Login
Newsletter
Werbung

Sicherheit: Cross-Site Scripting in BackupPC
Aktuelle Meldungen Distributionen
Name: Cross-Site Scripting in BackupPC
ID: USN-1444-1
Distribution: Ubuntu
Plattformen: Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04 LTS
Datum: Fr, 18. Mai 2012, 07:46
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5081
Applikationen: BackupPC

Originalnachricht


--===============2746880576027308671==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-Y6RX9ra0fBWLEivYBKCn"


--=-Y6RX9ra0fBWLEivYBKCn
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1444-1
May 17, 2012

backuppc vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
- Ubuntu 8.04 LTS

Summary:

BackupPC could be made to expose sensitive information over the network.

Software Description:
- backuppc: high-performance, enterprise-grade system for backing up PCs

Details:

It was discovered that BackupPC did not properly sanitize its input when
processing RestoreFile error messages, resulting in a cross-site
scripting (XSS) vulnerability. With cross-site scripting vulnerabilities,
if a user were tricked into viewing server output during a crafted server
request, a remote attacker could exploit this to modify the contents, or
steal confidential data, within the same domain.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
backuppc 3.2.1-2ubuntu1.1

Ubuntu 11.10:
backuppc 3.2.1-1ubuntu1.2

Ubuntu 11.04:
backuppc 3.2.0-3ubuntu4.3

Ubuntu 10.04 LTS:
backuppc 3.1.0-9ubuntu1.3

Ubuntu 8.04 LTS:
backuppc 3.0.0-4ubuntu1.4

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1444-1
CVE-2011-5081

Package Information:
https://launchpad.net/ubuntu/+source/backuppc/3.2.1-2ubuntu1.1
https://launchpad.net/ubuntu/+source/backuppc/3.2.1-1ubuntu1.2
https://launchpad.net/ubuntu/+source/backuppc/3.2.0-3ubuntu4.3
https://launchpad.net/ubuntu/+source/backuppc/3.1.0-9ubuntu1.3
https://launchpad.net/ubuntu/+source/backuppc/3.0.0-4ubuntu1.4



--Ò6RX9ra0fBWLEivYBKCn
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJPtYArAAoJEFHb3FjMVZVzWgIP/RVPrNoszlYR5GJ+K65yBXYL
sK4CPm7cMWZHolYwpX6htmM/TFv8v+3foHYLjZTvRKLH7x7vrrYmTKyPJWM0rvdY
7Yg8wNLgkiJ/n0dvXTwG5ONCgPVM2h+n8XSyVyZHa2yjzQ/nmHCSHVGUqB7yv8CI
F8IKJrIEDC1zp7fXKEa6p72J+9BIpd7ruqDjOjHaY65ujWvlhJoWn5BLLNNbgymZ
x1POtHSRt4dG6/TM2dLDqSyDWtgCAB4Rae7tRF2QpUg2j8QMjPVcAaY2CRtTDcQH
G57GCgocGEbERTTqN8zZTleMT/7rUbwoc8J8IIs9Sd1H9BJHJLhQxB2yaax9u4qA
l63rKzOGrQnI0df+OEyXDxbYvIMLRMuK2TXUBcVfZiBrlfYKX1XLroeLmI+oZdW+
TQvRnD70FXSrK6QCA9ci25psBcpyvBnrvRRGN36zFHzxgmWOQisrwzL3EBu9uqa4
K4o6RNv1CwcDys60mpgL4EKw8+/h/F4AS+xGfhQ8tj3HXeCUrK1SspcBjo45YyPk
eAjS+HMiUkTFARqfwMspkQOtzdggxSKk1MbS2AZr4aKKi0S2Drp3wDsfe/yZ3HWh
SK3xTw9Ws5GERvDNi3PFuh8gLcqiAtaqCLN3HLYaXf4y/29XgaEDW1GpxLyGBKQW
yCVQNk4UrnWSkjVBUlkY
=jopy
-----END PGP SIGNATURE-----

--=-Y6RX9ra0fBWLEivYBKCn--



--===============2746880576027308671==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============2746880576027308671==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung