glib2.0 2.16.6-3 source package in Debian

Changelog

glib2.0 (2.16.6-3) stable; urgency=low


  * SECURITY: 13_permissions_CVE-2009-3289.patch:
    + The g_file_copy function in glib 2.0 sets the permissions of a 
      target file to the permissions of a symbolic link (777), which 
      allows user-assisted local users to modify files of other users, 
      as demonstrated by using Nautilus to modify the permissions of the 
      user home directory.
    + Concatenation of 3 upstream patches, fixes CVE-2009-3289.

 -- Josselin Mouette <email address hidden>  Sat, 14 Nov 2009 16:19:20 +0100

Upload details

Uploaded by:
Loïc Minier
Uploaded to:
Lenny
Original maintainer:
Loïc Minier
Architectures:
any
Section:
libs
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Lenny release main libs

Builds

Downloads

File Size SHA-256 Checksum
glib2.0_2.16.6-3.dsc 1.4 KiB 7b46ba0e9325fe6dab474b5ceb638b345b1a3074928e758dafcfb1b19c83aa55
glib2.0_2.16.6.orig.tar.gz 6.2 MiB 977d5720f7f43a76261804e79cade381fa874385a45bf52a9cc4440106256f88
glib2.0_2.16.6-3.diff.gz 33.3 KiB 635966d6b1b12330ecd903d3476a84a7efae0e4c86040801c2d9e39922389d65

No changes file available.

Binary packages built by this source