From 647676c202022175a331c29a79dba20ef88e9f74 Mon Sep 17 00:00:00 2001 From: Jim Somerville Date: Thu, 21 Nov 2019 18:23:21 -0500 Subject: [PATCH] Uprev polkit to version 0.112-22.el7 This solves: polkit: Improper handling of user with uid > INT_MAX leading to authentication bypass (CVE-2018-19788) See the announcement link: https://lists.centos.org/pipermail/centos-cr-announce/2019-August/006051.html for more details. Change-Id: I6eb69cd129b2b6d0e115f65b42f997d2b3f69d9a Closes-Bug: 1849202 Signed-off-by: Jim Somerville --- centos-mirror-tools/rpms_centos.lst | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/centos-mirror-tools/rpms_centos.lst b/centos-mirror-tools/rpms_centos.lst index 2bc23ac1..6666b63d 100644 --- a/centos-mirror-tools/rpms_centos.lst +++ b/centos-mirror-tools/rpms_centos.lst @@ -1061,9 +1061,9 @@ plexus-interpolation-1.15-8.el7.noarch.rpm plexus-sec-dispatcher-1.4-13.el7.noarch.rpm plexus-utils-3.0.9-9.el7.noarch.rpm pm-utils-1.4.1-27.el7.x86_64.rpm -polkit-0.112-18.el7.x86_64.rpm -polkit-devel-0.112-18.el7.x86_64.rpm -polkit-docs-0.112-18.el7.noarch.rpm +polkit-0.112-22.el7.x86_64.rpm +polkit-devel-0.112-22.el7.x86_64.rpm +polkit-docs-0.112-22.el7.noarch.rpm polkit-pkla-compat-0.1-4.el7.x86_64.rpm poppler-0.26.5-20.el7.x86_64.rpm poppler-data-0.4.6-3.el7.noarch.rpm