SUSE-SU-2018:3625-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3625-1
SUSE-SU-2018:3625-1
Summary: Security update for accountsservice
Details: This update for accountsservice fixes the following issues: This security issue was fixed: - CVE-2018-14036: Prevent directory traversal caused by an insufficient path check in user_change_icon_file_authorized_cb() (bsc#1099699) Thsese non-security issues were fixed: - Don't abort loading users when an /etc/shadow entry is missing. (bsc#1090003) - When user session type is wayland, act_user_is_logged_in can return TRUE if the user is logged in. (bsc#1095918)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183625-1/, https://bugzilla.suse.com/1090003, https://bugzilla.suse.com/1095918, https://bugzilla.suse.com/1099699, https://www.suse.com/security/cve/CVE-2018-14036
Affected packages
Package
Name: accountsservice
Purl: pkg:rpm/suse/accountsservice&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015
Affected ranges
Type: ECOSYSTEM
Events:
