SCIENTIFIC-LINUX-ERRATA Archives

April 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Wed, 20 Apr 2011 14:30:51 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (30 lines)
Synopsis:	Important: polkit security update
Issue date:	2011-04-19
CVE Names:	CVE-2011-1485

A race condition flaw was found in the PolicyKit pkexec utility and 
polkitd daemon. A local user could use this flaw to appear as a 
privileged user to pkexec, allowing them to execute arbitrary commands 
as root by running those commands with pkexec. (CVE-2011-1485)

The system must be rebooted for this update to take effect.

SL 6.x

       SRPMS:
polkit-0.96-2.el6_0.1.src.rpm
       i386:
polkit-0.96-2.el6_0.1.i686.rpm
polkit-desktop-policy-0.96-2.el6_0.1.noarch.rpm
polkit-devel-0.96-2.el6_0.1.i686.rpm
polkit-docs-0.96-2.el6_0.1.i686.rpm
       x86_64:
polkit-0.96-2.el6_0.1.i686.rpm
polkit-0.96-2.el6_0.1.x86_64.rpm
polkit-desktop-policy-0.96-2.el6_0.1.noarch.rpm
polkit-devel-0.96-2.el6_0.1.i686.rpm
polkit-devel-0.96-2.el6_0.1.x86_64.rpm
polkit-docs-0.96-2.el6_0.1.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2