U radu programskog paketa xkeyboard-config uočen je nedostatak. Iskorištavanje navedenog nedostatka može dovesti do uskraćivanja usluga pokrenutih programa.
Paket:
xkeyboard-config 2.x
Operacijski sustavi:
Fedora 16
Kritičnost:
1.9
Problem:
neodgovarajuće rukovanje datotekama
Iskorištavanje:
lokalno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-0064
Izvorni ID preporuke:
FEDORA-2012-0712
Izvor:
Fedora
Problem:
Do ranjivosti dolazi jer je moguće izazvati rušenje aplikacije ukoliko korisnik pritisne određenu kombinaciju tipki na tastaturi.
Posljedica:
Uočeni propust može dovesti do uskraćivanja usluga pokrenutih programa.
Rješenje:
Korisnicima se savjetuje primjena nove inačice programskog paketa.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-0712
2012-01-19 21:21:19
--------------------------------------------------------------------------------
Name : xkeyboard-config
Product : Fedora 16
Version : 2.3
Release : 3.fc16
URL : http://www.freedesktop.org/wiki/Software/XKeyboardConfig
Summary : X Keyboard Extension configuration data
Description :
This package contains configuration data used by the X Keyboard Extension
(XKB), which allows selection of keyboard layouts when using a graphical
interface.
--------------------------------------------------------------------------------
Update Information:
The previous version of xkeyboard-config included the key combinations to clear
and/or kill grabs in the default keymap. This enabled users to get around screen
locks that use grabs to prevent input to other applications (e.g.
gnome-screensaver). This update moves the definition of the key combinations to
a XKB option that must be explicitly enabled by the user.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jan 19 2012 Peter Hutterer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 2.3-3
- Move Ungrab and ClearGrab from the default layout to option
grab:break_actions (#783044)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #783039 - CVE-2012-0064 xkeyboard-config: screen-saver unlock via
xkb debug key actions
https://bugzilla.redhat.com/show_bug.cgi?id=783039
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update xkeyboard-config' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke