gnome-boxes 3.20.4, 3.22.4, 3.23.4.1 security releases



Hello distributors,

We just made a round of unplanned releases for GNOME Boxes in order to
fix a possibly exploitable vulnerability with the caching of passwords
for express installs.

The user password entered during the express install process used to
be cached in plain-text in
~/.config/gnome-boxes/unatteded/setup-data.conf. As a solution, we are
now storing the password in the keyring.

The new releases are:

3.20.4
3.22.4
3.23.4-1

If in any doubt, contact us in #boxes at irc.gnome.org or email
https://mail.gnome.org/mailman/listinfo/gnome-boxes-list

Regards,
Felipe Borges.


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]