An Aptdaemon security update has been released for Ubuntu Linux 16.04 LTS, 18.04 LTS, 20.04 LTS, and 20.10.
==========================================================================
Ubuntu Security Notice USN-4664-1
December 08, 2020
aptdaemon vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Aptdaemon.
Software Description:
- aptdaemon: transaction based package management service
Details:
Kevin Backhouse discovered that Aptdaemon incorrectly handled certain
properties. A local attacker could use this issue to test for the presence
of local files. (CVE-2020-16128)
Kevin Backhouse discovered that Aptdaemon incorrectly handled permission
checks. A local attacker could possibly use this issue to cause a denial of
service. (CVE-2020-27349)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.10:
aptdaemon 1.1.1+bzr982-0ubuntu34.1
Ubuntu 20.04 LTS:
aptdaemon 1.1.1+bzr982-0ubuntu32.3
Ubuntu 18.04 LTS:
aptdaemon 1.1.1+bzr982-0ubuntu19.5
Ubuntu 16.04 LTS:
aptdaemon 1.1.1+bzr982-0ubuntu14.5
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://usn.ubuntu.com/4664-1
CVE-2020-16128, CVE-2020-27349
Package Information:
https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu34.1
https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu32.3
https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu19.5
https://launchpad.net/ubuntu/+source/aptdaemon/1.1.1+bzr982-0ubuntu14.5