[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2015-02-26 Thread Burnz
** Also affects: apport (Arch Linux) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged user To

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2014-06-07 Thread Marc Deslauriers
** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged user To manage notifications

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2014-06-06 Thread kitty sanders
** Information type changed from Public Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged user To manage notifications

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-12-10 Thread Martin Pitt
** Changed in: apport Assignee: kitty sanders (towncutie2233) => Martin Pitt (pitti) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-12-10 Thread kitty sanders
** Changed in: apport Assignee: Martin Pitt (pitti) => kitty sanders (towncutie2233) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-31 Thread Bug Watch Updater
** Changed in: apport (Debian) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged user To manage n

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Launchpad Bug Tracker
This bug was fixed in the package apport - 2.12.6-0ubuntu1 --- apport (2.12.6-0ubuntu1) trusty; urgency=low * New upstream security/bug fix release: - SECURITY FIX: For setuid programs which drop their privileges after startup, make the report and core dumps owned by root,

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Bug Watch Updater
** Changed in: apport (Debian) Status: Unknown => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged user To manage notifi

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Martin Pitt
** Changed in: apport (Ubuntu Trusty) Status: Triaged => Fix Committed ** Bug watch added: Debian Bug tracker #727661 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=727661 ** Also affects: apport (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=727661 Importance: Un

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Martin Pitt
Fixed in upstream release 2.12.6: https://launchpad.net/apport/trunk/2.12.6 ** Description changed: Elsewhere I have been working on a sensitive information leak via core dump generated by gcore(1). The sensitive information in question is read by a stock setuid root binary executed by

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Launchpad Bug Tracker
** Branch linked: lp:apport -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged user To manage notifications about this bug go to: https://b

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Ubuntu Foundations Team Bug Bot
** Tags added: patch -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged user To manage notifications about this bug go to: https://bugs.lau

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Launchpad Bug Tracker
This bug was fixed in the package apport - 2.12.5-0ubuntu2.1 --- apport (2.12.5-0ubuntu2.1) saucy-security; urgency=low * SECURITY UPDATE: incorrect permissions on setuid process core dumps (LP: #1242435) - use correct permissions when writing the core file in data/apport,

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Launchpad Bug Tracker
This bug was fixed in the package apport - 2.6.1-0ubuntu13 --- apport (2.6.1-0ubuntu13) quantal-security; urgency=low * SECURITY UPDATE: incorrect permissions on setuid process core dumps (LP: #1242435) - use correct permissions when writing the core file in data/apport,

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Launchpad Bug Tracker
This bug was fixed in the package apport - 2.0.1-0ubuntu17.6 --- apport (2.0.1-0ubuntu17.6) precise-security; urgency=low * SECURITY UPDATE: incorrect permissions on setuid process core dumps (LP: #1242435) - use correct permissions when writing the core file in data/apport,

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Marc Deslauriers
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1242435 Title: Desktop setuid cores readable by non-privileged user To manage noti

[Bug 1242435] Re: Desktop setuid cores readable by non-privileged user

2013-10-24 Thread Launchpad Bug Tracker
This bug was fixed in the package apport - 2.9.2-0ubuntu8.5 --- apport (2.9.2-0ubuntu8.5) raring-security; urgency=low * SECURITY UPDATE: incorrect permissions on setuid process core dumps (LP: #1242435) - use correct permissions when writing the core file in data/apport,