========================================================================== Ubuntu Security Notice USN-2618-1 May 21, 2015 python-dbusmock vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.10 - Ubuntu 14.04 LTS Summary: python-dbusmock could be tricked into running arbitrary programs. Software Description: - python-dbusmock: mock D-Bus objects for tests Details: It was discovered that python-dbusmock incorrectly handled template loading from shared directories. A local attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: python-dbusmock 0.14-1ubuntu2 python3-dbusmock 0.14-1ubuntu2 Ubuntu 14.10: python-dbusmock 0.11.4-1ubuntu1 python3-dbusmock 0.11.4-1ubuntu1 Ubuntu 14.04 LTS: python-dbusmock 0.10.1-1ubuntu1 python3-dbusmock 0.10.1-1ubuntu1 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2618-1 CVE-2015-1326 Package Information: https://launchpad.net/ubuntu/+source/python-dbusmock/0.14-1ubuntu2 https://launchpad.net/ubuntu/+source/python-dbusmock/0.11.4-1ubuntu1 https://launchpad.net/ubuntu/+source/python-dbusmock/0.10.1-1ubuntu1