it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 4350-1] policykit-1 security update
- Date: Thu, 6 Dec 2018 21:30:03 +0000
- List-archive: https://lists.debian.org/msgid-search/20181206213003.pnhrknybzgodnm5c AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Thu, 6 Dec 2018 21:30:16 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <9AMzf3cGzOP.A.mnB.oTZCcB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4350-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
December 06, 2018 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : policykit-1
CVE ID : CVE-2018-19788
Debian Bug : 915332
It was discovered that incorrect processing of very high UIDs in
Policykit, a framework for managing administrative policies and
privileges, could result in authentication bypass.
For the stable distribution (stretch), this problem has been fixed in
version 0.105-18+deb9u1.
We recommend that you upgrade your policykit-1 packages.
For the detailed security status of policykit-1 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/policykit-1
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlwJk64ACgkQEMKTtsN8
TjY2aw//Qen/EAxoHxRePg0cSVudZP0U293wyo6fWoMaGXPr0k1Xa4eu/vOe/aIz
y3evijVNiEHJokNdEdAUFWsw1eu05F/r7ozQ4eEt6VDtcvs1/4V2tAJiHImdkvPA
oN0IN6Ml3GCp1GWMb7v4k1ahLgWD7s3ir9Ap7pL5tIHgRZ+CeIwSVUJyL4rrptzk
qfLXrvib3x5tyxl/FhQg7PzjmD3M4gfV77oyxl98ucRwL2KP92masSLy+aUGMHn4
bNbG9POUA3cSqYw0s+12vTPgiM/vaR00rfzhGWBDyUMY0Oo2Jj+eWSQSeweyLM59
0aYvPFoWwC0bfSyhw/G2LEoMBHe8b3IH0oYjdscuOkeUVTt4q2tgNEYR8RFsIq8+
Gweww2/+02mtjyvgIYMxUgoVfq0wKDjIkeHaxrtnerf0jTpXv/4B2hC5HpEpw+Up
4HURoEzio6L8UXA8D7gXnvo4uDaCf2CvgqbW2DBIAUtums0nV5UosTuH7K6m0FEe
A7w6cq3AWDb95WCVBBupWKuwTGwLqw64KGKL9CCMAlFSwzVsTrxgecXnrBJKxVUG
il/W3J71G2eDBtjagqluQ2OSCbLwjYo3vCJWt6RMcfN0Uyn9kyoLyrKB2BqNp2UJ
accP0qWVC2zjnnDUeZvSIaV/KtvOaczEByjGhQmHv1c5YH1mv0s=
=9sHU
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 4350-1] policykit-1 security update, Moritz Muehlenhoff, 06.12.2018
Archiv bereitgestellt durch MHonArc 2.6.19.