summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-dev/2013-March/023280.html
blob: 59fc323c27c318576537bb91778c6f73fa951165 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
 <HEAD>
   <TITLE> [Mageia-dev] Regular users installing updates through packagekit or	rpmdrake
   </TITLE>
   <LINK REL="Index" HREF="index.html" >
   <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Regular%20users%20installing%20updates%20through%20packagekit%20or%0A%09rpmdrake&In-Reply-To=%3C1362433125.96019.YahooMailClassic%40web122001.mail.ne1.yahoo.com%3E">
   <META NAME="robots" CONTENT="index,nofollow">
   <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
   <LINK REL="Previous"  HREF="023287.html">
   <LINK REL="Next"  HREF="023323.html">
 </HEAD>
 <BODY BGCOLOR="#ffffff">
   <H1>[Mageia-dev] Regular users installing updates through packagekit or	rpmdrake</H1>
    <B>David Walser</B> 
    <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Regular%20users%20installing%20updates%20through%20packagekit%20or%0A%09rpmdrake&In-Reply-To=%3C1362433125.96019.YahooMailClassic%40web122001.mail.ne1.yahoo.com%3E"
       TITLE="[Mageia-dev] Regular users installing updates through packagekit or	rpmdrake">luigiwalser at yahoo.com
       </A><BR>
    <I>Mon Mar  4 22:38:45 CET 2013</I>
    <P><UL>
        <LI>Previous message: <A HREF="023287.html">[Mageia-dev] Freeze push: xfce4-eyes-plugin 4.4.2
</A></li>
        <LI>Next message: <A HREF="023323.html">[Mageia-dev] Regular users installing updates through packagekit or	rpmdrake
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#23280">[ date ]</a>
              <a href="thread.html#23280">[ thread ]</a>
              <a href="subject.html#23280">[ subject ]</a>
              <a href="author.html#23280">[ author ]</a>
         </LI>
       </UL>
    <HR>  
<!--beginarticle-->
<PRE>OpenSuSE issued an advisory for PackageKit, because when systems were configured to allow regular users to install security updates, they also had the ability to install *older* updates than the newest, reintroducing security issues into the system.

Does PackageKit in Mageia, or even our own rpmdrake tool which can be configured to allow users to install updates, have an issue with this?

References:
<A HREF="http://lists.opensuse.org/opensuse-updates/2013-03/msg00006.html">http://lists.opensuse.org/opensuse-updates/2013-03/msg00006.html</A>
<A HREF="https://bugzilla.novell.com/show_bug.cgi?id=804983">https://bugzilla.novell.com/show_bug.cgi?id=804983</A>
<A HREF="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1764">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1764</A>
</PRE>
















<!--endarticle-->
    <HR>
    <P><UL>
        <!--threads-->
	<LI>Previous message: <A HREF="023287.html">[Mageia-dev] Freeze push: xfce4-eyes-plugin 4.4.2
</A></li>
	<LI>Next message: <A HREF="023323.html">[Mageia-dev] Regular users installing updates through packagekit or	rpmdrake
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#23280">[ date ]</a>
              <a href="thread.html#23280">[ thread ]</a>
              <a href="subject.html#23280">[ subject ]</a>
              <a href="author.html#23280">[ author ]</a>
         </LI>
       </UL>

<hr>
<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
mailing list</a><br>
</body></html>