Address CVE-2025-30093 - rhbz#2355671. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a4d8b30f59 2025-04-06 01:15:25.866197+00:00 -------------------------------------------------------------------------------- Name : condor Product : Fedora 40 Version : 23.9.6 Release : 3.fc40 URL : http://htcondor.org Summary : HTCondor: High Throughput Computing Description : HTCondor is a workload management system for high-throughput and high-performance jobs. Like other full-featured batch systems, HTCondor provides a job queuing mechanism, scheduling policy, priority scheme, resource monitoring, and resource management. Users submit their serial or parallel jobs to HTCondor, HTCondor places them into a queue, chooses when and where to run the jobs based upon a policy, carefully monitors their progress, and ultimately informs the user upon completion. -------------------------------------------------------------------------------- Update Information: Address CVE-2025-30093 - rhbz#2355671 -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 28 2025 Tim Theisen - 23.9.6-3 - Address CVE-2025-30093 - rhbz#HTCONDOR-2025-0001 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2355671 - CVE-2025-30093 condor: authenticated attackers can potentially bypass authorization restrictions [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2355671 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a4d8b30f59' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
apt-xapian-index could be tricked into bypassing polkit authorizations.. =========================================================================Ubuntu Security Notice USN-1955-1 September 18, 2013 apt-xapian-index vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: apt-xapian-index could be tricked into bypassing polkit authorizations. Software Description: - apt-xapian-index: maintenance and search tools for a Xapian index of Debian package Details: It was discovered that apt-xapian-index was using polkit in an unsafe manner. A local attacker could possibly use this issue to bypass intended polkit authorizations. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: apt-xapian-index 0.45ubuntu2.1 Ubuntu 12.10: apt-xapian-index 0.44ubuntu7.1 Ubuntu 12.04 LTS: apt-xapian-index 0.44ubuntu5.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1955-1 CVE-2013-1064 Package Information: https://launchpad.net/ubuntu/+source/apt-xapian-index/0.45ubuntu2.1 https://launchpad.net/ubuntu/+source/apt-xapian-index/0.44ubuntu7.1 https://launchpad.net/ubuntu/+source/apt-xapian-index/0.44ubuntu5.1 . A vulnerability in apt-xapian-index may allow for eschewing polkit authorizations. Fortify your Ubuntu environment in light of this notice.. apt-xapian-index, polkit bypass, local attack security advisory, Ubuntu exploit. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.