U radu programskog paketa Notmuch, distribuiranog s operacijskim sustavima Fedora 15, 16 i 17, uočena je sigurnosna ranjivost. Udaljeni ju napadač može iskoristiti za otkrivanje osjetljivih informacija.
Paket:
Notmuch 0.x
Operacijski sustavi:
Fedora 15, Fedora 16, Fedora 17
Kritičnost:
4.4
Problem:
neodgovarajuća provjera ulaznih podataka
Iskorištavanje:
udaljeno
Posljedica:
otkrivanje osjetljivih informacija
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-1103
Izvorni ID preporuke:
FEDORA-2012-3315
Izvor:
Fedora
Problem:
Ranjivost je posljedica neodgovarajuće provjere ulaznih podataka u komponenti "notmuch-mua.el".
Posljedica:
Napadaču spomenuta nepravilnost omogućuje pregled/čitanje osjetljivih podataka.
Rješenje:
Korisnicima se preporuča korištenje novih programskih rješenja.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-3315
2012-03-08 03:35:07
--------------------------------------------------------------------------------
Name : notmuch
Product : Fedora 15
Version : 0.5
Release : 5.fc15
URL : http://notmuchmail.org/
Summary : System for indexing, searching, and tagging email
Description :
Fast system for indexing, searching, and tagging email. Even if you
receive 12000 messages per month or have on the order of millions of
messages that you've been saving for decades, Notmuch will be able to
quickly search all of it.
Notmuch is not much of an email program. It doesn't receive messages
(no POP or IMAP support). It doesn't send messages (no mail composer,
no network code at all). And for what it does do (email search) that
work is provided by an external library, Xapian. So if Notmuch
provides no user interface and Xapian does all the heavy lifting, then
what's left here? Not much.
--------------------------------------------------------------------------------
Update Information:
CVE-2011-1103: tag information disclosure flaw
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 7 2012 Karel KlÄ
Posljednje sigurnosne preporuke