drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in mc
Name: |
Ausführen beliebiger Kommandos in mc |
|
ID: |
FEDORA-2012-19349 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 17 |
|
Datum: |
Sa, 8. Dezember 2012, 14:48 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4463 |
|
Applikationen: |
Midnight Commander |
|
Originalnachricht |
Name : mc Product : Fedora 17 Version : 4.8.6 Release : 2.fc17 URL : http://www.midnight-commander.org/ Summary : User-friendly text console file manager and visual shell Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files.
------------------------------------------------------------------------------- - Update Information:
sanitize of MC_EXT_SELECTED variable when viewing multiple files, CVE-2012-4463 (#862814) https://www.midnight-commander.org/ticket/2913 ------------------------------------------------------------------------------- - ChangeLog:
* Wed Nov 28 2012 Jindrich Novy <jnovy@redhat.com> 4.8.6-2 - sanitize of MC_EXT_SELECTED variable when viewing multiple files, CVE-2012-4463 (#862814) https://www.midnight-commander.org/ticket/2913 * Thu Sep 20 2012 Jindrich Novy <jnovy@redhat.com> 4.8.6-1 - update to 4.8.6 (#857512) * Tue Sep 11 2012 Jindrich Novy <jnovy@redhat.com> 4.8.5-1 - update to 4.8.5 (#815307) * Mon Jul 23 2012 Jindrich Novy <jnovy@redhat.com> 4.8.4-2 - BR: libssh2-devel for SFTP support - BR: aspell-devel * Wed Jul 18 2012 Jindrich Novy <jnovy@redhat.com> 4.8.4-1 - update to 4.8.4 ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #862813 - CVE-2012-4463 mc: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files https://bugzilla.redhat.com/show_bug.cgi?id=862813 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update mc' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|