U radu programskog paketa cherokee uočena su dva sigurnosna propusta. Lokalni napadač propuste može iskoristiti za proizvoljno pokretanje skriptnog i HTML koda, te otkrivanje osjetljivih informacija.
Paket:
cherokee 1.x
Operacijski sustavi:
Fedora 16
Kritičnost:
4.6
Problem:
CSRF, nepravilno rukovanje lozinkama, XSS
Iskorištavanje:
lokalno
Posljedica:
otkrivanje osjetljivih informacija, umetanje HTML i skriptnog koda
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-2190, CVE-2011-2191
Izvorni ID preporuke:
FEDORA-2011-12657
Izvor:
Fedora
Problem:
Sigurnosne ranjivosti se javljaju zbog nepravilnog rukovanja lozinkama te zbog XSS (eng. Cross-Site Scripting) i CSRF (eng. Cross-Site Request Forgery) ranjivosti.
Posljedica:
Lokalni napadač nedostatke može iskoristiti za otkrivanje osjetljivih podataka (lozinke, korisnička imena) te proizvoljno pokretanje HTML i skriptnog koda.
Rješenje:
Rješenje problema sigurnosti je korištenje dostupnih programskih nadogradnji.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-12657
2011-09-13 22:02:26
--------------------------------------------------------------------------------
Name : cherokee
Product : Fedora 16
Version : 1.2.99
Release : 1.fc16
URL : http://www.cherokee-project.com/
Summary : Flexible and Fast Webserver
Description :
Cherokee is a very fast, flexible and easy to configure Web Server. It supports
the widespread technologies nowadays: FastCGI, SCGI, PHP, CGI, TLS and SSL
encrypted connections, Virtual hosts, Authentication, on the fly encoding,
Apache compatible log files, and much more.
--------------------------------------------------------------------------------
Update Information:
Latest 1.2.x upstream release and bugzilla resolving
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #713306 - CVE-2011-2190 CVE-2011-2191 cherokee: multiple
vulnerabilities [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=713306
[ 2 ] Bug #710473 - cherokee: A weakness in Cherokeeâ??s administrative
interface random administrator password generation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=710473
[ 3 ] Bug #728741 - Cherokee package is very old
https://bugzilla.redhat.com/show_bug.cgi?id=728741
[ 4 ] Bug #720515 - Provide native systemd unit file
https://bugzilla.redhat.com/show_bug.cgi?id=720515
[ 5 ] Bug #701196 - Cherokee not automatically started when installed
https://bugzilla.redhat.com/show_bug.cgi?id=701196
[ 6 ] Bug #712555 - Cherokee dies at boot time
https://bugzilla.redhat.com/show_bug.cgi?id=712555
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update cherokee' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke