USN-5169-1: oddjob vulnerability
9 August 2022
oddjob could be made to overwrite file and directory permissions.
Releases
Packages
- oddjob - D-Bus service which runs odd jobs -- daemon
Details
Matthias Gerstner discovered that there was a race condition in the mkhomedir
tool shipped with the oddjob package. An authenticated attacker could use this
to setup a symlink attack and change permissions on files on the host filesystem.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
-
oddjob
-
0.34.4-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
oddjob-mkhomedir
-
0.34.4-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04
-
oddjob
-
0.34.3-4ubuntu0.1~esm1
Available with Ubuntu Pro
-
oddjob-mkhomedir
-
0.34.3-4ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
oddjob
-
0.34.3-2ubuntu0.1~esm1
Available with Ubuntu Pro
-
oddjob-mkhomedir
-
0.34.3-2ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.