MGASA-2014-0111
Dashboard / Vulnerabilities / MGASA-2014-0111
Summary: Updated x2goserver package fixes security vulnerability
Details: A vulnerability in x2goserver before 4.0.0.2 in the setgid wrapper x2gosqlitewrapper.c, which does not hardcode an internal path to x2gosqlitewrapper.pl, allowing a remote attacker to change that path. A remote attacker may be able to execute arbitrary code with the privileges of the user running the server process (CVE-2013-4376). A vulnerability in x2goserver before 4.0.0.8 in x2gocleansessions has also been fixed.
References: https://advisories.mageia.org/MGASA-2014-0111.html, https://bugs.mageia.org/show_bug.cgi?id=11557, https://lists.berlios.de/pipermail/x2go-announcement/2013-May/000125.html, http://www.gentoo.org/security/en/glsa/glsa-201310-19.xml, https://lists.fedoraproject.org/pipermail/package-announce/2014-January/126414.html
Affected packages
Package
Name: x2goserver
Purl: pkg:rpm/mageia/x2goserver?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
