USN-3784-1

Source
https://ubuntu.com/security/notices/USN-3784-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3784-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-3784-1
Published
2018-10-04T21:34:40Z
Modified
2026-04-22T09:50:44.778185Z
Summary
AppArmor update
Details

As a security improvement, this update adjusts the private-files abstraction to disallow writing to thumbnailer configuration files. Additionally adjust the private-files, private-files-strict and user-files abstractions to disallow writes on parent directories of sensitive files.

References

Affected packages

Ubuntu:14.04:LTS / apparmor

Package

Name
apparmor
Purl
pkg:deb/ubuntu/apparmor@2.10.95-0ubuntu2.6~14.04.4?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.95-0ubuntu2.6~14.04.4

Affected versions

2.*
2.8.0-0ubuntu31
2.8.0-0ubuntu32
2.8.0-0ubuntu33
2.8.0-0ubuntu34
2.8.0-0ubuntu35
2.8.0-0ubuntu37
2.8.0-0ubuntu38
2.8.95~2430-0ubuntu1
2.8.95~2430-0ubuntu2
2.8.95~2430-0ubuntu3
2.8.95~2430-0ubuntu5
2.8.95~2430-0ubuntu5.1
2.8.95~2430-0ubuntu5.2
2.8.95~2430-0ubuntu5.3
2.10.95-0ubuntu2.5~14.04.1
2.10.95-0ubuntu2.6~14.04.1
2.10.95-0ubuntu2.6~14.04.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "apparmor-docs"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "apparmor-easyprof"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "apparmor-notify"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "apparmor-profiles"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "apparmor-utils"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "dh-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "libapache2-mod-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "libapparmor-perl"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "libapparmor1"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "libpam-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "python-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "python-libapparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "python3-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.6~14.04.4",
            "binary_name": "python3-libapparmor"
        }
    ],
    "availability": "No subscription required"
}

Database specific

cves_map
{
    "cves": [],
    "ecosystem": "Ubuntu:14.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3784-1.json"

Ubuntu:16.04:LTS / apparmor

Package

Name
apparmor
Purl
pkg:deb/ubuntu/apparmor@2.10.95-0ubuntu2.10?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.95-0ubuntu2.10

Affected versions

2.*
2.10-0ubuntu6
2.10-0ubuntu7
2.10-0ubuntu8
2.10-0ubuntu10
2.10-0ubuntu11
2.10-0ubuntu12
2.10-3ubuntu1
2.10-3ubuntu2
2.10.95-0ubuntu1
2.10.95-0ubuntu2
2.10.95-0ubuntu2.2
2.10.95-0ubuntu2.5
2.10.95-0ubuntu2.6
2.10.95-0ubuntu2.7
2.10.95-0ubuntu2.8
2.10.95-0ubuntu2.9

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "apparmor-docs"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "apparmor-easyprof"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "apparmor-notify"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "apparmor-profiles"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "apparmor-utils"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "dh-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "libapache2-mod-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "libapparmor-perl"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "libapparmor1"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "libpam-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "python-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "python-libapparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "python3-apparmor"
        },
        {
            "binary_version": "2.10.95-0ubuntu2.10",
            "binary_name": "python3-libapparmor"
        }
    ],
    "availability": "No subscription required"
}

Database specific

cves_map
{
    "cves": [],
    "ecosystem": "Ubuntu:16.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3784-1.json"

Ubuntu:18.04:LTS / apparmor

Package

Name
apparmor
Purl
pkg:deb/ubuntu/apparmor@2.12-4ubuntu5.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.12-4ubuntu5.1

Affected versions

2.*
2.11.0-2ubuntu17
2.11.0-2ubuntu18
2.11.0-2ubuntu19
2.12-4ubuntu1
2.12-4ubuntu2
2.12-4ubuntu3
2.12-4ubuntu4
2.12-4ubuntu5

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "apparmor"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "apparmor-easyprof"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "apparmor-notify"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "apparmor-profiles"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "apparmor-utils"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "dh-apparmor"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "libapache2-mod-apparmor"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "libapparmor-perl"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "libapparmor1"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "libpam-apparmor"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "python-apparmor"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "python-libapparmor"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "python3-apparmor"
        },
        {
            "binary_version": "2.12-4ubuntu5.1",
            "binary_name": "python3-libapparmor"
        }
    ],
    "availability": "No subscription required"
}

Database specific

cves_map
{
    "cves": [],
    "ecosystem": "Ubuntu:18.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3784-1.json"