Updated udisks and udisks2 packages fixes security vulnerability
Publication date: 15 Mar 2014Modification date: 15 Mar 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-0004
Description
A flaw was found in the way udisks and udisks2 handled long path names. A malicious, local user could use this flaw to create a specially-crafted directory structure that could lead to arbitrary code execution with the privileges of the udisks daemon (root) (CVE-2014-0004).
References
SRPMS
3/core
- udisks-1.0.4-10.1.mga3
- udisks2-2.0.1-2.1.mga3
4/core
- udisks-1.0.4-11.1.mga4
- udisks2-2.1.1-2.1.mga4