Ispravljen je sigurnosni propust otkriven u radu programskog paketa python-mwlib, za operacijski sustav Fedora 16. Udaljeni su ga napadači mogli iskoristiti za izvođenje DoS napada.
python-mwlib 0.x
Operacijski sustavi:
Fedora 16
pogreška u programskoj funkciji
uskraćivanje usluga (DoS)
programska zakrpa proizvođača
Izvorni ID preporuke:
Propust se očituje prilikom analize "#iferror" funkcija.
Napadačima spomenuta ranjivost omogućuje izvođenje DoS (eng. Denial of Service) napada.
Korisnicima se savjetuje korištenje ispravljene inačice.
Fedora Update Notification
2012-03-06 18:58:31
Name : python-mwlib
Product : Fedora 16
Version : 0.13.5
Release : 1.fc16
Summary : MediaWiki parser and utility library
Description :
mwlib provides a library for parsing MediaWiki articles and converting them to
different output formats. mwlib is used by Wikipedia's "Print/export" feature
in order to generate PDF documents from Wikipedia articles.
Update Information:
Update to version 0.13.5, which solves the following issues:
It was reported that mwlib suffered from a flaw that could allow a remote
attacker to perform a denial of service attack on a mwlib installation by
forcing it to parse a specially-crafted #iferror magic function. This issue has
been resolved in version 0.13.5.
syntaxhighlight nodes are supported properly in version 0.13.5.
* Mon Mar 5 2012 Ian Weller <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.13.5-1
- Update to 0.13.5 upstream
* Wed Feb 15 2012 Ian Weller <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.13.4-1
- Update to 0.13.4 upstream
- Update Requires: python-qserve >= 0.2.7
- Add Requires: python-simplejson
- Rebase Patch0 (Clean up dependencies)
- Rebase Patch1 (Unbundle apipkg)
- Rename patches to not be version-specific
- rm rm -rf buildroot
* Mon Feb 13 2012 Ian Weller <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.13.3-4
- Requires: python-setuptools
* Mon Feb 13 2012 Ian Weller <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.13.3-3
- BuildRequires: python-setuptools
* Sat Feb 11 2012 Ian Weller <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.13.3-2
- Move off of py.apipkg into the separate module
- Do a better job of unbundling apipkg completely
- Fix provides filtering
* Fri Jan 13 2012 Ian Weller <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.13.3-1
- Initial package build (again)
[ 1 ] Bug #800066 - mwlib: denial of service when parsing #iferror magic
functions [fedora-all]
[ 2 ] Bug #798615 - python-mwlib-0.13.5 is available
This update can be installed with the "yum" update program. Use
su -c 'yum update python-mwlib' at the command line.
For more information, refer to "Managing Software with yum",
available at
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke