U radu programskog paketa libpng uočena je sigurnosna ranjivost koja udaljenom napadaču omogućuje izvođenje DoS napada putem posebno oblikovane PNG datoteke.
Paket:
libpng 1.x
Operacijski sustavi:
CentOS
Kritičnost:
3.7
Problem:
pogreška u programskoj funkciji
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-2692
Izvorni ID preporuke:
CESA-2011:1103
Izvor:
CentOS
Problem:
Ranjivost je uzrokovana pogreškom u funkciji "png_handle_sCAL" u datoteci "pngrutil.c".
Posljedica:
Napadač ju može iskoristiti za izvođenje DoS (eng. Denial of Service) napada.
Rješenje:
Korisnicima se savjetuje instalacija inačica u kojima je spomenuta ranjivost otklonjena.
CentOS Errata and Security Advisory CESA-2011:1103
libpng security update for CentOS 4 i386:
https://rhn.redhat.com/errata/RHSA-2011-1103.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
i386:
updates/i386/RPMS/libpng10-1.0.16-9.el4.i386.rpm
updates/i386/RPMS/libpng10-devel-1.0.16-9.el4.i386.rpm
updates/i386/RPMS/libpng-1.2.7-8.el4.i386.rpm
updates/i386/RPMS/libpng-devel-1.2.7-8.el4.i386.rpm
source:
updates/SRPMS/libpng10-1.0.16-9.el4.src.rpm
updates/SRPMS/libpng-1.2.7-8.el4.src.rpm
You may update your CentOS-4 i386 installations by running the command:
yum update libpng
Tru
--
Tru Huynh (mirrors, CentOS i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
CentOS Errata and Security Advisory CESA-2011:1103
libpng security update for CentOS 4 x86_64:
https://rhn.redhat.com/errata/RHSA-2011-1103.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
x86_64:
updates/x86_64/RPMS/libpng10-1.0.16-9.el4.i386.rpm
updates/x86_64/RPMS/libpng10-1.0.16-9.el4.x86_64.rpm
updates/x86_64/RPMS/libpng10-devel-1.0.16-9.el4.x86_64.rpm
updates/x86_64/RPMS/libpng-1.2.7-8.el4.i386.rpm
updates/x86_64/RPMS/libpng-1.2.7-8.el4.x86_64.rpm
updates/x86_64/RPMS/libpng-devel-1.2.7-8.el4.x86_64.rpm
source:
updates/SRPMS/libpng10-1.0.16-9.el4.src.rpm
updates/SRPMS/libpng-1.2.7-8.el4.src.rpm
You may update your CentOS-4 x86_64 installations by running the command:
yum update libpng
Tru
--
Tru Huynh (mirrors, CentOS i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
Posljednje sigurnosne preporuke