Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE 13.1: 2013:1961-1 Important Local Token Issue Fix

opensuse
Calendar Grey December 25, 2013
Dist Opensuse Esm H88
An update has been released for openSUSE addressing a local vulnerability related to secret token file permissions, classified as significant.
An update that fixes one vulnerability is now available.

Description

Fixed CVE-2013-3709: make the secret token file

(secret_token.rb) readable only for the webyast user to

avoid forging the session cookie (bnc#851116) (reported by

joernchen of Phenoelit)

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch openSUSE-2013-1029

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (noarch):

webyast-base-0.3.45.1-2.4.1

webyast-base-branding-default-0.3.45.1-2.4.1

webyast-base-testsuite-0.3.45.1-2.4.1

References

https://www.suse.com/security/cve/CVE-2013-3709.html

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:1961-1
Rating: important
Affected Products: openSUSE 13.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here