SCIENTIFIC-LINUX-ERRATA Archives

April 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Condense Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Sender:
Security Errata for Scientific Linux <[log in to unmask]>
Date:
Wed, 20 Apr 2011 14:30:51 -0500
Reply-To:
Troy Dawson <[log in to unmask]>
Subject:
MIME-Version:
1.0
Content-Transfer-Encoding:
7bit
Content-Type:
text/plain; charset=ISO-8859-1; format=flowed
From:
Troy Dawson <[log in to unmask]>
Comments:
Parts/Attachments:
text/plain (30 lines)
Synopsis:	Important: polkit security update
Issue date:	2011-04-19
CVE Names:	CVE-2011-1485

A race condition flaw was found in the PolicyKit pkexec utility and 
polkitd daemon. A local user could use this flaw to appear as a 
privileged user to pkexec, allowing them to execute arbitrary commands 
as root by running those commands with pkexec. (CVE-2011-1485)

The system must be rebooted for this update to take effect.

SL 6.x

       SRPMS:
polkit-0.96-2.el6_0.1.src.rpm
       i386:
polkit-0.96-2.el6_0.1.i686.rpm
polkit-desktop-policy-0.96-2.el6_0.1.noarch.rpm
polkit-devel-0.96-2.el6_0.1.i686.rpm
polkit-docs-0.96-2.el6_0.1.i686.rpm
       x86_64:
polkit-0.96-2.el6_0.1.i686.rpm
polkit-0.96-2.el6_0.1.x86_64.rpm
polkit-desktop-policy-0.96-2.el6_0.1.noarch.rpm
polkit-devel-0.96-2.el6_0.1.i686.rpm
polkit-devel-0.96-2.el6_0.1.x86_64.rpm
polkit-docs-0.96-2.el6_0.1.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2