diff options
Diffstat (limited to 'zarb-ml/mageia-dev/2013-March/023280.html')
-rw-r--r-- | zarb-ml/mageia-dev/2013-March/023280.html | 78 |
1 files changed, 78 insertions, 0 deletions
diff --git a/zarb-ml/mageia-dev/2013-March/023280.html b/zarb-ml/mageia-dev/2013-March/023280.html new file mode 100644 index 000000000..59fc323c2 --- /dev/null +++ b/zarb-ml/mageia-dev/2013-March/023280.html @@ -0,0 +1,78 @@ +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> +<HTML> + <HEAD> + <TITLE> [Mageia-dev] Regular users installing updates through packagekit or rpmdrake + </TITLE> + <LINK REL="Index" HREF="index.html" > + <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Regular%20users%20installing%20updates%20through%20packagekit%20or%0A%09rpmdrake&In-Reply-To=%3C1362433125.96019.YahooMailClassic%40web122001.mail.ne1.yahoo.com%3E"> + <META NAME="robots" CONTENT="index,nofollow"> + <META http-equiv="Content-Type" content="text/html; charset=us-ascii"> + <LINK REL="Previous" HREF="023287.html"> + <LINK REL="Next" HREF="023323.html"> + </HEAD> + <BODY BGCOLOR="#ffffff"> + <H1>[Mageia-dev] Regular users installing updates through packagekit or rpmdrake</H1> + <B>David Walser</B> + <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Regular%20users%20installing%20updates%20through%20packagekit%20or%0A%09rpmdrake&In-Reply-To=%3C1362433125.96019.YahooMailClassic%40web122001.mail.ne1.yahoo.com%3E" + TITLE="[Mageia-dev] Regular users installing updates through packagekit or rpmdrake">luigiwalser at yahoo.com + </A><BR> + <I>Mon Mar 4 22:38:45 CET 2013</I> + <P><UL> + <LI>Previous message: <A HREF="023287.html">[Mageia-dev] Freeze push: xfce4-eyes-plugin 4.4.2 +</A></li> + <LI>Next message: <A HREF="023323.html">[Mageia-dev] Regular users installing updates through packagekit or rpmdrake +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#23280">[ date ]</a> + <a href="thread.html#23280">[ thread ]</a> + <a href="subject.html#23280">[ subject ]</a> + <a href="author.html#23280">[ author ]</a> + </LI> + </UL> + <HR> +<!--beginarticle--> +<PRE>OpenSuSE issued an advisory for PackageKit, because when systems were configured to allow regular users to install security updates, they also had the ability to install *older* updates than the newest, reintroducing security issues into the system. + +Does PackageKit in Mageia, or even our own rpmdrake tool which can be configured to allow users to install updates, have an issue with this? + +References: +<A HREF="http://lists.opensuse.org/opensuse-updates/2013-03/msg00006.html">http://lists.opensuse.org/opensuse-updates/2013-03/msg00006.html</A> +<A HREF="https://bugzilla.novell.com/show_bug.cgi?id=804983">https://bugzilla.novell.com/show_bug.cgi?id=804983</A> +<A HREF="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1764">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1764</A> +</PRE> + + + + + + + + + + + + + + + + +<!--endarticle--> + <HR> + <P><UL> + <!--threads--> + <LI>Previous message: <A HREF="023287.html">[Mageia-dev] Freeze push: xfce4-eyes-plugin 4.4.2 +</A></li> + <LI>Next message: <A HREF="023323.html">[Mageia-dev] Regular users installing updates through packagekit or rpmdrake +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#23280">[ date ]</a> + <a href="thread.html#23280">[ thread ]</a> + <a href="subject.html#23280">[ subject ]</a> + <a href="author.html#23280">[ author ]</a> + </LI> + </UL> + +<hr> +<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev +mailing list</a><br> +</body></html> |