U programskom paketu WebCalendar, inačicama namijenjenih za operacijske sustave Fedora 16 i 17, otkriven je sigurnosni propust koji udaljeni napadač može iskoristiti za pokretanje zlonamjernih skripti.
Paket:
WebCalendar 1.x
Operacijski sustavi:
Fedora 16, Fedora 17
Problem:
neodgovarajuća provjera ulaznih podataka
Iskorištavanje:
udaljeno
Posljedica:
umetanje HTML i skriptnog koda
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-0846
Izvorni ID preporuke:
FEDORA-2012-1934
Izvor:
Fedora
Problem:
Problem nastaje zbog neodgovarajućeg filtriranja određenih varijabli.
Posljedica:
Propust je moguće iskoristiti za XSS napad.
Rješenje:
Svim se korisnicima savjetuje primjena izdane nadogradnje.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-1934
2012-02-17 23:22:50
--------------------------------------------------------------------------------
Name : WebCalendar
Product : Fedora 16
Version : 1.2.4
Release : 3.fc16
URL : http://www.k5n.us/webcalendar.php
Summary : Single/multi-user web-based calendar application
Description :
WebCalendar is a PHP-based calendar application that can be configured as a
single-user calendar, a multi-user calendar for groups of users, or as an
event calendar viewable by visitors. MySQL, PostgreSQL, Oracle, DB2,
Interbase, MS SQL Server, or ODBC is required.
WebCalendar can be setup in a variety of ways, such as...
* A schedule management system for a single person
* A schedule management system for a group of people, allowing one or
more assistants to manage the calendar of another user
* An events schedule that anyone can view, allowing visitors to submit
new events
* A calendar server that can be viewed with iCal-compliant calendar
applications like Mozilla Sunbird, Apple iCal or GNOME Evolution or
RSS-enabled applications like Firefox, Thunderbird, RSSOwl, or
FeedDemon, or BlogExpress.
--------------------------------------------------------------------------------
Update Information:
Fixes CVE-2012-846 and some other XSS vulnerabilities
--------------------------------------------------------------------------------
ChangeLog:
* Fri Feb 17 2012 Patrick Monnerat <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.2.4-3
- Patch "cve2012_0846" fixes CVE-2012-0846 and some other XSS vulnerabilities.
http://sourceforge.net/tracker/?func=detail&aid=3472745&group_id=3870&atid=103870
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #794499 - CVE-2012-0846 WebCalendar: location XSS flaw
https://bugzilla.redhat.com/show_bug.cgi?id=794499
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update WebCalendar' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-1898
2012-02-17 17:58:54
--------------------------------------------------------------------------------
Name : WebCalendar
Product : Fedora 17
Version : 1.2.4
Release : 3.fc17
URL : http://www.k5n.us/webcalendar.php
Summary : Single/multi-user web-based calendar application
Description :
WebCalendar is a PHP-based calendar application that can be configured as a
single-user calendar, a multi-user calendar for groups of users, or as an
event calendar viewable by visitors. MySQL, PostgreSQL, Oracle, DB2,
Interbase, MS SQL Server, or ODBC is required.
WebCalendar can be setup in a variety of ways, such as...
* A schedule management system for a single person
* A schedule management system for a group of people, allowing one or
more assistants to manage the calendar of another user
* An events schedule that anyone can view, allowing visitors to submit
new events
* A calendar server that can be viewed with iCal-compliant calendar
applications like Mozilla Sunbird, Apple iCal or GNOME Evolution or
RSS-enabled applications like Firefox, Thunderbird, RSSOwl, or
FeedDemon, or BlogExpress.
--------------------------------------------------------------------------------
Update Information:
Fixes CVE-2012-846 and some other XSS vulnerabilities
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #794499 - CVE-2012-0846 WebCalendar: location XSS flaw
https://bugzilla.redhat.com/show_bug.cgi?id=794499
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update WebCalendar' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke