Vulnerability Description
UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications. Before UDM version 1.2+16.04.20160408-0ubuntu1 any confined application could make use of the UDM C++ API to run arbitrary commands in an unconfined environment as the phablet user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Download Manager | - |
Related Weaknesses (CWE)
References
- https://bazaar.launchpad.net/~phablet-team/ubuntu-download-manager/trunk/revisioThird Party Advisory
- https://bazaar.launchpad.net/~phablet-team/ubuntu-download-manager/trunk/revisioThird Party Advisory
FAQ
What is CVE-2016-1579?
CVE-2016-1579 is a vulnerability with a CVSS score of 6.7 (MEDIUM). UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications....
How severe is CVE-2016-1579?
CVE-2016-1579 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1579?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Download Manager.