An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for polkit ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2284-1 Rating: moderate References: #1099031 Cross-References: CVE-2018-1116 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for polkit fixes the following issues: Security issue fixed: - CVE-2018-1116: Fix uid comparison lacking in polkit_backend_interactive_authority_check_authorization (bsc#1099031). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-848=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libpolkit0-0.114-lp150.2.3.1 libpolkit0-debuginfo-0.114-lp150.2.3.1 polkit-0.114-lp150.2.3.1 polkit-debuginfo-0.114-lp150.2.3.1 polkit-debugsource-0.114-lp150.2.3.1 polkit-devel-0.114-lp150.2.3.1 polkit-devel-debuginfo-0.114-lp150.2.3.1 typelib-1_0-Polkit-1_0-0.114-lp150.2.3.1 - openSUSE Leap 15.0 (x86_64): libpolkit0-32bit-0.114-lp150.2.3.1 libpolkit0-32bit-debuginfo-0.114-lp150.2.3.1 - openSUSE Leap 15.0 (noarch): polkit-doc-0.114-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-1116.html https://bugzilla.suse.com/1099031 -- . openSUSE releases a fix addressing uid comparison concerns in polkit, classified as having moderate urgency. More information provided within.. openSUSE Security Update, Polkit Patch, Security Fix Updates. .LinuxSecurity.com Team
In the previous advisory for libpng (SSA:2004-222-01), the URL provided for the Slackware 9.0 patch mistakenly pointed to the old unpatched package. Slackware 9.0 users should follow the URL below for the new package: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] Slackware 9.0, libpng correction (SSA:2004-222-01b) In the previous advisory for libpng (SSA:2004-222-01), the URL provided for the Slackware 9.0 patch mistakenly pointed to the old unpatched package. Slackware 9.0 users should follow the URL below for the new package: 6a7ab390a92dbd28f77a5780be2b5ac1 libpng-1.2.5-i486-3.tgz Thanks, and sorry about the mixup, Pat -----BEGIN PGP SIGNATURE----- . Slackware 9.0 enthusiasts can now access the new package URL for libpng, resolving the earlier advisory concerns.. Slackware Libpng Update, Security Patch, Software Correction. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.