drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mangelnde Eingabeprüfung in KDE
Name: |
Mangelnde Eingabeprüfung in KDE |
|
ID: |
USN-1276-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04, Ubuntu 11.10 |
|
Datum: |
Di, 22. November 2011, 07:39 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2725 |
|
Applikationen: |
KDE Software Compilation |
|
Originalnachricht |
--===============8787015389124508251== Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-QWJ6Xn7ucvuCDHKZ5kOe"
--=-QWJ6Xn7ucvuCDHKZ5kOe Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-1276-1 November 21, 2011
kdeutils vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS
Summary:
Ark could be made to remove files.
Software Description: - kdeutils: KDE general-purpose utilities
Details:
Tim Brown discovered that Ark did not properly perform input validation when previewing archive files. If a user were tricked into opening a crafted archive file, an attacker could remove files via directory traversal.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 11.10: ark 4:4.7.1-0ubuntu3.1
Ubuntu 11.04: ark 4:4.6.5-0ubuntu1.2
Ubuntu 10.10: ark 4:4.5.5-0ubuntu2.2
Ubuntu 10.04 LTS: ark 4:4.4.5-0ubuntu1.2
After a standard system update you need to restart your session to make all the necessary changes.
NOTE: In order to build KDE Utilities on Ubuntu 10.04 LTS, 10.10 and 11.04, it was necessary to rebuild portions of the KDE point release updates.
References: http://www.ubuntu.com/usn/usn-1276-1 CVE-2011-2725
Package Information: https://launchpad.net/ubuntu/+source/kdeutils/4:4.7.1-0ubuntu3.1 https://launchpad.net/ubuntu/+source/kdeutils/4:4.6.5-0ubuntu1.2 https://launchpad.net/ubuntu/+source/kdeutils/4:4.5.5-0ubuntu2.2 https://launchpad.net/ubuntu/+source/kdeutils/4:4.4.5-0ubuntu1.2
--ÚWJ6Xn7ucvuCDHKZ5kOe Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAABCgAGBQJOyuSbAAoJEFHb3FjMVZVzEhQP/0/i7DpzIgIQlmJsisNsGzmW KpOqdtGfauuSg6J6yKcdNrh9b03U46oyGohpcXdLjDVkviOVDCFW5bOcahD2M8Aj /6l1j6gITql/A+I0VxEFfnPvIG2jTxoB3u6WReoBssfs/XkEsXQ/KDJHyOtmUFEy 9ub482Xxwx6FJvrAhE8RuXJN+mFSytuchcmWtWhAAJVAnY4zdmPB5ysssxyD+oD6 WYMV8zZCV0NLaflReFA+0dZt1h+uc4ZyZpIIYGQWqMduiUSFLHOfj5BjHJwweygO csdgdeQ8ryFBWpvIbNFjScLdweg3mkPikTKK+stjiFjp9+eILZiofevHRlfCEETl mM6dpMmRcDlhcmF0VnHxA+sSZFrrYTlVf+gd/uFPIITS0X6+CGC2a6dk9vcr6xAS eT2Rb6UApxmzUMMrEfdW5Og168rkf5jG4hRBSOMvgOBDu1n578xlwzb3t9wWVZON +a0LJh/IbNqeUtcxO8OoPBnfzazW1iGKQyadrquGRDfCPPgmw/XP9LgBg1t9J41B qujKO3frMqLCYR3toPhBXUrjOlsENRLeWw8dnLfJ9NmpwbyUCdnCwBbBbvTptjdP xkhfqdFLzhM8esOZDW7KyygtyHSlj/SGb7FxiSLmDNRRMlIu/qdrm6POewFkVVR4 PwnEjvFP6OUNsrCP35i9 =aAhW -----END PGP SIGNATURE-----
--=-QWJ6Xn7ucvuCDHKZ5kOe--
--===============8787015389124508251== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============8787015389124508251==--
|
|
|
|