Format: 1.8 Date: Tue, 06 Mar 2024 15:40:00 -0300 Source: apparmor Binary: apparmor apparmor-utils libapache2-mod-apparmor libapparmor-dev libapparmor-perl libapparmor1 libpam-apparmor python3-apparmor python3-libapparmor Architecture: armhf armhf_translations Version: 2.13.3-7ubuntu5.4 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Rodrigo Figueiredo Zaiden Description: apparmor - user-space parser utility for AppArmor apparmor-utils - utilities for controlling AppArmor libapache2-mod-apparmor - changehat AppArmor library as an Apache module libapparmor-dev - AppArmor development libraries and header files libapparmor-perl - AppArmor library Perl bindings libapparmor1 - changehat AppArmor library libpam-apparmor - changehat AppArmor library as a PAM module python3-apparmor - AppArmor Python3 utility library python3-libapparmor - AppArmor library Python3 bindings Launchpad-Bugs-Fixed: 1597017 Changes: apparmor (2.13.3-7ubuntu5.4) focal-security; urgency=medium . * SECURITY UPDATE: Excessive permissions with mount rules (LP: #1597017) - d/p/CVE-2016-1585/parser-Fix-expansion-of-variables-in-unix-rules-addr.patch: add calls to filter_slashes() in parser/af_unix.cc, make it external in parser/parser.h and change it to void in parser/parser_regex.c. - d/p/CVE-2016-1585/parser-enable-variable-expansion-for-mount-type-and-.patch: add variable expansion with expand_entry_variables() in parser/mount.cc. - d/p/CVE-2016-1585/parser-call-filter-slashes-for-mount-conditionals.patch: add calls to filter_slashes() in parser/mount.cc. - d/p/CVE-2016-1585/Support-rule-qualifiers-in-regression-tests.patch: update rule qualifiers in regression tests in tests/regression/apparmor/mkprofile.pl and tests/regression/apparmor/capabilities.sh. - d/p/CVE-2016-1585/Merge-Fix-mount-rules-encoding.patch: fix mount rules encoding in parser/mount.cc, parser/mount.h, parser/parser.h and fix multiple test cases in parser/tst/simple_tests/mount/*. - d/p/CVE-2016-1585/Merge-expand-mount-tests.patch: expand mount regression tests in tests/regression/apparmor/Makefile, tests/regression/apparmor/mount.c, tests/regression/apparmor/mount.sh and tests/regression/apparmor/mkprofile.pl. - d/p/CVE-2016-1585/Merge-Issue-312-added-missing-kernel-mount-options.patch: add missing kernel mount options flag in parser/apparmor.d.pod, parser/mount.cc, parser/mount.h, tests/regression/apparmor/mount.sh and parser/tst/simple_tests/mount/*. - d/p/CVE-2016-1585/Merge-extend-test-profiles-for-mount.patch: update test profiles in parser/tst/simple_tests/mount/*. - d/p/CVE-2016-1585/Merge-parser-fix-parsing-of-source-as-mount-point-fo.patch: update gen_policy_change_mount_type() in parser/mount.cc and also updated tests on parser/tst/simple_tests/mount/* and tests/regression/apparmor/mount.sh. - d/p/CVE-2016-1585/parser-fix-rule-flag-generation-change_mount-type-ru.patch: add device checks in gen_flag_rules() in parser/mount.cc and tests in parser/tst/simple_tests/mount/*, parser/tst/equality.sh, tests/regression/apparmor/mount.sh and utils/test/test-parser-simple-tests.py. - d/p/CVE-2016-1585/Fix-build-failure-in-df4ed537e-allow-reading-of-etc-.patch: remove the WARN_DEPRECATED flag in pwarn call in parser/mount.cc. - d/p/CVE-2016-1585/parser-Deprecation-warning-should-not-have-been-back.patch: remove deprecation warning message in parser/mount.cc. - CVE-2016-1585 Checksums-Sha1: 3b661fa89e9355eeb80cac30936d2e00d7d0634e 1775264 apparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 9467984ae93170c5b428b0b7b3bc9e7b0c33a922 51056 apparmor-utils_2.13.3-7ubuntu5.4_armhf.deb 307d5430e21c9fdf260d222aac4561ae37dafac7 12515 apparmor_2.13.3-7ubuntu5.4_armhf.buildinfo 22e8f4a1864c80cd51a69d2f63e0c36028141c18 436640 apparmor_2.13.3-7ubuntu5.4_armhf.deb d4e446281b8315d36a324a831d08cc79d1270a36 208498 apparmor_2.13.3-7ubuntu5.4_armhf_translations.tar.gz 11b19742b8b4bd2cdd4368128e713113e8e89605 18020 libapache2-mod-apparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 57161285855c30de905a33a54a3df54e54d56e23 14056 libapache2-mod-apparmor_2.13.3-7ubuntu5.4_armhf.deb e181bc5a137ca0ddc918bf35ef86486440ddaf7e 69692 libapparmor-dev_2.13.3-7ubuntu5.4_armhf.deb 61e3b4cd063642e1a2613a013e263a4a6de761ca 139892 libapparmor-perl-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb b27940ad97cae24eda7f36a07180ee1f27b16d9c 30332 libapparmor-perl_2.13.3-7ubuntu5.4_armhf.deb 3be5d463301c1bad63ce8377bcd1f2c4ca93feb2 68452 libapparmor1-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 7c28d60d44bbfdfbb533dda35ed50a22f33d9506 30944 libapparmor1_2.13.3-7ubuntu5.4_armhf.deb e4815a5bf711323bc7877da6f9fc23b2a07b39cd 8132 libpam-apparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 9090e2122b1e064823be6435b29a98efc183ccf8 7024 libpam-apparmor_2.13.3-7ubuntu5.4_armhf.deb f13136acfea54edaa2036913954fa8d9f62acdbe 79824 python3-apparmor_2.13.3-7ubuntu5.4_armhf.deb 9b342c661c921448c0c3a7d08b59a0c1113c7401 102280 python3-libapparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb a04f889adb308bbab2fde5da03fe666ba5b00eb4 22968 python3-libapparmor_2.13.3-7ubuntu5.4_armhf.deb Checksums-Sha256: 918a6e54f83f5ffe0ce60046eb99c587d629c60f9ac1b6c7d32f804c3650b8e0 1775264 apparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 23e5d4d3dd54128b9fd18a70ebd9b306d6501e496ad971c956a95ddfd8c7b9cd 51056 apparmor-utils_2.13.3-7ubuntu5.4_armhf.deb 1b14925425db122e50249fad8000e57b7afa377ed9f83f2c71b6251dfc4bad37 12515 apparmor_2.13.3-7ubuntu5.4_armhf.buildinfo 5282fc6b0b98affb3b5947358b4b93d27e939bf2216382b957018e1a01bdc005 436640 apparmor_2.13.3-7ubuntu5.4_armhf.deb a42cf0bf7d812076a6017f4ebaa28cc084192c6372c54b9ae0842bdc146f4ca1 208498 apparmor_2.13.3-7ubuntu5.4_armhf_translations.tar.gz ee4233cb3a29c4e9f4ba505fa79cdc3c622fb715fab47306dabc00c4c79406db 18020 libapache2-mod-apparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb c7b9ba76f31980b469b1da37c2d967bae164973f8e72e1f708f0c3b5e17aeec7 14056 libapache2-mod-apparmor_2.13.3-7ubuntu5.4_armhf.deb 9a6137ccbc1017e2947ffbd5a4137ae5fd8369a267c137762e1c83b587da0472 69692 libapparmor-dev_2.13.3-7ubuntu5.4_armhf.deb fda98871b77434da4921abba5f91e01b39f5ca31bb9087b6c10616dde6a5a072 139892 libapparmor-perl-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 17d4a301293c579432f7ed6320b24c8be8cf461c99568e066a0727e9cbb8f200 30332 libapparmor-perl_2.13.3-7ubuntu5.4_armhf.deb e5b43beba136fcbc2140f1aa2a62fb364ff6f0434b9d4bea7b190ce5df6933ee 68452 libapparmor1-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 33cb2eac95cb86e2de72fb31aab2745814fc315e27c33f36f0b9b1fc77abfe54 30944 libapparmor1_2.13.3-7ubuntu5.4_armhf.deb d136c15afbbc588847b6aa746db20b67a01756527f370fd151610e881014e379 8132 libpam-apparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb ff8e5204e652629d41e943f7585fc2f7c99df02f7de21598c8b1249013f45a0f 7024 libpam-apparmor_2.13.3-7ubuntu5.4_armhf.deb ef62a36e17628e67ab1493d6146ad0fcb63240af2c4965a2e82b35dfc7982461 79824 python3-apparmor_2.13.3-7ubuntu5.4_armhf.deb 4fad7d4e7abe1be5fae411a3c7926a1410811bf593762df5e258c402b5015ca2 102280 python3-libapparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 08300a3cbe4b0548f42f9fab947b6293a7c8ca86c943a3774d31a4515512ec77 22968 python3-libapparmor_2.13.3-7ubuntu5.4_armhf.deb Files: d2c3fdafbca1dd12a555e5be3e664fed 1775264 debug optional apparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 025fee91e44d6327bf0615f1d691b1ef 51056 admin optional apparmor-utils_2.13.3-7ubuntu5.4_armhf.deb 031a78d3cc526eab9f5225aa0527a272 12515 admin optional apparmor_2.13.3-7ubuntu5.4_armhf.buildinfo 82a01168b60e9f3fc3e416cce1df9ee5 436640 admin optional apparmor_2.13.3-7ubuntu5.4_armhf.deb 06576b8c70b5061459d08ce5660d2558 208498 raw-translations - apparmor_2.13.3-7ubuntu5.4_armhf_translations.tar.gz 7c8cba597fe2123791e847157362f156 18020 debug optional libapache2-mod-apparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb a16f6367ccb1e184543ea948ffefa9ef 14056 httpd optional libapache2-mod-apparmor_2.13.3-7ubuntu5.4_armhf.deb 7535898d7d542c77ac9843469dc232f7 69692 libdevel optional libapparmor-dev_2.13.3-7ubuntu5.4_armhf.deb 6e6680adc86a6ca35b75596ca863b614 139892 debug optional libapparmor-perl-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb e7eb19d51c16cc24bca8e4d05da6b546 30332 perl optional libapparmor-perl_2.13.3-7ubuntu5.4_armhf.deb 2b93533c531fa7209404f4c0013deb07 68452 debug optional libapparmor1-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 2cabd24354f5b2cc316b7362db3377e1 30944 libs optional libapparmor1_2.13.3-7ubuntu5.4_armhf.deb 8fdeaf3aaf79bdafeebdccd4b5a3b706 8132 debug optional libpam-apparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb 30f8e559f01a3ace9f68345f89ddc320 7024 admin optional libpam-apparmor_2.13.3-7ubuntu5.4_armhf.deb 3f70d53b57a3e761b31149a0093cd59c 79824 python optional python3-apparmor_2.13.3-7ubuntu5.4_armhf.deb bc2967351ade034b6aaec756ab747590 102280 debug optional python3-libapparmor-dbgsym_2.13.3-7ubuntu5.4_armhf.ddeb bb8cb9425974eab35c2f5945dd2c9986 22968 python optional python3-libapparmor_2.13.3-7ubuntu5.4_armhf.deb Original-Maintainer: Debian AppArmor Team