Summary: | <gnome-extra/nm-applet-1.4.6-r1: may give access to local files during login screen in combination with lightdm or some other desktop managers | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Mart Raudsepp <leio> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | gnome |
Priority: | Normal | Flags: | stable-bot:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://mail.gnome.org/archives/networkmanager-list/2017-March/msg00032.html | ||
Whiteboard: | B3 [glsa cve] | ||
Package list: |
=gnome-extra/nm-applet-1.4.6-r1
|
Runtime testing required: | --- |
Bug Depends on: | |||
Bug Blocks: | 611134 |
Description
Mart Raudsepp
2017-03-25 11:11:46 UTC
commit 5c732474a68cdacc6cb2f17d60e7af9982c057f8 Author: Mart Raudsepp <leio@gentoo.org> Date: Sat Mar 25 14:07:13 2017 +0200 gnome-extra/nm-applet: fix CVE-2017-6590, nma bindings and more Grab patches from upstream nm-1-4 branch for fixing broken NMA bindings, translations when used in gnome-control-center (gettext domain context issue), CVE-2017-6590 (a physical access login screen bypass issue with lightdm), and a certification file error message fix as requested by one of our users specifically. Thanks-to: Martin Mokrejš Gentoo-bug: 613646 Gentoo-bug: 613768 Arches, please proceed. In addition to the security fix, previous stable nm-applet is a bit old for newer stable networkmanager too for more trouble-free functioning. amd64 stable x86 stable. Maintainer(s), please cleanup. Security, please vote. cleanup done, 1.2.4 remains with keywords reduced to only ~ia64 ~sparc as they still haven't done bug 593496 Arches and Maintainer(s). Thank you for your work. New GLSA Request filed. Going to leave in cleanup state until they complete the bug. Arches and Maintainer(s), Thank you for your work. This issue was resolved and addressed in GLSA 201707-09 at https://security.gentoo.org/glsa/201707-09 by GLSA coordinator Thomas Deutschmann (whissi). |