|
|
Log in / Subscribe / Register

Ubuntu alert USN-8109-1 (debian-goodies)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8109-1] Debian Goodies vulnerability
Date:  Mon, 23 Mar 2026 08:56:21 +0000
Message-ID:  <E1w4b5B-0000wF-6e@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8109-1 March 18, 2026 debian-goodies vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Debian Goodies could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - debian-goodies: Small toolbox-style utilities for Debian systems Details: Jakub Wilk discovered that debmany in Debian Goodies incorrectly handled certain deb files. An attacker could possibly use this issue to execute arbitrary shell commands. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS debian-goodies 0.88.1ubuntu1.3 Ubuntu 18.04 LTS debian-goodies 0.79ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS debian-goodies 0.64ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS debian-goodies 0.63ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8109-1 CVE-2023-27635 Package Information: https://launchpad.net/ubuntu/+source/debian-goodies/0.88....


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmm8D78ACgkQcpJm3tlz hgHUZw/+IBKmo1kloy5aaAAAbd0lCXxvqWJPBjDuv7FGvMoAWETHK3HKgQZ4vck9 kwghh32wZfR8mLfJ99OeTmNLds73XbXylPloFoQ1kkdxrJ4NLo9cGgbcpjW0ST+c ute5qqglQQoQxlntjQlFVecB/wwazXhT22eWsycUOEQ9jx9ZeAJgHEndUXKit+4B CQlTtgMDtbykRSqxoTbenzOroDCynJWeo6ste7Qj6kvxbXN7r73Pekt8ic/6RotV PjvORdSlAGp7pUQSW+YiacycjF9c5eAxovnxFd6FoiJ+ZVNGCc/cmeuNSa6NgBtr XVELqAR1Z1DdTgtUUB3dt0djIOvS+Nhx2187k0riPBftFbuhvOLXem+bZi7NwkHT 66D3RglUAnqvE7TUCsL2Ka/E7Ar9AQIP5k6GPLddZOxkyi/ddcP/BGgORu2XS16H 2E1j/E3J80A85tO1kDTG+nCJ3usaoIBXEnaw2b92KBmtOOVPO0lefTEFKamJFz7m ZXdFgXa5H/EYPjsNpH12V+8HeNkTj3W/a+iuX73d29YK8bf031f27Z3s4HEArwE3 Q/suqFoT2WTnY00r+BmzoHRQHSNwCOW4Tn5bf2ONi35psOthOmOi7zKYQNKcV/Hc 6ix5rTe0TbbaSm+iWzQlXK9F+O4UGH4/aB/hhppmSuAMjzlU0d8= =GeOQ -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds