Login
Newsletter
Werbung

Sicherheit: Löschen beliebiger Dateien in gdm-guest-session
Aktuelle Meldungen Distributionen
Name: Löschen beliebiger Dateien in gdm-guest-session
ID: USN-1399-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04
Datum: Di, 13. März 2012, 16:36
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0943
Applikationen: gdm-guest-session

Originalnachricht


--===============0651465170121438060==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-+aCQe208oQMdIehb7V11"


--=-+aCQe208oQMdIehb7V11
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1399-1
March 13, 2012

gdm-guest-session vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

gdm-guest-session could be made to delete files as the administrator.

Software Description:
- gdm-guest-session: gdm extension for guest session

Details:

Ryan Lortie discovered that gdm-guest-session improperly cleaned out
certain guest session files. A local attacker could use this issue to
delete arbitrary files.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
gdm-guest-session 0.24ubuntu0.1

Ubuntu 10.10:
gdm-guest-session 0.17ubuntu0.1

Ubuntu 10.04 LTS:
gdm-guest-session 0.15ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1399-1
CVE-2012-0943

Package Information:
https://launchpad.net/ubuntu/+source/gdm-guest-session/0.24ubuntu0.1
https://launchpad.net/ubuntu/+source/gdm-guest-session/0.17ubuntu0.1
https://launchpad.net/ubuntu/+source/gdm-guest-session/0.15ubuntu0.1



--ÛaCQe208oQMdIehb7V11
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJPX1BcAAoJEGVp2FWnRL6T610P/jahbfk6rsBf3+bQTxlMHymT
bzwbckKe/U2Ge8UVe74M6DIXbG+zzYX6FE3WWswoTByoxWH2STJs1XynjyC0tssm
ELKU+6Nnm7X8/rAVLp1/MDH/UoGOksYGxl4MaxPnhrQrGbgJ5C1MaPZhFamdrLR8
lfqVKlHXoDcytTvmS+wuds1i1JjBIyHbvfjDZwUGvzlT2veiHNcC1WjyeSlfU9A4
pw9H5EjIXqU1JZH14FhpFX4TT17ErjcfI5EJldZd92UMopBDoxxUE5Cn7v29hB0x
VcTa5oavdZEGPzZZ1SSXy6kei/k/LuxZPGFuvxZlpRJ7EeOkO6MC+1itP/1JQmap
KBTp+KLaKNB/kf20dbQW3j3Qr3bU2pubmctMUtqlFu2pbA5lOX/gO/9DppXWcxzX
45GtQrteTNDw8Os+7kx16XRbOccsmpqqaWDRbB9A2tkw2q3jLeEAEwp7iOWjhFHe
+j4wiOvTatgA12tVWhyz/JjDwqhHRplfzJfP3othaYqbK4Oo3umvREqfZ/1yaRsx
A946nviOAMatytaxKyxGPSZuCANB0txsoxtfPcdYWkJnixDAYn4O9fK7LVLTwlok
Il4JNdG6xJLya3oAya5+J/Yqort9XbXVMrfsifShbr84vA9XABYqVX2RGmMbCwMb
Znfctv6kL536PY18UKfD
=o+jW
-----END PGP SIGNATURE-----

--=-+aCQe208oQMdIehb7V11--



--===============0651465170121438060==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============0651465170121438060==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung