U radu programskog paketa SeaMonkey uočen je niz sigurnosnih ranjivosti. Udaljeni ih napadač može iskoristiti za zaobilaženje pojedinih sigurnosnih ograničenja, izvođenje DoS napada ili pokretanje proizvoljnog programskog koda.
Paket:
SeaMonkey 1.x
Operacijski sustavi:
CentOS
Kritičnost:
7.4
Problem:
cjelobrojno prepisivanje, pogreška u programskoj funkciji, pogreška u programskoj komponenti
Bitnije su ranjivosti posljedica pogrešaka u funkcijama "nsSVGPathSegList::ReplaceItem", "nsXULCommandDispatcher", "nsSVGPointList::AppendElement", prepisivanja cijelog broja u Array.reduceRight metodi, itd.
Posljedica:
Zlonamjerni ih korisnik može iskoristiti za zaobilaženje sigurnosnih ograničenja, izvođenje DoS napada ili pokretanje proizvoljnog programskog koda.
Rješenje:
Korisnike se potiče na instalaciju odgovarajuće nadogradnje.
CentOS Errata and Security Advisory CESA-2011:0888
seamonkey security update for CentOS 4 i386:
https://rhn.redhat.com/errata/RHSA-2011-0888.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
i386:
updates/i386/RPMS/seamonkey-1.0.9-71.el4.centos.i386.rpm
updates/i386/RPMS/seamonkey-chat-1.0.9-71.el4.centos.i386.rpm
updates/i386/RPMS/seamonkey-devel-1.0.9-71.el4.centos.i386.rpm
updates/i386/RPMS/seamonkey-dom-inspector-1.0.9-71.el4.centos.i386.rpm
updates/i386/RPMS/seamonkey-js-debugger-1.0.9-71.el4.centos.i386.rpm
updates/i386/RPMS/seamonkey-mail-1.0.9-71.el4.centos.i386.rpm
source:
updates/SRPMS/seamonkey-1.0.9-71.el4.centos.src.rpm
You may update your CentOS-4 i386 installations by running the command:
yum update seamonkey
Tru
--
Tru Huynh (mirrors, CentOS i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
CentOS Errata and Security Advisory CESA-2011:0888
seamonkey security update for CentOS 4 x86_64:
https://rhn.redhat.com/errata/RHSA-2011-0888.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
x86_64:
updates/x86_64/RPMS/seamonkey-1.0.9-71.el4.centos.x86_64.rpm
updates/x86_64/RPMS/seamonkey-chat-1.0.9-71.el4.centos.x86_64.rpm
updates/x86_64/RPMS/seamonkey-devel-1.0.9-71.el4.centos.x86_64.rpm
updates/x86_64/RPMS/seamonkey-dom-inspector-1.0.9-71.el4.centos.x86_64.rpm
updates/x86_64/RPMS/seamonkey-js-debugger-1.0.9-71.el4.centos.x86_64.rpm
updates/x86_64/RPMS/seamonkey-mail-1.0.9-71.el4.centos.x86_64.rpm
source:
updates/SRPMS/seamonkey-1.0.9-71.el4.centos.src.rpm
You may update your CentOS-4 x86_64 installations by running the command:
yum update seamonkey
Tru
--
Tru Huynh (mirrors, CentOS i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
Posljednje sigurnosne preporuke