Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

openSUSE 13.1 Important: 2014:0953-1 ppc64-diag Race and Disclosure Fix

opensuse
Calendar Grey July 30, 2014
Dist Opensuse Esm H88
A critical update for openSUSE addresses race conditions in tmp directories and prevents potential information leaks associated with the ppc64-diag utility.
An update that fixes two vulnerabilities is now available

Description

ppc64-diag was updated to fix tmp race issues (CVE-2014-4038) and a file

disclosure problem in snapshot tarball generation (CVE-2014-4039).

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch openSUSE-2014-

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (ppc ppc64):

ppc64-diag-2.6.1-2.4.1

ppc64-diag-debuginfo-2.6.1-2.4.1

ppc64-diag-debugsource-2.6.1-2.4.1

References

https://www.suse.com/security/cve/CVE-2014-4038.html

https://www.suse.com/security/cve/CVE-2014-4039.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2014:0953-1
Rating: important
Affected Products: openSUSE 13.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here