Candidate: CVE-2015-8768 PublicDate: 2017-02-13 18:59:00 UTC References: https://insights.ubuntu.com/2015/10/15/update-on-ubuntu-phone-security-issue/ https://ubuntu.com/security/notices/USN-2771-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8768 http://www.openwall.com/lists/oss-security/2016/01/11/8 Description: click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone. Ubuntu-Description: Notes: jdstrand> app can ship a crafted .click directory that can be used to trick click into installing unintended security policy jdstrand> snappy not affected per me and mvo jdstrand> patch from cjwatson, but not committed to bzr yet jdstrand> updates also needed for vivid stable-phone-overlay and wily stable-phone-overlay. Bugs: https://launchpad.net/bugs/1506467 Priority: critical Discovered-by: Assigned-to: jdstrand CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_click: upstream: https://code.launchpad.net/~cjwatson/click/audit-missing-dot-slash/+merge/274554 upstream_click: released (0.4.41) precise_click: DNE trusty_click: released (0.4.21.1ubuntu0.2) trusty/esm_click: DNE (trusty was released [0.4.21.1ubuntu0.2]) vivid_click: released (0.4.38.5ubuntu0.2) vivid/ubuntu-core_click: DNE vivid/stable-phone-overlay_click: released (0.4.40+15.10.20151006-0ubuntu1.1) devel_click: released (0.4.39.1+15.10.20150702-0ubuntu2)