U radu programskog paketa Zabbix uočena je sigurnosna ranjivost koju udaljeni napadač može iskoristiti za otkrivanje informacija iz proizvoljne baze podataka.
Paket:
zabbix 1.x
Operacijski sustavi:
Fedora 16
Kritičnost:
4.4
Problem:
pogreška u programskoj komponenti
Iskorištavanje:
udaljeno
Posljedica:
otkrivanje osjetljivih informacija
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-3265
Izvorni ID preporuke:
FEDORA-2011-12457
Izvor:
Fedora
Problem:
Sigurnosni propust se javlja zbog pogreške u skripti "popup.php".
Posljedica:
Udaljeni napadač ranjivost može iskoristiti za čitanje sadržaja iz proizvoljne baze podataka.
Rješenje:
Rješenje problema sigurnosti je korištenje dostupnih programskih nadogradnji.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-12457
2011-09-10 18:51:25
--------------------------------------------------------------------------------
Name : zabbix
Product : Fedora 16
Version : 1.8.7
Release : 2.fc16
URL : http://www.zabbix.com/
Summary : Open-source monitoring solution for your IT infrastructure
Description :
ZABBIX is software that monitors numerous parameters of a network and
the health and integrity of servers. ZABBIX uses a flexible
notification mechanism that allows users to configure e-mail based
alerts for virtually any event. This allows a fast reaction to server
problems. ZABBIX offers excellent reporting and data visualisation
features based on the stored data. This makes ZABBIX ideal for
capacity planning.
ZABBIX supports both polling and trapping. All ZABBIX reports and
statistics, as well as configuration parameters are accessed through a
web-based front end. A web-based front end ensures that the status of
your network and the health of your servers can be assessed from any
location. Properly configured, ZABBIX can play an important role in
monitoring IT infrastructure. This is equally true for small
organisations with a few servers and for large companies with a
multitude of servers.
--------------------------------------------------------------------------------
Update Information:
- move the zabbix user home directory to the common zabbix package
- fix https://support.zabbix.com/browse/ZBX-4099
- update to 1.8.7
- upstream changelog at http://www.zabbix.com/rn1.8.7.php
- update to 1.8.7
- upstream changelog at http://www.zabbix.com/rn1.8.7.php
- update to 1.8.7
- upstream changelog at http://www.zabbix.com/rn1.8.7.php
- update to 1.8.7
- upstream changelog at http://www.zabbix.com/rn1.8.7.php
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #732130 - CVE-2011-3265 zabbix: remote information disclosure flaw
in popup.php
https://bugzilla.redhat.com/show_bug.cgi?id=732130
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update zabbix' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke