drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Pufferüberlauf in CVS
Name: |
Pufferüberlauf in CVS |
|
ID: |
MDVSA-2012:044 |
|
Distribution: |
Mandriva |
|
Plattformen: |
Mandriva Enterprise Server 5.0, Mandriva 2010.1, Mandriva 2011 |
|
Datum: |
Do, 29. März 2012, 21:42 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0804 |
|
Applikationen: |
CVS |
|
Originalnachricht |
This is a multi-part message in MIME format...
------------=_1333020248-2905-114
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDVSA-2012:044 http://www.mandriva.com/security/ _______________________________________________________________________
Package : cvs Date : March 29, 2012 Affected: 2010.1, 2011., Enterprise Server 5.0 _______________________________________________________________________
Problem Description:
A vulnerability has been found and corrected in cvs: A heap-based buffer overflow flaw was found in the way the CVS client handled responses from HTTP proxies. A malicious HTTP proxy could use this flaw to cause the CVS client to crash or, possibly, execute arbitrary code with the privileges of the user running the CVS client (CVE-2012-0804). The updated packages have been patched to correct this issue. _______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0804 _______________________________________________________________________
Updated Packages:
Mandriva Linux 2010.1: 75eadafea0df6324db8e1036d32f52a7 2010.1/i586/cvs-1.12.13-18.1mdv2010.2.i586.rpm 11e671d1b1ef4938a1ea857b6bde2b8b 2010.1/SRPMS/cvs-1.12.13-18.1mdv2010.2.src.rpm
Mandriva Linux 2010.1/X86_64: d2c2e13fb83f5e9548f5fc45e4a9416a 2010.1/x86_64/cvs-1.12.13-18.1mdv2010.2.x86_64.rpm 11e671d1b1ef4938a1ea857b6bde2b8b 2010.1/SRPMS/cvs-1.12.13-18.1mdv2010.2.src.rpm
Mandriva Linux 2011: 8f0aabdd69627ba79ff8c5506e5bbbd5 2011/i586/cvs-1.12.13-18.1-mdv2011.0.i586.rpm cd6ef457350d4f25b762efcf613e95e4 2011/SRPMS/cvs-1.12.13-18.1.src.rpm
Mandriva Linux 2011/X86_64: 36a3b6d65bbbbf80ce2b949a2c906a2e 2011/x86_64/cvs-1.12.13-18.1-mdv2011.0.x86_64.rpm cd6ef457350d4f25b762efcf613e95e4 2011/SRPMS/cvs-1.12.13-18.1.src.rpm
Mandriva Enterprise Server 5: a883573ca234e76fd1179634034a41e4 mes5/i586/cvs-1.12.13-18.1mdvmes5.2.i586.rpm ac4f289b966f7af566c921b7111f186c mes5/SRPMS/cvs-1.12.13-18.1mdvmes5.2.src.rpm
Mandriva Enterprise Server 5/X86_64: f27b646c50d6412f7d3e855d85b07abb mes5/x86_64/cvs-1.12.13-18.1mdvmes5.2.x86_64.rpm ac4f289b966f7af566c921b7111f186c mes5/SRPMS/cvs-1.12.13-18.1mdvmes5.2.src.rpm _______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com _______________________________________________________________________
Type Bits/KeyID Date User ID pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iD8DBQFPdBeZmqjQ0CJFipgRAgF1AKDf/v3sGgDmbj3HiUuDO5JaDJS3TgCg7UIc LJvfJkrvUExhZxyrvXboNEg= =AYEA -----END PGP SIGNATURE-----
------------=_1333020248-2905-114 Content-Type: text/plain; charset="UTF-8"; name="message-footer.txt" Content-Disposition: inline; filename="message-footer.txt" Content-Transfer-Encoding: 8bit
To unsubscribe, send a email to sympa@mandrivalinux.org with this subject : unsubscribe security-announce _______________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://www.mandrivastore.com Join the Club : http://www.mandrivaclub.com _______________________________________________________
------------=_1333020248-2905-114--
|
|
|
|