Timeshift vulnerability
A security issue affects these releases of Ubuntu and its
derivatives:
* Ubuntu 19.10
Summary
Timeshift could be made to run programs as an administrator.
Software Description
* timeshift - System restore utility
Details
Matthias Gerstner discovered that Timeshift did not securely
create temporary files. An attacker could exploit a race condition
in Timeshift and potentially execute arbitrary commands as root.
Update instructions
The problem can be corrected by updating your system to the
following package versions:
Ubuntu 19.10
timeshift - 19.01+ds-2ubuntu0.1
To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system update will make all the necessary
changes.
References
* CVE-2020-10174
--- Mystic BBS v1.12 A45 (Linux/64)
* Origin: BZ&BZ BBS (21:4/110)