Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <1334634401.439720.1302196350623.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Thu, 7 Apr 2011 13:12:30 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley <coley@...re.org>
Subject: consolekit security flaw heads up

I've assigned this CVE-2010-4664.

It's not terribly serious. The short story is that local users have some
special treatment with consolekit, and it's easy to become a "local user".

https://bugzilla.redhat.com/show_bug.cgi?id=585952
https://bugzilla.redhat.com/show_bug.cgi?id=600455
https://bugs.freedesktop.org/show_bug.cgi?id=28377

The upstream bug has a patch.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.