touch-packages team mailing list archive
-
touch-packages team
-
Mailing list archive
-
Message #70374
[Bug 1444518] [NEW] Insecure /proc/net/unix parsing
*** This bug is a security vulnerability ***
Public security bug reported:
The fix in USN-2569-1 introduced a vulnerability when parsing
/proc/net/unix.
There is a known issue in the kernel where newlines aren't being escaped properly:
http://www.spinics.net/lists/netdev/msg320556.html
Resulting in Tavis Ormandy finding a new issue:
http://www.openwall.com/lists/oss-security/2015/04/14/18
** Affects: apport (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to apport in Ubuntu.
https://bugs.launchpad.net/bugs/1444518
Title:
Insecure /proc/net/unix parsing
Status in apport package in Ubuntu:
New
Bug description:
The fix in USN-2569-1 introduced a vulnerability when parsing
/proc/net/unix.
There is a known issue in the kernel where newlines aren't being escaped properly:
http://www.spinics.net/lists/netdev/msg320556.html
Resulting in Tavis Ormandy finding a new issue:
http://www.openwall.com/lists/oss-security/2015/04/14/18
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1444518/+subscriptions
Follow ups
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Launchpad Bug Tracker, 2015-04-17
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Martin Pitt, 2015-04-16
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Martin Pitt, 2015-04-16
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Martin Pitt, 2015-04-16
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Launchpad Bug Tracker, 2015-04-16
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Martin Pitt, 2015-04-16
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Launchpad Bug Tracker, 2015-04-16
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Launchpad Bug Tracker, 2015-04-16
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Tyler Hicks, 2015-04-15
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Stéphane Graber, 2015-04-15
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Tyler Hicks, 2015-04-15
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Ubuntu Foundations Team Bug Bot, 2015-04-15
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Stéphane Graber, 2015-04-15
-
[Bug 1444518] Re: Insecure /proc/net/unix parsing
From: Marc Deslauriers, 2015-04-15
-
[Bug 1444518] [NEW] Insecure /proc/net/unix parsing
From: Marc Deslauriers, 2015-04-15
References