Ubuntu 6586 Published by

A security flaw has been found in the Ubuntu Advantage Desktop Daemon, which may expose personal data. Marco Trevisan revealed that the Daemon shared the Pro token with unprivileged users, allowing an attacker to get unauthorized access to an Ubuntu Pro subscription. Updated packages are available for Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS:

[USN-7063-1] Ubuntu Advantage Desktop Daemon vulnerability




[USN-7063-1] Ubuntu Advantage Desktop Daemon vulnerability


==========================================================================
Ubuntu Security Notice USN-7063-1
October 11, 2024

ubuntu-advantage-desktop-daemon vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- - Ubuntu 24.04 LTS
- - Ubuntu 22.04 LTS
- - Ubuntu 20.04 LTS
- - Ubuntu 18.04 LTS
- - Ubuntu 16.04 LTS

Summary:

Ubuntu Advantage Desktop Daemon could be made to expose sensitive information.

Software Description:
- - ubuntu-advantage-desktop-daemon: Daemon to allow access to
ubuntu-advantage via D-Bus

Details:

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon leaked
the Pro token to unprivileged users by passing the token as an argument
in plaintext. An attacker could use this issue to gain unauthorized access
to an Ubuntu Pro subscription. (CVE-2024-6388)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
ubuntu-advantage-desktop-daemon 1.11ubuntu0.1

Ubuntu 22.04 LTS
ubuntu-advantage-desktop-daemon 1.10.ubuntu0.22.04.2

Ubuntu 20.04 LTS
ubuntu-advantage-desktop-daemon 1.10.ubuntu0.20.04.1

Ubuntu 18.04 LTS
ubuntu-advantage-desktop-daemon 1.10.ubuntu0.18.04.1~esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
ubuntu-advantage-desktop-daemon 1.10.ubuntu0.16.04.1~esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7063-1
CVE-2024-6388

Package Information:
https://launchpad.net/ubuntu/+source/ubuntu-advantage-desktop-daemon/1.11ubuntu0.1
https://launchpad.net/ubuntu/+source/ubuntu-advantage-desktop-daemon/1.10.ubuntu0.22.04.2
https://launchpad.net/ubuntu/+source/ubuntu-advantage-desktop-daemon/1.10.ubuntu0.20.04.1