drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Überschreiben von Dateien in patch
Name: |
Überschreiben von Dateien in patch |
|
ID: |
FEDORA-2011-1272 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 14 |
|
Datum: |
Di, 8. März 2011, 08:23 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4651 |
|
Applikationen: |
patch |
|
Originalnachricht |
------------------------------------------------------------------------------- - Fedora Update Notification FEDORA-2011-1272 2011-02-10 20:46:53 ------------------------------------------------------------------------------- -
Name : patch Product : Fedora 14 Version : 2.6.1 Release : 8.fc14 URL : http://www.gnu.org/software/patch/patch.html Summary : Utility for modifying/upgrading files Description : The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file).
Patch should be installed because it is a common way of upgrading applications.
------------------------------------------------------------------------------- - Update Information:
Applied fix so that malicious patches cannot create files above the current directory (CVE-2010-4651). ------------------------------------------------------------------------------- - ChangeLog:
* Thu Feb 10 2011 Tim Waugh <twaugh@redhat.com> 2.6.1-8 - Incorporate upstream fix for CVE-2010-4651 patch so that a target name given on the command line is not validated (bug #667529). * Tue Feb 8 2011 Tim Waugh <twaugh@redhat.com> 2.6.1-7 - Applied upstream patch to fix CVE-2010-4651 so that malicious patches cannot create files above the current directory (bug #667529). * Tue Jan 4 2011 Tim Waugh <twaugh@redhat.com> 2.6.1-6 - Use smp_mflags correctly (bug #665770). ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #667529 - CVE-2010-4651 patch: directory traversal flaw allows for arbitrary file creation https://bugzilla.redhat.com/show_bug.cgi?id=667529 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update patch' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|