-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3217-1 [email protected] https://www.debian.org/lts/security/ Utkarsh Gupta December 03, 2022 https://wiki.debian.org/LTS - -----------------------------------------------------------------------
Package : g810-led Version : 0.3.3-2+deb10u1 CVE ID : CVE-2022-46338 Debian Bug : 1024998 g810-led, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data. For Debian 10 buster, this problem has been fixed in version 0.3.3-2+deb10u1. We recommend that you upgrade your g810-led packages. For the detailed security status of g810-led please refer to its security tracker page at: https://security-tracker.debian.org/tracker/g810-led Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmOKhoIACgkQgj6WdgbD S5bwHQ//XhWLQEJujLvt5eux/9loKuoZqTmQPSL5yNCEclNZj84qMULdsdkOHdnW Er9oTlpoH7qWBK3BQ35kMBuacjVeXhySZZ0gCabKnUIaGZsxMyfeFOVl/uE98pAd 6rsZ70kWwXPGHSMOwYRIb4aXFdsvTlff5RVK04S0KIJExRSbxxmmgegrj7TIBybK RJQ69+dI4Tm/Ut0GwheQk9HSqV4G0vDj3Y8K4wCgbzjyPzPSMESIRyz6wDPGRvRA rRQIJN94J6YFx0dYAE8qo+nDiIEhw5iRXV0XTMh+ZQ/igJpb9nY4uPBq6CI5Wpjj OJTc2uCt1uxK4wme9o1mIqNmejfPh9LnPVpmX9deqJL3fx1fZlYlDoMb+EUQCBYf Envrdq32jmTXIHVtfOV8ip639lCHrg2ilurqxTmkJEr6Vg3aBtaj5/80WnVaUPa+ 2NpbT9eIztFc8B7c2ZVqHn91YdgdbB+8f28Pn4+iAd3n6CZxU6FEAV3jci1SJ4HS NfH9moj5u9ZI7BeMRFnEKRI5t2kBt/0DcCpjyoo/4mvlahYOEuxwYKdzeY2J6qdT 6eFgvdQw1rlsT2tYX02p3fG8I/tGE7FMIn34FlFdTpO6Qi9AygNwtliruohpSKI8 lSDWDzceQ5jl8/ZWTW46kCdAEx86CVJ8xtkf7pr1snWGSLJTv2M= =+aDp -----END PGP SIGNATURE-----
