Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in gdm
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in gdm
ID: SUSE-SU-2019:0527-1
Distribution: SUSE
Plattformen: SUSE Linux Enterprise Module for Desktop Applications 15, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15
Datum: Fr, 1. März 2019, 18:22
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3825
Applikationen: Gnome Display Manager

Originalnachricht

   SUSE Security Update: Security update for gdm
______________________________________________________________________________

Announcement ID: SUSE-SU-2019:0527-1
Rating: moderate
References: #1112294 #1112578 #1113245 #1113700 #1120307
#1124628
Cross-References: CVE-2019-3825
Affected Products:
SUSE Linux Enterprise Module for Open Buildservice
Development Tools 15
SUSE Linux Enterprise Module for Desktop Applications 15
______________________________________________________________________________

An update that solves one vulnerability and has 5 fixes is
now available.

Description:

This update for gdm fixes the following issues:

Security issue fixed:

- CVE-2019-3825: Fixed a lock screen bypass when timed login was enabled
(bsc#1124628).

Other issues fixed:

- GLX applications do not work well when the proprietary nvidia driver is
used with a wayland session. Because of that this update disables
wayland on that hardware (bsc#1112578).
- Fixed an issue where gdm restart fails to kill user processes
(bsc#1112294 and bsc#1113245).
- Fixed a System halt in the screen with message "End of ORACLE
section"
(bsc#1120307).
- Fixed an issue which did not allow the returning to text console when
gdm is stopped (bsc#1113700).
- Fixed an issue which was causing system hang during the load of gdm
(bsc#1112578).


Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation
methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15:

zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-527=1

- SUSE Linux Enterprise Module for Desktop Applications 15:

zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-2019-527=1



Package List:

- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15
(noarch):

gdm-branding-upstream-3.26.2.1-13.19.2

- SUSE Linux Enterprise Module for Desktop Applications 15 (aarch64 ppc64le
s390x x86_64):

gdm-3.26.2.1-13.19.2
gdm-debuginfo-3.26.2.1-13.19.2
gdm-debugsource-3.26.2.1-13.19.2
gdm-devel-3.26.2.1-13.19.2
libgdm1-3.26.2.1-13.19.2
libgdm1-debuginfo-3.26.2.1-13.19.2
typelib-1_0-Gdm-1_0-3.26.2.1-13.19.2

- SUSE Linux Enterprise Module for Desktop Applications 15 (noarch):

gdm-lang-3.26.2.1-13.19.2
gdmflexiserver-3.26.2.1-13.19.2


References:

https://www.suse.com/security/cve/CVE-2019-3825.html
https://bugzilla.suse.com/1112294
https://bugzilla.suse.com/1112578
https://bugzilla.suse.com/1113245
https://bugzilla.suse.com/1113700
https://bugzilla.suse.com/1120307
https://bugzilla.suse.com/1124628

_______________________________________________
sle-security-updates mailing list
sle-security-updates@lists.suse.com
http://lists.suse.com/mailman/listinfo/sle-security-updates
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung