U radu programskog paketa Smokeping uočen je sigurnosni propust kojeg udaljeni napadač može iskoristiti za umetanje proizvoljne web skripte ili HTML koda.
Paket:
smokeping
Operacijski sustavi:
Fedora 15, Fedora 16
Kritičnost:
3.2
Problem:
XSS
Iskorištavanje:
udaljeno
Posljedica:
umetanje HTML i skriptnog koda
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-0790
Izvorni ID preporuke:
FEDORA-2012-0813
Izvor:
Fedora
Problem:
Propust je posljedica XSS (eng. cross-site scripting) ranjivosti u skripti "smokeping_cgi".
Posljedica:
Napadaču omogućuje umetanje proizvoljne web skripte ili HTML koda putem "displaymode" parametra.
Rješenje:
Korisnicima se savjetuje korištenje ispravljenih inačica.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-0813
2012-01-22 22:14:52
--------------------------------------------------------------------------------
Name : smokeping
Product : Fedora 15
Version : 2.4.2
Release : 13.fc15
URL : http://oss.oetiker.ch/smokeping/
Summary : Latency Logging and Graphing System
Description :
SmokePing is a latency logging and graphing system. It consists of a
daemon process which organizes the latency measurements and a CGI
which presents the graphs.
--------------------------------------------------------------------------------
Update Information:
Backport of security issue resolved in smokeping 2.6.7.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jan 22 2012 Terje Rosten <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 2.4.2-13
- Add patch to fix CVE-2012-0790 (#783584)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #783584 - CVE-2012-0790 smokeping: XSS flaw
https://bugzilla.redhat.com/show_bug.cgi?id=783584
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update smokeping' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-0801
2012-01-22 22:12:39
--------------------------------------------------------------------------------
Name : smokeping
Product : Fedora 16
Version : 2.4.2
Release : 16.fc16
URL : http://oss.oetiker.ch/smokeping/
Summary : Latency Logging and Graphing System
Description :
SmokePing is a latency logging and graphing system. It consists of a
daemon process which organizes the latency measurements and a CGI
which presents the graphs.
--------------------------------------------------------------------------------
Update Information:
Backport of security issue resolved in smokeping 2.6.7.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jan 22 2012 Terje Rosten <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 2.4.2-16
- Add patch to fix CVE-2012-0790 (#783584)
* Sat Jan 14 2012 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> -
2.4.2-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #783584 - CVE-2012-0790 smokeping: XSS flaw
https://bugzilla.redhat.com/show_bug.cgi?id=783584
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update smokeping' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke