drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in wicd
Name: |
Ausführen beliebiger Kommandos in wicd |
|
ID: |
FEDORA-2012-5923 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 15 |
|
Datum: |
Di, 24. April 2012, 19:06 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2095 |
|
Applikationen: |
wicd |
|
Originalnachricht |
Name : wicd Product : Fedora 15 Version : 1.7.0 Release : 12.fc15 URL : http://wicd.sourceforge.net/ Summary : Wireless and wired network connection manager Description : Wicd is designed to give the user as much control over behavior of network connections as possible. Every network, both wired and wireless, has its own profile with its own configuration options and connection behavior. Wicd will try to automatically connect only to networks the user specifies it should try, with a preference first to a wired network, then to wireless.
This package provides the architecture-dependent components of wicd.
------------------------------------------------------------------------------- - Update Information:
This update fixes CVE-2012-2095. The wicd daemon suffered from a local privilege escalation flaw due to incomplete input sanitization. A local attacker sould use this to inject arbitrary code through the D-Bus interface. ------------------------------------------------------------------------------- - ChangeLog:
* Fri Apr 13 2012 David Cantrell <dcantrell@redhat.com> - 1.7.0-12 - Fix CVE-2012-2095 (#811763) * Fri Jan 27 2012 David Cantrell <dcantrell@redhat.com> - 1.7.0-11 - Fix CVE-2012-0813 (#785147) * Fri Aug 19 2011 David Cantrell <dcantrell@redhat.com> - 1.7.0-10 - Initialize appGui._wired_showing in __init__ (#723553) - Make sure check and message in wicd-cli are a lambda (#712435) * Thu Aug 11 2011 David Cantrell <dcantrell@redhat.com> - 1.7.0-9 - Correct systemd unit file for wicd, add D-Bus service file (#699116) - Move docs to the wicd-common subpackage - Correct /etc/dbus-1/system.d/wicd.conf (#699116) * Mon May 9 2011 Bill Nottingham <notting@redhat.com> - 1.7.0-8 - fix systemd scriptlets for upgrade * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #811762 - CVE-2012-2095 wicd: broken filtering leads to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=811762 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update wicd' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|