An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.54.1+ds-4build3", "binary_name": "libpd-dev" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "libpd0" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "libpd0-dbgsym" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-common" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-common-dbgsym" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-core" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-core-dbgsym" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-dev" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-doc" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-extra" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-extra-dbgsym" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-gui" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-gui-l10n" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-utils" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata-utils-dbgsym" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata64" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata64-core" }, { "binary_version": "0.54.1+ds-4build3", "binary_name": "puredata64-core-dbgsym" } ] }