UbuntuUpdates.org

Package "networkd-dispatcher"

Name: networkd-dispatcher

Description:

Dispatcher service for systemd-networkd connection status changes

Latest version: 1.7-0ubuntu3.5
Release: bionic (18.04)
Level: security
Repository: main
Homepage: https://github.com/craftyguy/networkd-dispatcher

Links


Download "networkd-dispatcher"


Other versions of "networkd-dispatcher" in Bionic

Repository Area Version
updates main 1.7-0ubuntu3.5

Changelog

Version: 1.7-0ubuntu3.5 2022-05-04 19:06:21 UTC

  networkd-dispatcher (1.7-0ubuntu3.5) bionic-security; urgency=medium

  * SECURITY REGRESSION: Incomplete security fix (LP: #1971550)
    - debian/patches/CVE-2022-29799-regression.patch: Add initialized state
      in ADMIN_STATES in networkd-dispatcher.

 -- Rodrigo Figueiredo Zaiden <email address hidden> Wed, 04 May 2022 10:51:28 -0300

Source diff to previous version
1971550 networkd-dispatcher missing state 'initialized'

Version: 1.7-0ubuntu3.4 2022-04-28 17:06:19 UTC

  networkd-dispatcher (1.7-0ubuntu3.4) bionic-security; urgency=medium

    * SECURITY UPDATE: Directory traversal
    - debian/patches/CVE-2022-29799.patch: Add allowed admin and
      operational states in networkd-dispatcher and throw exceptions in
      handle_state function if the current state is not one of those.
    - CVE-2022-29799
  * SECURITY UPDATE: Time-of-check-time-of-use race condition
    - debian/patches/CVE-2022-29800-1.patch: Add check_perms function that
      will be invoked in scripts_in_path function before appending a file
      path to the script_list in networkd-dispatcher.
    - debian/patches/CVE-2022-29800-2.patch: Passes os.path.dirname(path)
      when checking for permissions in scripts_in_path function in
      networkd-dispatcher.
    - CVE-2022-29800

 -- Rodrigo Figueiredo Zaiden <email address hidden> Thu, 28 Apr 2022 07:43:22 -0300




About   -   Send Feedback to @ubuntu_updates