LWN.net Logo

PackageKit: installs old package versions

Package(s):PackageKit CVE #(s):
Created:March 4, 2013 Updated:March 6, 2013
Description: From the openSUSE advisory:

PackageKit was fixed to add a patch to forbid update to downgrade (bnc#804983)

As the update operation is allowed for logged in regular users, they could install old package versions which might have been still affected by already fixed security problems.

Alerts:
openSUSE openSUSE-SU-2013:0381-1 2013-03-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds