Public bug reported:

Please sync libusbmuxd 1.0.10-3 (main) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
  * SECURITY UPDATE: incorrectly bound listening socket
    - debian/patches/CVE-2016-5104.patch: use INADDR_LOOPBACK in
      common/socket.c.
    - CVE-2016-5104
Fixed in Debian.

Changelog entries since current yakkety version 1.0.10-2ubuntu1:

libusbmuxd (1.0.10-3) unstable; urgency=high

  * [12da77b] Make sure sockets only listen locally.
    Fixes CVE-2016-5104 (Closes: #825554)

 -- Chow Loong Jin <[email protected]>  Sun, 05 Jun 2016 09:54:05
+0800

** Affects: libusbmuxd (Ubuntu)
     Importance: Wishlist
         Status: New

** Changed in: libusbmuxd (Ubuntu)
   Importance: Undecided => Wishlist

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1590232

Title:
  Sync libusbmuxd 1.0.10-3 (main) from Debian unstable (main)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libusbmuxd/+bug/1590232/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to