USN-841-1: GLib vulnerability
5 October 2009
GLib vulnerability
Releases
Packages
- glib2.0 -
Details
Arand Nash discovered that applications linked to GLib (e.g. Nautilus)
did not correctly copy symlinks. If a user copied symlinks with GLib,
the symlink target files would become world-writable, allowing local
attackers to gain access to potentially sensitive information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.04
Ubuntu 8.10
Ubuntu 8.04
After a standard system upgrade you need to restart your session to effect
the necessary changes.