It was discovered that nano allowed a possible privilege escalation through an insecure temporary file. If nano was killed while editing, the permissions granted to the emergency save file could be used by an attacker to escalate privileges using a malicious symlink.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_version": "2.5.3-2ubuntu2+esm1", "binary_name": "nano" }, { "binary_version": "2.5.3-2ubuntu2+esm1", "binary_name": "nano-dbgsym" }, { "binary_version": "2.5.3-2ubuntu2+esm1", "binary_name": "nano-tiny" }, { "binary_version": "2.5.3-2ubuntu2+esm1", "binary_name": "nano-tiny-dbgsym" }, { "binary_version": "2.5.3-2ubuntu2+esm1", "binary_name": "nano-udeb" }, { "binary_version": "2.5.3-2ubuntu2+esm1", "binary_name": "nano-udeb-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_version": "2.9.3-2ubuntu0.1~esm1", "binary_name": "nano" }, { "binary_version": "2.9.3-2ubuntu0.1~esm1", "binary_name": "nano-dbgsym" }, { "binary_version": "2.9.3-2ubuntu0.1~esm1", "binary_name": "nano-tiny" }, { "binary_version": "2.9.3-2ubuntu0.1~esm1", "binary_name": "nano-tiny-dbgsym" }, { "binary_version": "2.9.3-2ubuntu0.1~esm1", "binary_name": "nano-udeb" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4.8-1ubuntu1.1", "binary_name": "nano" }, { "binary_version": "4.8-1ubuntu1.1", "binary_name": "nano-dbgsym" }, { "binary_version": "4.8-1ubuntu1.1", "binary_name": "nano-tiny" }, { "binary_version": "4.8-1ubuntu1.1", "binary_name": "nano-tiny-dbgsym" }, { "binary_version": "4.8-1ubuntu1.1", "binary_name": "nano-udeb" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "6.2-1ubuntu0.1", "binary_name": "nano" }, { "binary_version": "6.2-1ubuntu0.1", "binary_name": "nano-dbgsym" }, { "binary_version": "6.2-1ubuntu0.1", "binary_name": "nano-tiny" }, { "binary_version": "6.2-1ubuntu0.1", "binary_name": "nano-tiny-dbgsym" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "7.2-2ubuntu0.1", "binary_name": "nano" }, { "binary_version": "7.2-2ubuntu0.1", "binary_name": "nano-dbgsym" }, { "binary_version": "7.2-2ubuntu0.1", "binary_name": "nano-tiny" }, { "binary_version": "7.2-2ubuntu0.1", "binary_name": "nano-tiny-dbgsym" } ] }