U radu programskog paketa thunderbird uočena su dva sigurnosna propusta. Udaljeni napadač ih može iskoristiti za proizvoljno izvršavanje programskog koda, obilaženje postavljenih sigurnosnih ograničenja te DoS napad.
Sigurnosne ranjivosti su posljedica neodgovarajućeg rukovanja memorijskim lokacijama te cjelobrojnog podljeva.
Posljedica:
Udaljeni napadač ranjivosti može iskoristiti za obilaženje ograničenja, napad uskraćivanjem usluga (eng. Denial of Service) te proizvoljno izvršavanje programskog koda.
Rješenje:
Rješenje problema sigurnosti je korištenje dostupnih programskih nadogradnji.
CentOS Errata and Security Advisory CESA-2011:1343
thunderbird security update for CentOS 4 x86_64:
https://rhn.redhat.com/errata/RHSA-2011-1343.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
x86_64:
updates/x86_64/RPMS/thunderbird-1.5.0.12-44.el4.centos.x86_64.rpm
source:
updates/SRPMS/thunderbird-1.5.0.12-44.el4.centos.src.rpm
You may update your CentOS-4 x86_64 installations by running the command:
yum update thunderbird
Tru
--
Tru Huynh (mirrors, CentOS i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
CentOS Errata and Security Advisory CESA-2011:1343
thunderbird security update for CentOS 4 i386:
https://rhn.redhat.com/errata/RHSA-2011-1343.html
The following updated file has been uploaded and is currently syncing to
the mirrors:
i386:
updates/i386/RPMS/thunderbird-1.5.0.12-44.el4.centos.i386.rpm
source:
updates/SRPMS/thunderbird-1.5.0.12-44.el4.centos.src.rpm
You may update your CentOS-4 i386 installations by running the command:
yum update thunderbird
Tru
--
Tru Huynh (mirrors, CentOS i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B
Posljednje sigurnosne preporuke