File _patchinfo of Package patchinfo.import5631
<patchinfo incident="sysconfig" version="5631"> <issue tracker="bnc" id="559170" /> <issue tracker="bnc" id="580018" /> <issue tracker="bnc" id="697929" /> <issue tracker="bnc" id="739338" /> <issue tracker="bnc" id="735394" /> <issue tracker="CVE" id="CVE-2011-4182" /> <category>security</category> <rating>low</rating> <summary>sysconfig security update</summary> <description>This update for sysconfig contains the following fixes: - sysconfig hook script for NetworkManager did not properly quote shell meta characters when processing ESSIDs. Specially crafted network names could therefore lead to execution of shell code (CVE-2011-4182). - Explicitly disabled posix mode in all bash scripts as we are using several features not supported in posix mode (bnc#739338). - Fixed ipv6 dad / link ready wait time calculation (1/10 of the specified time were used), replaced useless up flag check loop with link_ready_wait to avoid send errors from dhclient6 and cleaned up link / dad wait verify flag after status update (bnc#697929). </description> <packager>adrianSuSE</packager> </patchinfo>