Format: 1.8 Date: Tue, 06 Mar 2024 15:40:00 -0300 Source: apparmor Binary: apparmor apparmor-utils libapache2-mod-apparmor libapparmor-dev libapparmor-perl libapparmor1 libpam-apparmor python3-apparmor python3-libapparmor Architecture: riscv64 riscv64_translations Version: 2.13.3-7ubuntu5.4 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Rodrigo Figueiredo Zaiden Description: apparmor - user-space parser utility for AppArmor apparmor-utils - utilities for controlling AppArmor libapache2-mod-apparmor - changehat AppArmor library as an Apache module libapparmor-dev - AppArmor development libraries and header files libapparmor-perl - AppArmor library Perl bindings libapparmor1 - changehat AppArmor library libpam-apparmor - changehat AppArmor library as a PAM module python3-apparmor - AppArmor Python3 utility library python3-libapparmor - AppArmor library Python3 bindings Launchpad-Bugs-Fixed: 1597017 Changes: apparmor (2.13.3-7ubuntu5.4) focal-security; urgency=medium . * SECURITY UPDATE: Excessive permissions with mount rules (LP: #1597017) - d/p/CVE-2016-1585/parser-Fix-expansion-of-variables-in-unix-rules-addr.patch: add calls to filter_slashes() in parser/af_unix.cc, make it external in parser/parser.h and change it to void in parser/parser_regex.c. - d/p/CVE-2016-1585/parser-enable-variable-expansion-for-mount-type-and-.patch: add variable expansion with expand_entry_variables() in parser/mount.cc. - d/p/CVE-2016-1585/parser-call-filter-slashes-for-mount-conditionals.patch: add calls to filter_slashes() in parser/mount.cc. - d/p/CVE-2016-1585/Support-rule-qualifiers-in-regression-tests.patch: update rule qualifiers in regression tests in tests/regression/apparmor/mkprofile.pl and tests/regression/apparmor/capabilities.sh. - d/p/CVE-2016-1585/Merge-Fix-mount-rules-encoding.patch: fix mount rules encoding in parser/mount.cc, parser/mount.h, parser/parser.h and fix multiple test cases in parser/tst/simple_tests/mount/*. - d/p/CVE-2016-1585/Merge-expand-mount-tests.patch: expand mount regression tests in tests/regression/apparmor/Makefile, tests/regression/apparmor/mount.c, tests/regression/apparmor/mount.sh and tests/regression/apparmor/mkprofile.pl. - d/p/CVE-2016-1585/Merge-Issue-312-added-missing-kernel-mount-options.patch: add missing kernel mount options flag in parser/apparmor.d.pod, parser/mount.cc, parser/mount.h, tests/regression/apparmor/mount.sh and parser/tst/simple_tests/mount/*. - d/p/CVE-2016-1585/Merge-extend-test-profiles-for-mount.patch: update test profiles in parser/tst/simple_tests/mount/*. - d/p/CVE-2016-1585/Merge-parser-fix-parsing-of-source-as-mount-point-fo.patch: update gen_policy_change_mount_type() in parser/mount.cc and also updated tests on parser/tst/simple_tests/mount/* and tests/regression/apparmor/mount.sh. - d/p/CVE-2016-1585/parser-fix-rule-flag-generation-change_mount-type-ru.patch: add device checks in gen_flag_rules() in parser/mount.cc and tests in parser/tst/simple_tests/mount/*, parser/tst/equality.sh, tests/regression/apparmor/mount.sh and utils/test/test-parser-simple-tests.py. - d/p/CVE-2016-1585/Fix-build-failure-in-df4ed537e-allow-reading-of-etc-.patch: remove the WARN_DEPRECATED flag in pwarn call in parser/mount.cc. - d/p/CVE-2016-1585/parser-Deprecation-warning-should-not-have-been-back.patch: remove deprecation warning message in parser/mount.cc. - CVE-2016-1585 Checksums-Sha1: a892732e819360546bfe3c9372dd57cfa82a982b 1474012 apparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 3074e16b5be14000f7cd338f9fd30346da90a0c5 51060 apparmor-utils_2.13.3-7ubuntu5.4_riscv64.deb 644509dd104f168817ccaaec91b12b456dc6b863 12493 apparmor_2.13.3-7ubuntu5.4_riscv64.buildinfo 80641fcf22f27f6db43cd12148320c8bbf74cebd 511108 apparmor_2.13.3-7ubuntu5.4_riscv64.deb 5eb06a0a6d879a82aaa9b20e508546fc398d2864 211542 apparmor_2.13.3-7ubuntu5.4_riscv64_translations.tar.gz f6008a5171ce791723630f581f3cdff63d6af914 18164 libapache2-mod-apparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 4b92b650294da4fa8932b15d4665f91a0ae919ab 13896 libapache2-mod-apparmor_2.13.3-7ubuntu5.4_riscv64.deb d897582ab4b4fdc6988a519d2bb2a262e7b64fd3 97528 libapparmor-dev_2.13.3-7ubuntu5.4_riscv64.deb cdd5dea940393ebdcf7c4d748e5615d449ba1de6 132616 libapparmor-perl-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 869947907b53c3376f84d9f5220133b20a6e509f 30476 libapparmor-perl_2.13.3-7ubuntu5.4_riscv64.deb 717f778c7c0ec454489649efbea7541a80facafa 67796 libapparmor1-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 4302e1f2d85d9129cfb2b0b3b51124029ab9f1f6 32204 libapparmor1_2.13.3-7ubuntu5.4_riscv64.deb 519d11ede355cd940e3287d3e48039c65d734821 7944 libpam-apparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb d50e30aef587a8489d0a4a3093e992b44cf7aac6 6868 libpam-apparmor_2.13.3-7ubuntu5.4_riscv64.deb 71dc765bf936e6da72e11c3583d947e9868dc138 79828 python3-apparmor_2.13.3-7ubuntu5.4_riscv64.deb c124a8d8e936fcda3db47d2c5e671763b35f3d83 98384 python3-libapparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 41a339b7622ffd37e1e869e3df3a4f9e57b0635e 23032 python3-libapparmor_2.13.3-7ubuntu5.4_riscv64.deb Checksums-Sha256: 24a8e5b4b18197c6c685f4f90e2d8b7a1dbd16aad33b13f85506c0a203ba9909 1474012 apparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 2197cdf507196c7c8ff79fa072072d957c9ee3b3c3af50d05c907458a189670a 51060 apparmor-utils_2.13.3-7ubuntu5.4_riscv64.deb df4b61fbde427df7a5d17e02ad95c6ff4c5cd015f0259de1712a75f9b688b773 12493 apparmor_2.13.3-7ubuntu5.4_riscv64.buildinfo 3eed5d3c6bdb5d6dc4142733fa33879abf18f04f85a685216311ce44b899b370 511108 apparmor_2.13.3-7ubuntu5.4_riscv64.deb 7f996d6a5d94a676933d6a7e0b12558b3a23674ac753bb343a01cde0a807c0f6 211542 apparmor_2.13.3-7ubuntu5.4_riscv64_translations.tar.gz ec0f059a6323b5aab1566eca4bfb9e9735b4ee9e6b6a7e929e389ab01c236e1a 18164 libapache2-mod-apparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 0ad2efb9f4681e2de0439d32c85e5fd83b8415c69bca62a847f11a5914fa5891 13896 libapache2-mod-apparmor_2.13.3-7ubuntu5.4_riscv64.deb 5c8d89f5c9be032406ff02442e7d0ab53b3d461c0e01073462e3ebddf95ff9be 97528 libapparmor-dev_2.13.3-7ubuntu5.4_riscv64.deb 14b187de26ecbffbeccf30a2a8c6d8930a59c5a3973eb44df6d63d37d06b4782 132616 libapparmor-perl-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb e9abf0f62186dfc5b8eef07f19c890a53be328229e83014893e7f2f0b757af0e 30476 libapparmor-perl_2.13.3-7ubuntu5.4_riscv64.deb 5b89c14c33af1d6af0d9faf06540b4d9de6d702fdb69f2d77c428a15257b5fae 67796 libapparmor1-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb abcaa9c328435239936e61d093ebb1cfcd4d5968b23cf4779284dc478f50625d 32204 libapparmor1_2.13.3-7ubuntu5.4_riscv64.deb 07f54022aaa23289b292410e0438f2acaceed3435e0d7f580fe6fd83902e8095 7944 libpam-apparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 7b34a468330710ea74299fb935f1c4654a5b1b51683f28bc97acb0f1b187f3e4 6868 libpam-apparmor_2.13.3-7ubuntu5.4_riscv64.deb 97b06c4faf3dee34303156aaf160d003c819ca039ee27eb4b89e7748e9793630 79828 python3-apparmor_2.13.3-7ubuntu5.4_riscv64.deb 8ad5ca5889e18392f08783e50ce68c255e0f5e6c6f4e0c46132f969ff50a7a38 98384 python3-libapparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb ac3169f7647fb2f1ac439b0fbc8f3a46435e52060f146b0f50a42c216e7ee4c1 23032 python3-libapparmor_2.13.3-7ubuntu5.4_riscv64.deb Files: 05f373e63d4e3749244778ae3e74ec41 1474012 debug optional apparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb e2265965255526d828d4e3bbfe7e0831 51060 admin optional apparmor-utils_2.13.3-7ubuntu5.4_riscv64.deb b84a360406dcd894c146d3ba37d326b1 12493 admin optional apparmor_2.13.3-7ubuntu5.4_riscv64.buildinfo 2e4796555634aaa827000badaa8dd13a 511108 admin optional apparmor_2.13.3-7ubuntu5.4_riscv64.deb 4b46478cacc64f59b72e4a235df1f40c 211542 raw-translations - apparmor_2.13.3-7ubuntu5.4_riscv64_translations.tar.gz 5a9a56f3ececc47e87d51f3e7d63aaf2 18164 debug optional libapache2-mod-apparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb cd79d2f7cb5ea577e0249f503c11a51d 13896 httpd optional libapache2-mod-apparmor_2.13.3-7ubuntu5.4_riscv64.deb 4dc9527b992b3cfc2c028dc750bdc3c9 97528 libdevel optional libapparmor-dev_2.13.3-7ubuntu5.4_riscv64.deb 0270fd245d0f8ec028b3aa85a0fe523a 132616 debug optional libapparmor-perl-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb ba828cc34d56b4cb2274130564ae3691 30476 perl optional libapparmor-perl_2.13.3-7ubuntu5.4_riscv64.deb 8af30b1b55e25973ec69d60f721bb7a9 67796 debug optional libapparmor1-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 45e2a3427efb1d0a92a9b88befaf31ad 32204 libs optional libapparmor1_2.13.3-7ubuntu5.4_riscv64.deb b610ed2a3a43f2170d7583192ab9adde 7944 debug optional libpam-apparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb c9fc75cad5d58874fc47ba443a0ceb42 6868 admin optional libpam-apparmor_2.13.3-7ubuntu5.4_riscv64.deb 2e19430a75fbfd7e3894f41da5075091 79828 python optional python3-apparmor_2.13.3-7ubuntu5.4_riscv64.deb f00fb7d11de944ce81b71cb5a98158bc 98384 debug optional python3-libapparmor-dbgsym_2.13.3-7ubuntu5.4_riscv64.ddeb 7dd1a32456bea6427ddd0f18648ba583 23032 python optional python3-libapparmor_2.13.3-7ubuntu5.4_riscv64.deb Original-Maintainer: Debian AppArmor Team