Ausführen beliebiger Kommandos in wicd
ID: | FEDORA-2012-5909 |
Distribution: | Fedora |
Plattformen: | Fedora 16 |
Datum: | Di, 24. April 2012, 19:06 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2095 |
Applikationen: | wicd |
Originalnachricht |
|
Name : wicd Product : Fedora 16 Version : 1.7.0 Release : 13.fc16 URL : http://wicd.sourceforge.net/ Summary : Wireless and wired network connection manager Description : Wicd is designed to give the user as much control over behavior of network connections as possible. Every network, both wired and wireless, has its own profile with its own configuration options and connection behavior. Wicd will try to automatically connect only to networks the user specifies it should try, with a preference first to a wired network, then to wireless. This package provides the architecture-dependent components of wicd. -------------------------------------------------------------------------------- Update Information: This update fixes CVE-2012-2095. The wicd daemon suffered from a local privilege escalation flaw due to incomplete input sanitization. A local attacker sould use this to inject arbitrary code through the D-Bus interface. -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 13 2012 David Cantrell |