U radu programskog paketa gnash uočene su sigurnosne ranjivosti koje zlonamjerni korisnik može iskoristiti za izvođenje DoS napada, izvršavanje proizvoljnog programskog koda, otkrivanje osjetljivih informacija ili prepisivanje proizvoljnih datoteka.
gnash 0.x
Operacijski sustavi:
Debian Linux 6.0 (squeeze), Debian Linux sid (unstable)
cjelobrojno prepisivanje, pogreška u programskoj komponenti
Propusti su posljedica cjelobrojnog prepisivanja, nepravilnog rukovanja HTTP kolačićima (eng. cookie) te privremenim datotekama.
Zlonamjerni korisnik može iskoristiti navedene propuste za rušenje programa, izvršavanje proizvoljnog programskog koda, čitanje određenih podataka ili prepisivanje proizvoljnih datoteka.
Svim korisnicima se savjetuje korištenje nadogradnje koja otklanja opisane propuste.
Hash: SHA1
- - -------------------------------------------------------------------------
Debian Security Advisory DSA-2435-1 Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://www.debian.org/security/ Gabriele Giacone
March 19, 2012 http://www.debian.org/security/faq
- - -------------------------------------------------------------------------
Package : gnash
Vulnerability : several
Problem type : local / local (remote)
Debian-specific: no
CVE ID : CVE-2010-4337 CVE-2011-4328 CVE-2012-1175
Debian Bug : 605419 649384 664023
Several vulnerabilities have been identified in Gnash, the GNU Flash
Tielei Wang from Georgia Tech Information Security Center discovered a
vulnerability in GNU Gnash which is caused due to an integer overflow
error and can be exploited to cause a heap-based buffer overflow by
tricking a user into opening a specially crafted SWF file.
Alexander Kurtz discovered an unsafe management of HTTP cookies. Cookie
files are stored under /tmp and have predictable names, vulnerability
that allows a local attacker to overwrite arbitrary files the users has
write permissions for, and are also world-readable which may cause
information leak.
Jakub Wilk discovered an unsafe management of temporary files during the
build process. Files are stored under /tmp and have predictable names,
vulnerability that allows a local attacker to overwrite arbitrary files
the users has write permissions for.
For the stable distribution (squeeze), this problem has been fixed in
version 0.8.8-5+squeeze1.
For the unstable distribution (sid), this problem has been fixed in
version 0.8.10-5.
We recommend that you upgrade your gnash packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Version: GnuPG v1.4.11 (GNU/Linux)
To UNSUBSCRIBE, email to Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
with a subject of "unsubscribe". Trouble? Contact Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Archive: http://lists.debian.org/Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke