Synopsis: Moderate: luci security, bug fix, and enhancement update Advisory ID: SLSA-2013:1603-2 Issue Date: 2013-11-21 CVE Numbers: CVE-2013-4481 CVE-2013-4482 -- A flaw was found in the way the luci service was initialized. If a system administrator started the luci service from a directory that was writable to by a local user, that user could use this flaw to execute arbitrary code as the root or luci user. (CVE-2013-4482) A flaw was found in the way luci generated its configuration file. The file was created as world readable for a short period of time, allowing a local user to gain access to the authentication secrets stored in the configuration file. (CVE-2013-4481) After installing this update, the luci service will be restarted automatically. -- SL6 x86_64 luci-0.26.0-48.el6.x86_64.rpm luci-debuginfo-0.26.0-48.el6.x86_64.rpm i386 luci-0.26.0-48.el6.i686.rpm luci-debuginfo-0.26.0-48.el6.i686.rpm - Scientific Linux Development Team