http://www.mandriva.com/en/
______________________________
Package : gtk+3.0
Date : March 29, 2015
Affected: Business Server 2.0
______________________________
Problem Description:
Updated gtk+3.0 packages fix security vulnerability:
Clemens Fries reported that, when using Cinnamon, it was possible to
bypass the screensaver lock. An attacker with physical access to the
machine could use this flaw to take over the locked desktop session
(CVE-2014-1949).
This was fixed by including a patch for the root cause of the issue in
gtk+3.0, which came from the implementation of popup menus in GtkWindow
(bgo#722106).
This update also includes other patches from upstream to fix bugs
affecting GtkFileChooser (bgo#386569, bgo#719977) and GtkSpinButton
(bgo#709491), and a crash related to clipboard handling (bgo#719314).
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
______________________________
Updated Packages:
Mandriva Business Server 2/X86_64:
e3ae4df5ec401079c4a7ce2f3d2215
ada010a4b9ec261466b7a84667307c
76fe719ea817c92af101e585043a9a
c526223a0e26ef700e521ae71f4e04
dde3ff74d3392b7e3574ac4e440230
791d51dbf5239f91a4cd87881d9a36
5b52b3399c57432ad316dc42f888f0
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą