-   Slackware (
-   -   Slackware Security Update: GDM security update (

phoeniXflame 08-25-2003 11:00 AM

Slackware Security Update: GDM security update
I thought this might be helpful for everyone who isnt subscribed to the mailing lists ...


[slackware-security] GDM security update (SSA:2003-236-01)

Upgraded gdm packages are available for Slackware 9.0 and -current.
These fix a security issue where a local user may use GDM to read any
file on the system.

Here are the details from the Slackware 9.0 ChangeLog:
Sun Aug 24 14:36:29 PDT 2003
patches/packages/gdm- Upgraded to gdm-
This fixes a bug where a local user may read any system file by making a
symlink to it from $HOME/.xsession-errors and using GDM's error browser
to read the file.
(* Security fix *)


Updated package for Slackware 9.0:

Updated package for Slackware -current:


Slackware 9.0 package:
a5939f91ac56b5dd97d4a2013f099aed gdm-

Slackware -current package:
26459fb6dec7279fe4d80aba0b3ac4ff gdm-


Upgrade using upgradepkg (as root):
upgradepkg gdm-


Slackware Linux Security Team

zsejk 08-25-2003 11:50 AM

Thanks for the info phoeniX... I was indeed not on that mailing list (am now though :D ), so this came in handy.



Astro 08-26-2003 04:21 PM

As far as I can tell this package screwed up my GDM and wouldn't let me load gnome with GDM anymore... I was testing out some Dropline stuff and upgraded the package and something must be different, someone might want to let dropline know about that.

All times are GMT -5. The time now is 09:38 PM.