========================================================================== Ubuntu Security Notice USN-4312-1 March 30, 2020
Timeshift vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 Summary: Timeshift could be made to run programs as an administrator. Software Description: - timeshift: System restore utility Details: Matthias Gerstner discovered that Timeshift did not securely create temporary files. An attacker could exploit a race condition in Timeshift and potentially execute arbitrary commands as root. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: timeshift 19.01+ds-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/4312-1 CVE-2020-10174 Package Information: https://launchpad.net/ubuntu/+source/timeshift/19.01+ds-2ubuntu0.1
signature.asc
Description: OpenPGP digital signature
-- ubuntu-security-announce mailing list [email protected] Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
