LWN.net Logo

Fedora alert FEDORA-2012-10120 (accountsservice)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 17 Update: accountsservice-0.6.21-2.fc17
Date:  Mon, 02 Jul 2012 22:29:15 +0000
Message-ID:  <20120702222917.4B77920C8F@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-10120 2012-06-30 21:31:35 -------------------------------------------------------------------------------- Name : accountsservice Product : Fedora 17 Version : 0.6.21 Release : 2.fc17 URL : http://www.fedoraproject.org/wiki/Features/UserAccountDialog Summary : D-Bus interfaces for querying and manipulating user account information Description : The accountsservice project provides a set of D-Bus interfaces for querying and manipulating user account information and an implementation of these interfaces, based on the useradd, usermod and userdel commands. -------------------------------------------------------------------------------- Update Information: This updates accountsservice to correct a local file disclosure security flaw. CVE-2012-2737 This update also corrects and issue where spurios users show up in the login screen user list. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 28 2012 Ray Strode <rstrode@redhat.com> 0.6.21-2 - CVE-2012-2737: local file disclosure * Tue Jun 12 2012 Matthias Clasen <mclasen@redhatcom> 0.6.21-1 - Update to 0.6.21 * Fri May 4 2012 Ray Strode <rstrode@redhat.com> 0.6.20-1 - Update to 0.6.20. Should fix user list. Related: #814690 * Thu May 3 2012 Ray Strode <rstrode@redhat.com> 0.6.19-1 - Update to 0.6.19 Allows user deletion of logged in users Related: #814690 -------------------------------------------------------------------------------- References: [ 1 ] Bug #836284 - CVE-2012-2737 accountsservice: local file disclosure flaw [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=836284 [ 2 ] Bug #836595 - Remove users "lightdm" and "root" from userlist https://bugzilla.redhat.com/show_bug.cgi?id=836595 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update accountsservice' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds