Ubuntu Security Notice 412-1 - Dean Gaudet discovered that the GeoIP update tool did not validate the filename responses from the update server. A malicious server, or man-in-the-middle system posing as a server, could write to arbitrary files with user privileges.
75b01f4e95484735f0268d67b3306e71226620a309e2561ff38b6f456e600f2c