[ubuntu/natty] gdm 2.32.0-0ubuntu15 (Accepted)

Steve Beattie sbeattie at ubuntu.com
Tue Apr 5 07:25:32 UTC 2011


gdm (2.32.0-0ubuntu15) natty; urgency=low

  * SECURITY UPDATE: race condition allowing privilege escalation
    - debian/patches/43_CVE-2011-0727.patch: fix
      daemon/gdm-session-worker.c to copy files as session user rather
      than root followed by a subsequent chown. (LP: #746053)
    - CVE-2011-0727

Date: Mon, 04 Apr 2011 20:42:03 -0700
Changed-By: Steve Beattie <sbeattie at ubuntu.com>
Maintainer: Sebastien Bacher <seb128 at ubuntu.com>
Signed-By: Robert Ancell <robert.ancell at canonical.com>
https://launchpad.net/ubuntu/natty/+source/gdm/2.32.0-0ubuntu15
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 04 Apr 2011 20:42:03 -0700
Source: gdm
Binary: gdm
Architecture: source
Version: 2.32.0-0ubuntu15
Distribution: natty
Urgency: low
Maintainer: Sebastien Bacher <seb128 at ubuntu.com>
Changed-By: Steve Beattie <sbeattie at ubuntu.com>
Description: 
 gdm        - GNOME Display Manager
Launchpad-Bugs-Fixed: 746053
Changes: 
 gdm (2.32.0-0ubuntu15) natty; urgency=low
 .
   * SECURITY UPDATE: race condition allowing privilege escalation
     - debian/patches/43_CVE-2011-0727.patch: fix
       daemon/gdm-session-worker.c to copy files as session user rather
       than root followed by a subsequent chown. (LP: #746053)
     - CVE-2011-0727
Checksums-Sha1: 
 d2f084861dec09191025bf3f2da7fc6b9a05f514 1543 gdm_2.32.0-0ubuntu15.dsc
 4b2349dfba411a51885c40e0c3a83dc9b2583910 122090 gdm_2.32.0-0ubuntu15.debian.tar.gz
Checksums-Sha256: 
 cf9bc544710332d71177c3ffcf5fa13d6ba1441b8a1e57699bce2af57fd1a725 1543 gdm_2.32.0-0ubuntu15.dsc
 f499f780d04fe18d8c4f847d05f5b3ceab3631534541eec9f78e304670d119d9 122090 gdm_2.32.0-0ubuntu15.debian.tar.gz
Files: 
 16d25dbc0ba00507f5d1a7c6eba1dcaf 1543 gnome optional gdm_2.32.0-0ubuntu15.dsc
 b60e1dab82e6f8d3e61630a4d552fa5f 122090 gnome optional gdm_2.32.0-0ubuntu15.debian.tar.gz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk2awtsACgkQGOqhiQ98iC4AFwCfZ2ZnILtx4iJl8U+Iu4vrrPId
LwIAoLn9QRTtmFq0oLDQT4ki8SnUGWmM
=3zT2
-----END PGP SIGNATURE-----


More information about the Natty-changes mailing list