Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:2125-1

Опубликовано: 28 июл. 2018
Источник: suse-cvrf

Описание

Security update for cinnamon

This update for cinnamon fixes the following issues:

Security issue fixed:

  • CVE-2018-13054: Fix symlink attack vulnerability (boo#1083067).

Bug fixes:

  • Update to version 3.4.6 (changes since 3.4.4):
    • osdWindow.js: Always check the theme node on first showing - an actor's width isn't necessarily filled if it hasn't been explicitly set, causing the first few activations of the OSD to not show an accurate level bar.
    • cs_default: Fix an incorrect button label (but preserve translations).
    • main.js: Remove an obsolete Meta enum member reference.
    • workspace.js: Use our normal prototype init method.
    • workspace.js: Initalise WindowClone._zoomStep to 0.
    • slideshow-applet: Fix a translation.
    • cs_themes.py: Create the file '~/.icons/default/index.theme' and set the selected cursor theme inside of it. This ensures other (non-gtk) applications end up using the same theme (though they are required to be restarted for these changes to take effect).
    • keyboard-applet: Applet icon vanishes when moved in edit mode.
    • cinnamon-json-makepot: Add keyword option, change language used by xgettext to JavaScript.
    • expoThumbnail: Correct a couple of calls with mismatched argument counts.
    • window-list: Set AppMenuButtons unreactive during panel edit mode.
    • panel-launchers: Set PanelAppLaunchers unreactive during panel edit mode.
    • windows-quick-list: Fix argument warning.
    • Fix a reference to undefined actor._delegate warning.
    • ui/environment: Handle undefined actors in containerClass.prototype.add.
    • ui/cinnamonDBus: Handle null xlet objects in CinnamonDBus.highlightXlet.
    • deskletManager: Initialise some variables and remove the variables that were initialised, probable typo

Список пакетов

openSUSE Leap 42.3
cinnamon-3.4.6-2.3.1
cinnamon-gschemas-3.4.6-2.3.1
cinnamon-gschemas-branding-upstream-3.4.6-2.3.1

Описание

An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.


Затронутые продукты
openSUSE Leap 42.3:cinnamon-3.4.6-2.3.1
openSUSE Leap 42.3:cinnamon-gschemas-3.4.6-2.3.1
openSUSE Leap 42.3:cinnamon-gschemas-branding-upstream-3.4.6-2.3.1

Ссылки