group.of.nepali.translators team mailing list archive
-
group.of.nepali.translators team
-
Mailing list archive
-
Message #18998
[Bug 1617617] Re: Firewall configuration can be modified by any logged in user
This bug was fixed in the package firewalld - 0.4.0-1ubuntu0.1
---------------
firewalld (0.4.0-1ubuntu0.1) xenial-security; urgency=medium
* SECURITY UPDATE: Any logged in user could modify passthrough rules
and set ipset entries (LP: #1617617)
- debian/patches/CVE-2016-5410.patch: Enforce appropriate PolicyKit
authentication requirements, based on upstream 0.4.3.3 commit
- CVE-2016-5410
-- Lucas Kocia <lucas.kocia@xxxxxxxxx> Wed, 25 Oct 2017 21:03:52 -0400
** Changed in: firewalld (Ubuntu Xenial)
Status: Confirmed => Fix Released
--
You received this bug notification because you are a member of नेपाली
भाषा समायोजकहरुको समूह, which is subscribed to Xenial.
Matching subscriptions: Ubuntu 16.04 Bugs
https://bugs.launchpad.net/bugs/1617617
Title:
Firewall configuration can be modified by any logged in user
Status in firewalld package in Ubuntu:
Fix Released
Status in firewalld source package in Xenial:
Fix Released
Status in firewalld package in Debian:
Fix Released
Bug description:
Copying from the Debian bug:
---
The following vulnerability was published for firewalld.
CVE-2016-5410[0]:
Firewall configuration can be modified by any logged in user
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2016-5410
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1360135
[2] http://seclists.org/oss-sec/2016/q3/291
[3] https://github.com/t-woerner/firewalld/commit/0371995a58ec4c777960007b7dbee93933f760cb
---
This only affects firewalld >= 0.3.12 & < 0.4.3.3 (so trusty is not
affected).
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/firewalld/+bug/1617617/+subscriptions
References