ALAS-2014-286


Amazon Linux AMI Security Advisory: ALAS-2014-286
Advisory Release Date: 2014-09-16 22:30 Pacific
Severity: Medium

Issue Overview:

A flaw was found in the way Augeas handled certain umask settings when creating new configuration files. This flaw could result in configuration files being created as world writable, allowing unprivileged local users to modify their content. (CVE-2013-6412 )


Affected Packages:

augeas


Issue Correction:
Run yum update augeas to update your system.

New Packages:
i686:
    augeas-1.0.0-5.7.amzn1.i686
    augeas-debuginfo-1.0.0-5.7.amzn1.i686
    augeas-devel-1.0.0-5.7.amzn1.i686
    augeas-libs-1.0.0-5.7.amzn1.i686

src:
    augeas-1.0.0-5.7.amzn1.src

x86_64:
    augeas-1.0.0-5.7.amzn1.x86_64
    augeas-devel-1.0.0-5.7.amzn1.x86_64
    augeas-libs-1.0.0-5.7.amzn1.x86_64
    augeas-debuginfo-1.0.0-5.7.amzn1.x86_64