Activity log for bug #194166

Date Who What changed Old value New value Message
2008-02-21 23:07:43 Mihai Varzaru bug added bug
2008-02-21 23:07:43 Mihai Varzaru bug added attachment 'gksu' (Demo gksu script)
2008-02-22 17:04:23 Mihai Varzaru bug assigned to update-manager
2008-02-24 13:00:31 Mihai Varzaru description Binary package hint: update-manager gksu is called without giving the full path. An application that has normal user rights could use this for an elevation of privilege by modifying the PATH variable. After it modifies the PATH variable to point to a location where it holds a custom gksu script it has just to wait for the the next Ubuntu update in order to run with root privileges. The code for this is in UpdateManager.py, run_synaptic function, line 697 on version 0.81.2: cmd = ["gksu", "--desktop", "/usr/share/applications/update-manager.desktop", Found in: Ubuntu 7.10 Package: update-manager v. 0.81.2 Binary package hint: update-manager gksu is called without giving the full path. An application that has normal user rights could use this for an elevation of privilege by modifying the PATH variable. After it modifies the PATH variable to point to a location where it holds a custom gksu script it has just to wait for the the next Ubuntu update in order to run with root privileges. The code for this is in UpdateManager.py, run_synaptic function, line 697 on version 0.81.2: cmd = ["gksu", "--desktop", "/usr/share/applications/update-manager.desktop", Found in: Ubuntu 7.10 Package: update-manager v. 0.81.2 It is also present in Ubuntu Hardy, update-manager v. 0.87.9. It seems that the problem was introduces in Ubuntu Edgy, update manager v. 0.45.
2008-02-24 13:53:30 James Westby update-manager: status New In Progress
2008-02-24 13:53:30 James Westby update-manager: assignee james-w
2008-02-24 13:56:35 James Westby bug added attachment 'update-manager-security.diff' (update-manager-security.diff)
2008-03-10 09:59:44 Michael Vogt update-manager: status New Fix Committed
2008-03-10 09:59:44 Michael Vogt update-manager: assignee mvo
2008-03-10 09:59:53 Michael Vogt update-manager: status In Progress Fix Committed
2008-03-11 12:30:05 Launchpad Janitor update-manager: status Fix Committed Fix Released
2009-01-10 00:39:06 Kees Cook update-manager: status Fix Committed Fix Released
2009-07-04 05:05:14 Launchpad Janitor branch linked lp:ubuntu/karmic/language-selector
2010-02-22 00:31:39 Launchpad Janitor branch linked lp:ubuntu/update-manager