UbuntuUpdates.org

Package "ubuntu-advantage-desktop-daemon"

Name: ubuntu-advantage-desktop-daemon

Description:

Daemon to allow access to ubuntu-advantage via D-Bus

Latest version: 1.10.ubuntu0.22.04.2
Release: jammy (22.04)
Level: security
Repository: main
Homepage: https://github.com/canonical/ubuntu-advantage-desktop-daemon

Links


Download "ubuntu-advantage-desktop-daemon"


Other versions of "ubuntu-advantage-desktop-daemon" in Jammy

Repository Area Version
updates main 1.10.ubuntu0.22.04.2

Changelog

Version: 1.10.ubuntu0.22.04.2 2024-10-11 02:07:16 UTC

  ubuntu-advantage-desktop-daemon (1.10.ubuntu0.22.04.2) jammy-security; urgency=medium

  * SECURITY UPDATE: Pro client is called with attach parameter in plain text,
    allowing for potentially leak of private information. (LP: #2068944)
    - debian/patches/CVE-2024-6388.patch: Use a temporary file with 400
      permissions instead.
      https://github.com/canonical/ubuntu-advantage-desktop-daemon/pull/24/
    - CVE-2024-6388

 -- Chris Kim <email address hidden> Tue, 08 Oct 2024 14:39:35 -0700

2068944 ubuntu-advantage-desktop-daemon (pro client in general) may expose the pro token to other users
CVE-2024-6388 Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the tok



About   -   Send Feedback to @ubuntu_updates