Merge lp:~ken-vandine/content-hub/15.04-lp1456628 into lp:content-hub/15.04
Status: | Merged |
---|---|
Approved by: | Michael Sheldon |
Approved revision: | 209 |
Merged at revision: | 209 |
Proposed branch: | lp:~ken-vandine/content-hub/15.04-lp1456628 |
Merge into: | lp:content-hub/15.04 |
Diff against target: |
489 lines (+192/-27) 16 files modified
CMakeLists.txt (+1/-0) debian/apparmor/content-hub-testability (+15/-0) debian/content-hub-testability.install (+1/-0) debian/control (+4/-0) debian/rules (+4/-0) debian/tests/aa-check (+41/-0) debian/tests/control (+3/-0) src/com/ubuntu/content/CMakeLists.txt (+2/-0) src/com/ubuntu/content/detail/service.h (+1/-1) src/com/ubuntu/content/detail/transfer.cpp (+19/-2) src/com/ubuntu/content/detail/transfer.h (+4/-2) src/com/ubuntu/content/utils.cpp (+51/-7) tests/peers/exporter/CMakeLists.txt (+2/-0) tests/peers/exporter/autoexporter.cpp (+21/-12) tests/peers/exporter/autoexporter.h (+4/-0) tests/peers/exporter/exporter.cpp (+19/-3) |
To merge this branch: | bzr merge lp:~ken-vandine/content-hub/15.04-lp1456628 |
Related bugs: |
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
Michael Sheldon (community) | Approve | ||
Review via email: mp+260831@code.launchpad.net |
Commit message
* SECURITY UPDATE: file disclosure via unchecked AppArmor profile
(LP: #1456628)
- Don't allow exporting of files that aren't allowed by the source apparmor profile
- CVE-2015-1327
Description of the change
Verify the source app has read access to local files being transferred
Debs can be found at http://
This can be tested by installing the content-
"content-
Should exit 0
"content-
Should exit 1
Are there any related MPs required for this MP to build/function as expected? Please list.
* No
Is your branch in sync with latest trunk (e.g. bzr pull lp:trunk -> no changes)
* Yes
Did you perform an exploratory manual test run of your code change and any related functionality on device or emulator?
* Yes
Did you successfully run all tests found in your component's Test Plan (https:/ /wiki.ubuntu. com/Process/ Merges/ TestPlan/ content- hub) on device or emulator?
* Yes
If you changed the UI, was the change specified/approved by design?
* No change
If you changed UI labels, did you update the pot file?
* No change
If you changed the packaging (debian), did you add a core-dev as a reviewer to this MP?
* I'm a core-dev, added autopkgtests, apparmor profile for testing and build depends for apparmor