python-dbusmock 0.14-1ubuntu2 source package in Ubuntu

Changelog

python-dbusmock (0.14-1ubuntu2) vivid-security; urgency=medium

  * SECURITY FIX: When loading a template from an arbitrary file through the
    AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template()
    Python method, don't create or use Python's *.pyc cached files. By
    tricking a user into loading a template from a world-writable directory
    like /tmp, an attacker could run arbitrary code with the user's
    privileges by putting a crafted .pyc file into that directory.

    Note that this is highly unlikely to actually appear in practice as custom
    dbusmock templates are usually shipped in project directories, not
    directly in world-writable directories.
    (LP: #1453815, CVE-2015-1326)

 -- Martin Pitt <email address hidden>  Tue, 12 May 2015 13:20:03 +0200

Upload details

Uploaded by:
Martin Pitt
Sponsored by:
Marc Deslauriers
Uploaded to:
Vivid
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
python
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Vivid: [FULLYBUILT] amd64

Downloads

File Size SHA-256 Checksum
python-dbusmock_0.14.orig.tar.gz 63.2 KiB f734d1fecb98cbbc2be6b5e3422896172f03cc0e0fe3e722cf896ab4d3846bcb
python-dbusmock_0.14-1ubuntu2.debian.tar.xz 5.3 KiB 2df3b23f30335ce288054549452bc06aa992f15dc915cae6fe97147bd995df82
python-dbusmock_0.14-1ubuntu2.dsc 2.3 KiB c3c54659c45f5e128fb9078f2330dddce83b374d13c545bacb417e883a10fa57

View changes file

Binary packages built by this source

python-dbusmock: No summary available for python-dbusmock in ubuntu vivid.

No description available for python-dbusmock in ubuntu vivid.

python3-dbusmock: No summary available for python3-dbusmock in ubuntu vivid.

No description available for python3-dbusmock in ubuntu vivid.