drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Pufferüberläufe in mod_auth_pgsql
Name: |
Pufferüberläufe in mod_auth_pgsql |
|
ID: |
FEDORA-2005-014 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora Core 3 |
|
Datum: |
Fr, 6. Januar 2006, 18:46 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3656 |
|
Applikationen: |
mod_auth_pgsql |
|
Originalnachricht |
--------------------------------------------------------------------- Fedora Update Notification FEDORA-2005-014 2006-01-06 ---------------------------------------------------------------------
Product : Fedora Core 3 Name : mod_auth_pgsql Version : 2.0.1 Release : 6.2 Summary : Basic authentication for the Apache web server using a PostgreSQL database. Description : mod_auth_pgsql can be used to limit access to documents served by a web server by checking fields in a table in a PostgresQL database.
--------------------------------------------------------------------- Update Information:
Several format string flaws were found in the way mod_auth_pgsql logs information. It may be possible for a remote attacker to execute arbitrary code as the 'apache' user if mod_auth_pgsql is used for user authentication. The Common Vulnerabilities and Exposures project assigned the name CVE-2005-3656 to this issue.
Please note that this issue only affects servers which have mod_auth_pgsql installed and configured to perform user authentication against a PostgreSQL database.
Red Hat would like to thank iDefense for reporting this issue. --------------------------------------------------------------------- * Fri Jan 6 2006 Joe Orton <jorton@redhat.com> 2.0.1-6.2 - add security fix for CVE-2005-3656 - don't strip .so file so debuginfo works - fix r->user handling (Mirko Streckenbach, #150087)
--------------------------------------------------------------------- This update can be downloaded from: http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
f4de3874523d13558b62a7b616a9924b SRPMS/mod_auth_pgsql-2.0.1-6.2.src.rpm 710fe9e31a155fca650aa2e948caf3e0 x86_64/mod_auth_pgsql-2.0.1-6.2.x86_64.rpm a98acc532d16f6824643f84681a925ba x86_64/debug/mod_auth_pgsql-debuginfo-2.0.1-6.2.x86_64.rpm 2b1130b5b5be47de09f927b2dd87bd94 i386/mod_auth_pgsql-2.0.1-6.2.i386.rpm 2d348cb3ca7f7525dce925a20fed88da i386/debug/mod_auth_pgsql-debuginfo-2.0.1-6.2.i386.rpm
This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. ---------------------------------------------------------------------
-- fedora-announce-list mailing list fedora-announce-list@redhat.com https://www.redhat.com/mailman/listinfo/fedora-announce-list
|
|
|
|