SCIENTIFIC-LINUX-ERRATA Archives

September 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Connie Sieh <[log in to unmask]>
Reply To:
Date:
Tue, 24 Sep 2013 22:09:30 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (24 lines)
Synopsis:          Important: rtkit security update
Advisory ID:       SLSA-2013:1282-1
Issue Date:        2013-09-24
CVE Numbers:       CVE-2013-4326
--

It was found that RealtimeKit communicated with PolicyKit for
authorization using a D-Bus API that is vulnerable to a race condition.
This could have led to intended PolicyKit authorizations being bypassed.
This update modifies RealtimeKit to communicate with PolicyKit via a
different API that is not vulnerable to the race condition.
(CVE-2013-4326)
--

SL6
  x86_64
    rtkit-0.5-2.el6_4.x86_64.rpm
    rtkit-debuginfo-0.5-2.el6_4.x86_64.rpm
  i386
    rtkit-0.5-2.el6_4.i686.rpm
    rtkit-debuginfo-0.5-2.el6_4.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2