USN-6912-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-6912-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6912-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6912-1
Related
Published
2024-07-24T08:18:12.576031Z
Modified
2024-07-24T08:18:12.576031Z
Summary
provd vulnerability
Details

James Henstridge discovered that provd incorrectly handled environment variables. A local attacker could possibly use this issue to run arbitrary programs and escalate privileges.

References

Affected packages

Ubuntu:24.04:LTS / provd

Package

Name
provd
Purl
pkg:deb/ubuntu/provd@0.1.2+24.04?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.2+24.04

Affected versions

0.*

0.1.0
0.1.1
0.1.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "provd": "0.1.2+24.04",
            "provd-dbgsym": "0.1.2+24.04"
        }
    ]
}