core-launcher:
    - only allow mounting /snap/ubuntu-core/*/... to safeguard against this in
      the future
    - add lib32 and libx32 to match setup_snappy_os_mounts()

 -- Jamie Strandboge <email address hidden>  Fri, 29 Apr 2016 11:17:42 -0500

Upload details

Uploaded by:
Jamie Strandboge
Uploaded to:
Yakkety
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
utils
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
ubuntu-core-launcher_1.0.28.tar.xz 29.2 KiB a68b64f42f13c2ea2c8bad35bff570d7ecdf31c61558c45ab8b42ca1687c3715
ubuntu-core-launcher_1.0.28.dsc 1.6 KiB 98ed5c39c9121b6410a02c5be7121759f6124ea8ebea3c7c04c6c7e7796b3026

Available diffs

View changes file

Binary packages built by this source

ubuntu-core-launcher: No summary available for ubuntu-core-launcher in ubuntu yakkety.

No description available for ubuntu-core-launcher in ubuntu yakkety.

ubuntu-core-launcher-dbgsym: No summary available for ubuntu-core-launcher-dbgsym in ubuntu yakkety.

No description available for ubuntu-core-launcher-dbgsym in ubuntu yakkety.