Objavljena je nova inačica aplikacije Zabbix, namijenjene operacijskim sustavima Fedora 14 i 15. Spomenuta inačica ispravlja ranjivost koja je udaljenim napadačima omogućavala izvođenje XSS (eng. Cross-site scripting) napada.
Paket:
zabbix 1.x
Operacijski sustavi:
Fedora 14, Fedora 15
Kritičnost:
4.3
Problem:
neodgovarajuća provjera ulaznih podataka
Iskorištavanje:
udaljeno
Posljedica:
umetanje HTML i skriptnog koda
CVE:
CVE-2011-2904
Izvorni ID preporuke:
FEDORA-2011-10601
Izvor:
Fedora
Problem:
Sigurnosni propust posljedica je neodgovarajuće provjere ulaznih podataka predanih argumentu "backurl" u datoteci acknow.php.
Posljedica:
Udaljeni napadač navedeni nedostatak može iskoristiti za pokretanje XSS napada.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-10601
2011-08-10 03:01:23
--------------------------------------------------------------------------------
Name : zabbix
Product : Fedora 14
Version : 1.8.6
Release : 1.fc14
URL : http://www.zabbix.com/
Summary : Open-source monitoring solution for your IT infrastructure
Description :
ZABBIX is software that monitors numerous parameters of a network and
the health and integrity of servers. ZABBIX uses a flexible
notification mechanism that allows users to configure e-mail based
alerts for virtually any event. This allows a fast reaction to server
problems. ZABBIX offers excellent reporting and data visualisation
features based on the stored data. This makes ZABBIX ideal for
capacity planning.
ZABBIX supports both polling and trapping. All ZABBIX reports and
statistics, as well as configuration parameters are accessed through a
web-based front end. A web-based front end ensures that the status of
your network and the health of your servers can be assessed from any
location. Properly configured, ZABBIX can play an important role in
monitoring IT infrastructure. This is equally true for small
organisations with a few servers and for large companies with a
multitude of servers.
--------------------------------------------------------------------------------
Update Information:
- update to 1.8.6
- upstream changelog at http://www.zabbix.com/rn1.8.6.php
--------------------------------------------------------------------------------
ChangeLog:
* Tue Aug 9 2011 Dan HorÄ
Posljednje sigurnosne preporuke