Advisories ยป MGASA-2014-0129

Updated udisks and udisks2 packages fixes security vulnerability

Publication date: 15 Mar 2014
Modification date: 15 Mar 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-0004

Description

A flaw was found in the way udisks and udisks2 handled long path names. A
malicious, local user could use this flaw to create a specially-crafted
directory structure that could lead to arbitrary code execution with the
privileges of the udisks daemon (root) (CVE-2014-0004).
                

References

SRPMS

3/core

4/core