opie security update
This update fixes off-by-one errors in opiesu
(CVE-2011-2489) and missing setuid() return value checks in
opielogin (CVE-2011-2490).
This update also removes the setuid bit from opiesu
program. If you rely on the setuid bit on opiesu, add the
following line to /etc/permissions.local:
/usr/bin/opiesu root:root 4755
-
Submitted by
Adrian Schröter (adrianSuSE)
- Version 4812