This update for polkit fixes the following issues: Change permissions for rules folders (bsc#1209282). # Security update for polkit Announcement ID: SUSE-SU-2024:0010-1 Rating: moderate References: * bsc#1209282 Affected Products: * Basesystem Module 15-SP4 * openSUSE Leap 15.4 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has one security fix can now be installed. ## Description: This update for polkit fixes the following issues: * Change permissions for rules folders (bsc#1209282) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-10=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-10=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2024-10=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-10=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-10=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-10=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-10=1 * Basesystem Module15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2024-10=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-10=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-10=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-10=1 ## Package List: * openSUSE Leap Micro 5.3 (aarch64 x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * typelib-1_0-Polkit-1_0-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-devel-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * polkit-devel-0.116-150200.3.12.1 * openSUSE Leap 15.4 (x86_64) * libpolkit0-32bit-debuginfo-0.116-150200.3.12.1 * libpolkit0-32bit-0.116-150200.3.12.1 * openSUSE Leap 15.4 (noarch) * polkit-doc-0.116-150200.3.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * SUSE LinuxEnterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * typelib-1_0-Polkit-1_0-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-devel-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * polkit-devel-0.116-150200.3.12.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libpolkit0-0.116-150200.3.12.1 * polkit-debugsource-0.116-150200.3.12.1 * polkit-0.116-150200.3.12.1 * libpolkit0-debuginfo-0.116-150200.3.12.1 * polkit-debuginfo-0.116-150200.3.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1209282 . Adjusts access rights for polkit configurations in response to the openSUSE security patch SUSE-SU-2024:0010-1 classified as moderate.. polkit updates, openSUSE security, access control fix, SUSE advisory. . LinuxSecurity.com Team
Updated ant packages fix security vulnerability: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file . MGASA-2021-0173 - Updated ant packages fix security vulnerability Publication date: 03 Apr 2021 URL: https://advisories.mageia.org/MGASA-2021-0173.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-11979 Updated ant packages fix security vulnerability: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process(CVE-2020-11979). References: - https://bugs.mageia.org/show_bug.cgi?id=27386 - https://www.openwall.com/lists/oss-security/2020/09/30/6 - https://ant.apache.org/security.html - https://www.cve.org/CVERecord?id=CVE-2020-11979 SRPMS: - 7/core/ant-1.10.9-1.mga7 . Latest updates for Ant packages have been released to address a vulnerability permitting code execution due to a permissions error. Refer to the Mageia advisory for further information.. Mageia Ant Update,Critical Security Fix,Code Injection Risk,Apache Ant Permissions Issue. . Severity: Critical. LinuxSecurity.com Team
The permissions on the prewikka.conf file are world readable and contain the sql database password used by prewikka. This update makes it readable just by the apache group.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-3789 2009-04-21 23:55:14 -------------------------------------------------------------------------------- Name : prewikka Product : Fedora 9 Version : 0.9.14 Release : 2.fc9 URL : https://prelude-ids.org/ Summary : Graphical front-end analysis console for the Prelude Hybrid IDS Framework Description : Prewikka is a graphical front-end analysis console for the Prelude Hybrid IDS Framework. Providing numerous features, Prewikka facilitates the work of users and analysts. It provides alert aggregation and sensor and hearbeat views, and has user management and configurable filters. It has access to external tools such as whois and traceroute. Please read README.fedora for installation instructions. -------------------------------------------------------------------------------- Update Information: The permissions on the prewikka.conf file are world readable and contain the sql database password used by prewikka. This update makes it readable just by the apache group. -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 17 2009 Steve Grubb 0.9.14-2 - Change default perms on conf file * Thu Apr 24 2008 Steve Grubb 0.9.14-1 - new upstream release -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update prewikka' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.