Bug 1006669 (CVE-2013-4324)
Summary: | CVE-2013-4324 spice-gtk: Insecure calling of polkit via polkit_unix_process_new() | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Huzaifa S. Sidhpurwala <huzaifas> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | high | Docs Contact: | |||||
Priority: | high | ||||||
Version: | unspecified | CC: | cfergeau, hdegoede, marcandre.lureau, security-response-team | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2021-10-20 10:41:34 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 1005137, 1006786, 1006787, 1009540 | ||||||
Bug Blocks: | 1002376 | ||||||
Attachments: |
|
Description
Huzaifa S. Sidhpurwala
2013-09-11 05:28:14 UTC
Created attachment 796257 [details]
spice-gtk patch
This is now public: http://www.openwall.com/lists/oss-security/2013/09/18/4 Created spice-gtk tracking bugs for this issue: Affects: fedora-all [bug 1009540] This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:1273 https://rhn.redhat.com/errata/RHSA-2013-1273.html spice-gtk-0.20-6.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. |