U radu programskog paketa zabbix uočena su tri sigurnosna propusta. Napadaču omogućuju izvođenje XSS napada, otkrivanje osjetljivih informacija te DoS napad.
Paket:
zabbix 1.x
Operacijski sustavi:
Fedora 16
Kritičnost:
4.4
Problem:
neodgovarajuća provjera ulaznih podataka, pogreška u programskoj komponenti, XSS
Iskorištavanje:
lokalno/udaljeno
Posljedica:
otkrivanje osjetljivih informacija, umetanje HTML i skriptnog koda, uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-2904, CVE-2011-3263, CVE-2011-3264
Izvorni ID preporuke:
FEDORA-2011-10583
Izvor:
Fedora
Problem:
Propusti su posljedica XSS ranjivosti u skropti "acknow.php", pogreške u datoteci "popup.php" te nepravilnosti u komponenti "zabbix_agentd ".
Posljedica:
Napdaču omogućuju izvođenje DoS i XSS napada, te otkrivanje osjetljivih informacija.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-10583
2011-08-09 21:51:02
--------------------------------------------------------------------------------
Name : zabbix
Product : Fedora 16
Version : 1.8.6
Release : 1.fc16
URL : http://www.zabbix.com/
Summary : Open-source monitoring solution for your IT infrastructure
Description :
ZABBIX is software that monitors numerous parameters of a network and
the health and integrity of servers. ZABBIX uses a flexible
notification mechanism that allows users to configure e-mail based
alerts for virtually any event. This allows a fast reaction to server
problems. ZABBIX offers excellent reporting and data visualisation
features based on the stored data. This makes ZABBIX ideal for
capacity planning.
ZABBIX supports both polling and trapping. All ZABBIX reports and
statistics, as well as configuration parameters are accessed through a
web-based front end. A web-based front end ensures that the status of
your network and the health of your servers can be assessed from any
location. Properly configured, ZABBIX can play an important role in
monitoring IT infrastructure. This is equally true for small
organisations with a few servers and for large companies with a
multitude of servers.
--------------------------------------------------------------------------------
Update Information:
- update to 1.8.6
- upstream changelog at http://www.zabbix.com/rn1.8.6.php
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #729162 - CVE-2011-2904 CVE-2011-3263 CVE-2011-3264 zabbix:
multiple flaws in zabbix < 1.8.6
https://bugzilla.redhat.com/show_bug.cgi?id=729162
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update zabbix' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke