python-dbusmock 0.11.4-1ubuntu1 source package in Ubuntu

Changelog

python-dbusmock (0.11.4-1ubuntu1) utopic-security; urgency=medium

  * SECURITY FIX: When loading a template from an arbitrary file through the
    AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template()
    Python method, don't create or use Python's *.pyc cached files. By
    tricking a user into loading a template from a world-writable directory
    like /tmp, an attacker could run arbitrary code with the user's
    privileges by putting a crafted .pyc file into that directory.

    Note that this is highly unlikely to actually appear in practice as custom
    dbusmock templates are usually shipped in project directories, not
    directly in world-writable directories.
    (LP: #1453815, CVE-2015-1326)

 -- Martin Pitt <email address hidden>  Tue, 12 May 2015 13:23:38 +0200

Upload details

Uploaded by:
Martin Pitt
Sponsored by:
Marc Deslauriers
Uploaded to:
Utopic
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
python
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Utopic: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
python-dbusmock_0.11.4.orig.tar.gz 59.9 KiB f390174ad96a02e5df2f8b3678e74cfb85253bca292956c7bf09fd65eab03ec1
python-dbusmock_0.11.4-1ubuntu1.debian.tar.xz 4.7 KiB b93dc293e2fcf9e422ba3b026470495505c327ef249d7ee12a3fefe018a922a7
python-dbusmock_0.11.4-1ubuntu1.dsc 2.4 KiB a31786166e5beee0b8f4121173424234651f059fe0a52b833f33992c6d2d7f87

View changes file

Binary packages built by this source

python-dbusmock: No summary available for python-dbusmock in ubuntu utopic.

No description available for python-dbusmock in ubuntu utopic.

python3-dbusmock: No summary available for python3-dbusmock in ubuntu utopic.

No description available for python3-dbusmock in ubuntu utopic.