Your submission was sent successfully! Close

USN-572-1: apt-listchanges vulnerability

18 January 2008

apt-listchanges vulnerability

Releases

Packages

Details

Felipe Sateler discovered that apt-listchanges did not use safe paths when
importing additional Python libraries. A local attacker could exploit
this and execute arbitrary commands as the user running apt-listchanges.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 7.10
Ubuntu 7.04

In general, a standard system upgrade is sufficient to effect the
necessary changes.

References