drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in expat
Name: |
Zwei Probleme in expat |
|
ID: |
USN-1527-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 8.04 LTS, Ubuntu 10.04 LTS, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04 LTS |
|
Datum: |
Fr, 10. August 2012, 08:01 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0876
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1148 |
|
Applikationen: |
expat |
|
Originalnachricht |
--===============9019529066822907204== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="45Z9DzgjV8m4Oswq" Content-Disposition: inline
--45Z9DzgjV8m4Oswq Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-1527-1 August 10, 2012
expat vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS - Ubuntu 8.04 LTS
Summary:
Expat could be made to cause a denial of service by consuming excessive CPU and memory resources.
Software Description: - expat: XML parsing C library - example application
Details:
It was discovered that Expat computed hash values without restricting the ability to trigger hash collisions predictably. If a user or application linked against Expat were tricked into opening a crafted XML file, an attacker could cause a denial of service by consuming excessive CPU resources. (CVE-2012-0876)
Tim Boddy discovered that Expat did not properly handle memory reallocation when processing XML files. If a user or application linked against Expat were tricked into opening a crafted XML file, an attacker could cause a denial of service by consuming excessive memory resources. This issue only affected Ubuntu 8.04 LTS, 10.04 LTS, 11.04 and 11.10. (CVE-2012-1148)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04 LTS: lib64expat1 2.0.1-7.2ubuntu1.1 libexpat1 2.0.1-7.2ubuntu1.1 libexpat1-udeb 2.0.1-7.2ubuntu1.1
Ubuntu 11.10: lib64expat1 2.0.1-7ubuntu3.11.10.1 libexpat1 2.0.1-7ubuntu3.11.10.1 libexpat1-udeb 2.0.1-7ubuntu3.11.10.1
Ubuntu 11.04: lib64expat1 2.0.1-7ubuntu3.11.04.1 libexpat1 2.0.1-7ubuntu3.11.04.1 libexpat1-udeb 2.0.1-7ubuntu3.11.04.1
Ubuntu 10.04 LTS: lib64expat1 2.0.1-7ubuntu1.1 libexpat1 2.0.1-7ubuntu1.1 libexpat1-udeb 2.0.1-7ubuntu1.1
Ubuntu 8.04 LTS: lib64expat1 2.0.1-0ubuntu1.2 libexpat1 2.0.1-0ubuntu1.2 libexpat1-udeb 2.0.1-0ubuntu1.2
After a standard system upgrade you need to restart any applications linked against Expat to effect the necessary changes.
References: http://www.ubuntu.com/usn/usn-1527-1 CVE-2012-0876, CVE-2012-1148
Package Information: https://launchpad.net/ubuntu/+source/expat/2.0.1-7.2ubuntu1.1 https://launchpad.net/ubuntu/+source/expat/2.0.1-7ubuntu3.11.10.1 https://launchpad.net/ubuntu/+source/expat/2.0.1-7ubuntu3.11.04.1 https://launchpad.net/ubuntu/+source/expat/2.0.1-7ubuntu1.1 https://launchpad.net/ubuntu/+source/expat/2.0.1-0ubuntu1.2
--45Z9DzgjV8m4Oswq Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAEBCgAGBQJQJIytAAoJENaSAD2qAscK6awQAKpRGtV9uJWD/AmQUxPeMUwS cJRkTGuYSZmlIE61Ioe/8ZCjNWWEk1dWuC4s5rEk3jpIwVT7vSUkKu0YEVhceQdM 6sEbyfGebjJU/jBEHQedOAvdjvsDyKfLXbyJe6G+Ta2oijEz32cSrKkrI6HqJu4f J20wBBs8XuLpue7wmyhKxyggRVzk2asHHjdWys388Uov+uhQoAy5df8bITDERX0r B6mU7+Eu19aKpPCzk7ZeV30Xxfcx/QqM0pPKjJrqy3dcpAaAAmx7EUEJamU5Qeol S8I5cFMDHBVk7vqKT1anO8prLct+ie1MK4U1VmWUBYavHCQqYjEkGS/3ZsySUIJw YmrRUryH6+hzFxjyZ5O3Qt+FJbg4r2e987+i69+a5p6QEEfXs8Jr/Tnc326bXU3C y5ibTT7ioaMQKxvYdzu4dh1nnlULpHnVYqUv8Z/GiC26DZ3/q9RvqVfm+h98Hn0k 1sUnZSizS+tI/ZJrN4EkQWSJA8AdBS9OadypLq+Ahes0kt4Yqm3Cv21rq0eIKiUs hAzGY3eOrxoQuqOxGhbTTcKbNAW8uuGsAWItuOGLEhfBnsvbbmOWaxFL82fTfDZu 07A+Kbi3+rwz+riNXaZ3ePXK/EZUVlwy4zbVz/RJE9vdT5td4u9mMpL24aThNYVi oJoG99M8Vc+Xy5uLcAYW =h/eU -----END PGP SIGNATURE-----
--45Z9DzgjV8m4Oswq--
--===============9019529066822907204== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============9019529066822907204==--
|
|
|
|