[Bug 1222159] AUDIT-0: CVE-2024-5148: gnome-remote-desktop: Polkit and D-Bus review for Gnome 46.0
22 May
2024
22 May
'24
11:31
https://bugzilla.suse.com/show_bug.cgi?id=1222159 https://bugzilla.suse.com/show_bug.cgi?id=1222159#c27 --- Comment #27 from Matthias Gerstner <matthias.gerstner@suse.com> --- I checked version 46.2 and the fixes seem okay so far. The remaining issues #5 and #9 don't relate to the D-Bus interface, so whitelisting the D-Bus API is okay now. Issue #9 is rather unfortunate though, since upstream doesn't want to remove the insecure CLI invocation style. Depending upon how this ends up in release 47, we could consider adding a patch in our packaging at least, that warns the user when this insecure invocation style is used. -- You are receiving this mail because: You are on the CC list for the bug.
225
Age (days ago)
225
Last active (days ago)
0 comments
1 participants
participants (1)
-
bugzilla_noreply@suse.com