apport 2.20.7-0ubuntu3.4 source package in Ubuntu

Changelog

apport (2.20.7-0ubuntu3.4) artful-security; urgency=medium

  * SECURITY UPDATE: Denial of service via resource exhaustion and
    privilege escalation when handling crashes of tainted processes
    (LP: #1726372)
    - When /proc/sys/fs/suid_dumpable is set to 2, do not assume that
      the user and group owning the /proc/<PID>/stat file is the same
      user and group that started the process. Rather check the dump
      mode of the crashed process and do not write a core file if its
      value is 2. Thanks to Sander Bos for discovering this issue!
    - CVE-2017-14177
  * SECURITY UPDATE: Denial of service via resource exhaustion,
    privilege escalation, and possible container escape when handling
    crashes of processes inside PID namespaces (LP: #1726372)
    - Change the method for determining if a crash is from a container
      so that there are no false positives from software using PID
      namespaces. Additionally, disable container crash forwarding by
      ignoring crashes that occur in a PID namespace. This functionality
      may be re-enabled in a future update. Thanks to Sander Bos for
      discovering this issue!
    - CVE-2017-14180

 -- Brian Murray <email address hidden>  Tue, 14 Nov 2017 08:37:05 -0800

Upload details

Uploaded by:
Brian Murray
Sponsored by:
Tyler Hicks
Uploaded to:
Artful
Original maintainer:
Martin Pitt
Architectures:
all
Section:
utils
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Artful: [FULLYBUILT] amd64

Downloads

File Size SHA-256 Checksum
apport_2.20.7-0ubuntu3.4.tar.gz 1.4 MiB 7984e526669fdcf56860c50c1bbf18813ae5bea96e0e0c35b33f050e01928159
apport_2.20.7-0ubuntu3.4.dsc 2.8 KiB cc57d7c5adb369cae7c12f1f4adb9a5bd58514d98f692e780211265f1e7fecb6

View changes file

Binary packages built by this source

apport: No summary available for apport in ubuntu artful.

No description available for apport in ubuntu artful.

apport-gtk: No summary available for apport-gtk in ubuntu artful.

No description available for apport-gtk in ubuntu artful.

apport-kde: No summary available for apport-kde in ubuntu artful.

No description available for apport-kde in ubuntu artful.

apport-noui: No summary available for apport-noui in ubuntu artful.

No description available for apport-noui in ubuntu artful.

apport-retrace: No summary available for apport-retrace in ubuntu artful.

No description available for apport-retrace in ubuntu artful.

apport-valgrind: No summary available for apport-valgrind in ubuntu artful.

No description available for apport-valgrind in ubuntu artful.

dh-apport: No summary available for dh-apport in ubuntu artful.

No description available for dh-apport in ubuntu artful.

python-apport: No summary available for python-apport in ubuntu artful.

No description available for python-apport in ubuntu artful.

python-problem-report: No summary available for python-problem-report in ubuntu artful.

No description available for python-problem-report in ubuntu artful.

python3-apport: No summary available for python3-apport in ubuntu artful.

No description available for python3-apport in ubuntu artful.

python3-problem-report: No summary available for python3-problem-report in ubuntu artful.

No description available for python3-problem-report in ubuntu artful.