Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE 12.3: 2013:1952-1 Important: Session Token Issue

opensuse
Calendar Grey December 25, 2013
Dist Opensuse Esm H88
A new patch for openSUSE addresses a local vulnerability concerning session identifiers. The specifics of the resolution are provided.
An update that fixes one vulnerability is now available

Description

Fixed CVE-2013-3709: make the secret token file

(secret_token.rb) readable only for the webyast user to

avoid forging the session cookie (bnc#851116)

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 12.3:

zypper in -t patch openSUSE-2013-1028

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 12.3 (noarch):

webyast-base-0.3.43.1-1.4.1

webyast-base-branding-default-0.3.43.1-1.4.1

webyast-base-testsuite-0.3.43.1-1.4.1

References

https://www.suse.com/security/cve/CVE-2013-3709.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:1952-1
Rating: important
Affected Products: openSUSE 12.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here