apport 2.20.11-0ubuntu71.2 source package in Ubuntu
Changelog
apport (2.20.11-0ubuntu71.2) impish-security; urgency=medium * SECURITY UPDATE: Fix multiple security issues - test/test_report.py: Fix flaky test. - data/apport: Fix too many arguments for error_log(). - data/apport: Use proper argument variable name executable_path. - etc/init.d/apport: Set core_pipe_limit to a non-zero value to make sure the kernel waits for apport to finish before removing the /proc information. - apport/fileutils.py, data/apport: Search for executable name if one wan't provided such as when being called in a container. - data/apport: Limit memory and duration of gdbus call. (CVE-2022-28654, CVE-2022-28656) - data/apport, apport/fileutils.py, test/test_fileutils.py: Validate D-Bus socket location. (CVE-2022-28655) - apport/fileutils.py, test/test_fileutils.py: Turn off interpolation in get_config() to prevent DoS attacks. (CVE-2022-28652) - Refactor duplicate code into search_map() function. - Switch from chroot to container to validating socket owner. (CVE-2022-1242, CVE-2022-28657) - data/apport: Clarify error message. - apport/fileutils.py: Fix typo in comment. - apport/fileutils.py: Do not call str in loop. - data/apport, etc/init.d/apport: Switch to using non-positional arguments. Get real UID and GID from the kernel and make sure they match the process. Also fix executable name space handling in argument parsing. (CVE-2022-28658, CVE-2021-3899) -- Marc Deslauriers <email address hidden> Tue, 10 May 2022 09:23:35 -0400
Upload details
- Uploaded by:
- Marc Deslauriers
- Uploaded to:
- Impish
- Original maintainer:
- Ubuntu Developers
- Architectures:
- all
- Section:
- utils
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
apport_2.20.11-0ubuntu71.2.tar.gz | 1.3 MiB | 428175d725b34158af0a4b70ce4d29ae96347d79558939b43ea040d2ff969b11 |
apport_2.20.11-0ubuntu71.2.dsc | 2.6 KiB | ff127f8579cbb83d5c649044b255795b8c727396a97a38106fa51e97bf534e58 |
Available diffs
Binary packages built by this source
- apport: No summary available for apport in ubuntu impish.
No description available for apport in ubuntu impish.
- apport-gtk: No summary available for apport-gtk in ubuntu impish.
No description available for apport-gtk in ubuntu impish.
- apport-kde: No summary available for apport-kde in ubuntu impish.
No description available for apport-kde in ubuntu impish.
- apport-noui: No summary available for apport-noui in ubuntu impish.
No description available for apport-noui in ubuntu impish.
- apport-retrace: No summary available for apport-retrace in ubuntu impish.
No description available for apport-retrace in ubuntu impish.
- apport-valgrind: No summary available for apport-valgrind in ubuntu impish.
No description available for apport-valgrind in ubuntu impish.
- dh-apport: No summary available for dh-apport in ubuntu impish.
No description available for dh-apport in ubuntu impish.
- python3-apport: No summary available for python3-apport in ubuntu impish.
No description available for python3-apport in ubuntu impish.
- python3-problem-report: No summary available for python3-problem-report in ubuntu impish.
No description available for python3-
problem- report in ubuntu impish.