-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-14157 2012-09-17 16:38:51 --------------------------------------------------------------------------------
Name : dbus Product : Fedora 17 Version : 1.4.10 Release : 5.fc17 URL : http://www.freedesktop.org/software/dbus/ Summary : D-BUS message bus Description : D-BUS is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility. -------------------------------------------------------------------------------- Update Information: Resolves https://bugzilla.redhat.com/show_bug.cgi?id=857226 and https://bugzilla.redhat.com/show_bug.cgi?id=857227 -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 13 2012 Colin Walters <[email protected]> - 1:1.4.0-5 - CVE-2012-3524 -------------------------------------------------------------------------------- References: [ 1 ] Bug #857226 - CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=857226 [ 2 ] Bug #857227 - CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=857227 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update dbus' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
