LinuxQuestions.org

LinuxQuestions.org (http://www.linuxquestions.org/questions/index.php)
-   Slackware (http://www.linuxquestions.org/questions/forumdisplay.php?f=14)
-   -   Slackware Security Update: GDM security update (http://www.linuxquestions.org/questions/showthread.php?t=85514)

phoeniXflame 08-25-2003 11:00 AM

Slackware Security Update: GDM security update
 
I thought this might be helpful for everyone who isnt subscribed to the mailing lists ...

Quote:

[slackware-security] GDM security update (SSA:2003-236-01)

Upgraded gdm packages are available for Slackware 9.0 and -current.
These fix a security issue where a local user may use GDM to read any
file on the system.


Here are the details from the Slackware 9.0 ChangeLog:
+--------------------------+
Sun Aug 24 14:36:29 PDT 2003
patches/packages/gdm-2.4.1.6-i386-1.tgz: Upgraded to gdm-2.4.1.6.
This fixes a bug where a local user may read any system file by making a
symlink to it from $HOME/.xsession-errors and using GDM's error browser
to read the file.
(* Security fix *)
+--------------------------+



WHERE TO FIND THE NEW PACKAGES:
+-----------------------------+

Updated package for Slackware 9.0:
ftp://ftp.slackware.com/pub/slackwar...1.6-i386-1.tgz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackwar...1.6-i486-1.tgz



MD5 SIGNATURES:
+-------------+

Slackware 9.0 package:
a5939f91ac56b5dd97d4a2013f099aed gdm-2.4.1.6-i386-1.tgz

Slackware -current package:
26459fb6dec7279fe4d80aba0b3ac4ff gdm-2.4.1.6-i486-1.tgz



INSTALLATION INSTRUCTIONS:
+------------------------+

Upgrade using upgradepkg (as root):
upgradepkg gdm-2.4.1.6-i386-1.tgz



+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com

zsejk 08-25-2003 11:50 AM

Thanks for the info phoeniX... I was indeed not on that mailing list (am now though :D ), so this came in handy.

:)

-zsejk

Astro 08-26-2003 04:21 PM

As far as I can tell this package screwed up my GDM and wouldn't let me load gnome with GDM anymore... I was testing out some Dropline stuff and upgraded the package and something must be different, someone might want to let dropline know about that.


All times are GMT -5. The time now is 04:53 AM.