Date: Thu, 7 Apr 2011 13:12:30 -0400 (EDT) From: Josh Bressers <bressers@...hat.com> To: oss-security@...ts.openwall.com Cc: coley <coley@...re.org> Subject: consolekit security flaw heads up I've assigned this CVE-2010-4664. It's not terribly serious. The short story is that local users have some special treatment with consolekit, and it's easy to become a "local user". https://bugzilla.redhat.com/show_bug.cgi?id=585952 https://bugzilla.redhat.com/show_bug.cgi?id=600455 https://bugs.freedesktop.org/show_bug.cgi?id=28377 The upstream bug has a patch. Thanks. -- JB
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.