Sicherheit: Ausführen beliebiger Kommandos in Xdg-utils
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in Xdg-utils
ID: FEDORA-2015-0954
Distribution: Fedora
Plattformen: Fedora 21
Datum: Mo, 26. Januar 2015, 08:09
Referenzen: https://bugs.freedesktop.org/show_bug.cgi?id=66670
Applikationen: Xdg-utils


Name        : xdg-utils
Product : Fedora 21
Version : 1.1.0
Release : 0.35.rc3.fc21
URL : http://portland.freedesktop.org/
Summary : Basic desktop integration functions
Description :
The xdg-utils package is a set of simple scripts that provide basic
desktop integration functions for any Free Desktop, such as Linux.
They are intended to provide a set of defacto standards.
This means that:
* Third party software developers can rely on these xdg-utils
for all of their simple integration needs.
* Developers of desktop environments can make sure that their
environments are well supported
* Distribution vendors can provide custom versions of these utilities

The following scripts are provided at this time:
* xdg-desktop-icon Install icons to the desktop
* xdg-desktop-menu Install desktop menu items
* xdg-email Send mail using the user's preferred e-mail
* xdg-icon-resource Install icon resources
* xdg-mime Query information about file type handling and
install descriptions for new file types
* xdg-open Open a file or URL in the user's preferred
* xdg-screensaver Control the screensaver
* xdg-settings Get various settings from the desktop environment

Update Information:

refresh packaging to 1.1.0-rc3, and include fix for possible command injection vulerability, see https://bugs.freedesktop.org/show_bug.cgi?id=66670

* Mon Jan 19 2015 Rex Dieter <rdieter@fedoraproject.org> 1.1.0-0.35.rc3
- pull in latest commits, notably more fdo screensaver fixes
* Tue Jan 6 2015 Rex Dieter <rdieter@fedoraproject.org> 1.1.0-0.34.rc3
- refresh for latest attepmt to fix upstream BR66670
* Mon Jan 5 2015 Rex Dieter <rdieter@fedoraproject.org> 1.1.0-0.33.rc3
- pull in latest commits
* Sat Jan 3 2015 Rex Dieter <rdieter@fedoraproject.org> 1.1.0-0.32.rc3
- xdg-utils-1.1.0-rc3

This update can be installed with the "yum" update program. Use
su -c 'yum update xdg-utils' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Pro-Linux @Facebook
Neue Nachrichten