Mailinglist Archive: opensuse-updates (130 mails)

< Previous Next >
openSUSE-SU-2013:1955-1: moderate: aaa_base: fixed root users default group and /etc/shadow permissions
openSUSE Security Update: aaa_base: fixed root users default group and
/etc/shadow permissions
______________________________________________________________________________

Announcement ID: openSUSE-SU-2013:1955-1
Rating: moderate
References: #843230 #851908
Cross-References: CVE-2013-3713
Affected Products:
openSUSE 13.1
______________________________________________________________________________

An update that solves one vulnerability and has one errata
is now available.

Description:


On systems installed via the Live Media that /etc/shadow
file was readable by the "users" group, which was not
intended. (bnc#843230, CVE-2013-3713)

Reason for this was that the user "root" was put into the
"users" group.

Also a commandline completion bug was fixed:
- Use only bash and readline defaults for fallback
completion (bnc#851908)


Patch Instructions:

To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch openSUSE-2013-1031

To bring your system up-to-date, use "zypper patch".


Package List:

- openSUSE 13.1 (i586 x86_64):

aaa_base-13.1-16.26.1
aaa_base-debuginfo-13.1-16.26.1
aaa_base-debugsource-13.1-16.26.1
aaa_base-extras-13.1-16.26.1
aaa_base-malloccheck-13.1-16.26.1


References:

http://support.novell.com/security/cve/CVE-2013-3713.html
https://bugzilla.novell.com/843230
https://bugzilla.novell.com/851908


< Previous Next >
This Thread
  • No further messages