diff options
author | Chris Lamb <lamby@debian.org> | 2020-09-15 12:24:15 +0100 |
---|---|---|
committer | Chris Lamb <lamby@debian.org> | 2020-09-15 12:24:16 +0100 |
commit | 943fdae171ceaeb4a44d08b77255762821cb5331 (patch) | |
tree | d5f9078760f1d063ee7a8995362c820fc3cd7eeb | |
parent | bf3bfe54e200fdc15031a695f1a95e2a5f4333b3 (diff) |
Add DLA-2374-1.
-rw-r--r-- | english/lts/security/2020/dla-2374.data | 9 | ||||
-rw-r--r-- | english/lts/security/2020/dla-2374.wml | 36 |
2 files changed, 45 insertions, 0 deletions
diff --git a/english/lts/security/2020/dla-2374.data b/english/lts/security/2020/dla-2374.data new file mode 100644 index 00000000000..b5cdc3593e3 --- /dev/null +++ b/english/lts/security/2020/dla-2374.data @@ -0,0 +1,9 @@ +<define-tag pagetitle>DLA-2374-1 gnome-shell</define-tag> +<define-tag report_date>2020-09-15</define-tag> +<define-tag secrefs>CVE-2020-17489</define-tag> +<define-tag packages>gnome-shell</define-tag> +<define-tag isvulnerable>yes</define-tag> +<define-tag fixed>yes</define-tag> +<define-tag fixed-section>no</define-tag> + +#use wml::debian::security diff --git a/english/lts/security/2020/dla-2374.wml b/english/lts/security/2020/dla-2374.wml new file mode 100644 index 00000000000..e0cd5a7fea3 --- /dev/null +++ b/english/lts/security/2020/dla-2374.wml @@ -0,0 +1,36 @@ +<define-tag description>LTS security update</define-tag> +<define-tag moreinfo> + +<p>It was discovered that there was an issue around revealing passwords in the +<tt>gnome-shell</tt> component of the GNOME desktop.</p> + +<p>In certain configurations, when logging out of an account the password box +from the login dialog could reappear with the password visible in +cleartext.</p> + +<ul> + +<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-17489">CVE-2020-17489</a> + + <p>An issue was discovered in certain configurations of GNOME gnome-shell + through 3.36.4. When logging out of an account, the password box from the + login dialog reappears with the password still visible. If the user had + decided to have the password shown in cleartext at login time, it is then + visible for a brief moment upon a logout. (If the password were never shown + in cleartext, only the password length is revealed.)</p></li> + +</ul> + +<p>For Debian 9 <q>Stretch</q>, these problems have been fixed in version +3.22.3-3+deb9u1.</p> + +<p>We recommend that you upgrade your gnome-shell packages.</p> + +<p>Further information about Debian LTS security advisories, how to apply +these updates to your system and frequently asked questions can be +found at: <a href="https://wiki.debian.org/LTS">https://wiki.debian.org/LTS</a></p> +</define-tag> + +# do not modify the following line +#include "$(ENGLISHDIR)/lts/security/2020/dla-2374.data" +# $Id: $ |