openSUSE-SU-2013:1955-1: moderate: aaa_base: fixed root users default group and /etc/shadow permissions
openSUSE Security Update: aaa_base: fixed root users default group and /etc/shadow permissions ______________________________________________________________________________ Announcement ID: openSUSE-SU-2013:1955-1 Rating: moderate References: #843230 #851908 Cross-References: CVE-2013-3713 Affected Products: openSUSE 13.1 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: On systems installed via the Live Media that /etc/shadow file was readable by the "users" group, which was not intended. (bnc#843230, CVE-2013-3713) Reason for this was that the user "root" was put into the "users" group. Also a commandline completion bug was fixed: - Use only bash and readline defaults for fallback completion (bnc#851908) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.1: zypper in -t patch openSUSE-2013-1031 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.1 (i586 x86_64): aaa_base-13.1-16.26.1 aaa_base-debuginfo-13.1-16.26.1 aaa_base-debugsource-13.1-16.26.1 aaa_base-extras-13.1-16.26.1 aaa_base-malloccheck-13.1-16.26.1 References: http://support.novell.com/security/cve/CVE-2013-3713.html https://bugzilla.novell.com/843230 https://bugzilla.novell.com/851908
participants (1)
-
opensuse-security@opensuse.org