The apport lock file permission was addressed in bug #1862348.
** Changed in: apport (Ubuntu)
Status: Confirmed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to apport in Ubuntu.
@serge-hallyn: The fix for the reported bug was entirely in man-db (see
comment #15), although it was a combination of upstream and packaging
work. The apport, pam, and shadow tasks were spun off by @sarnold; the
pam/shadow tasks are explained in comment #2.
--
You received this bug
@cjwatson - is it safe to assume the fix was entirely in man-db? Or was
shadow supposed to do something here as well?
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to apport in Ubuntu.
https://bugs.launchpad.net/bugs/1482786
Was the decision made not to backport this to 14.04 and 16.04 LTS?
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to apport in Ubuntu.
https://bugs.launchpad.net/bugs/1482786
Title:
man-db daily cron job TOCTOU bug when
This bug was fixed in the package man-db - 2.7.6.1-1
---
man-db (2.7.6.1-1) unstable; urgency=medium
* New upstream release:
- Don't chmod CACHEDIR.TAG if it doesn't exist (closes: #847810).
-- Colin Watson Mon, 12 Dec 2016 12:51:57 +
** Changed
Apologies for my long delay in dealing with these bugs, both reported by
halfdog. Fixes turned out to be quite complicated, since in part they
involved unwinding incorrect logic from nearly 20 years ago and ensuring
that everything else built on that was appropriately adjusted.
Here are the
** Changed in: apport (Ubuntu)
Status: Fix Committed => Confirmed
** Changed in: man-db (Ubuntu)
Status: Fix Committed => Confirmed
** Changed in: pam (Ubuntu)
Status: Fix Committed => Confirmed
** Changed in: shadow (Ubuntu)
Status: Fix Committed => Confirmed
--
** Changed in: apport (Ubuntu)
Status: Confirmed => Fix Committed
** Changed in: man-db (Ubuntu)
Status: Confirmed => Fix Committed
** Changed in: pam (Ubuntu)
Status: Confirmed => Fix Committed
** Changed in: shadow (Ubuntu)
Status: Confirmed => Fix Committed
--
** Changed in: man-db (Ubuntu)
Importance: Undecided => Medium
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to pam in Ubuntu.
https://bugs.launchpad.net/bugs/1482786
Title:
man-db daily cron job TOCTOU bug when
** Information type changed from Private Security to Public Security
--
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to pam in Ubuntu.
https://bugs.launchpad.net/bugs/1482786
Title:
man-db daily cron job TOCTOU bug when
10 matches
Mail list logo