ALAS2-2018-1030


Amazon Linux 2 Security Advisory: ALAS-2018-1030
Advisory Release Date: 2018-06-11 22:03 Pacific
Severity: Low
References: CVE-2017-15131 

Issue Overview:

It was found that the system umask policy is not being honored when creating XDG user directories (~/Desktop etc) on first login. This could lead to user's files being inadvertently exposed to other local users.(CVE-2017-15131 )


Affected Packages:

xdg-user-dirs


Issue Correction:
Run yum update xdg-user-dirs to update your system.

New Packages:
src:
    xdg-user-dirs-0.15-5.amzn2.src

x86_64:
    xdg-user-dirs-0.15-5.amzn2.x86_64
    xdg-user-dirs-debuginfo-0.15-5.amzn2.x86_64