U radu programskog paketa perl-YAML-LibYAML uočena je sigurnosna nepravilnost. Zloćudni napadači mogu iskoristiti ranjivost za DoS (eng. Denial of Service) napad.
Paket:
Operacijski sustavi:
Fedora 15, Fedora 16
Kritičnost:
4.3
Problem:
neodgovarajuće rukovanje datotekama
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-1152
Izvorni ID preporuke:
FEDORA-2012-5035
Izvor:
Fedora
Problem:
Problem se javlja jer ranjivi programski paket na neodgovarajući način obrađuje string datoteke.
Posljedica:
Udaljeni napadač može iskoristiti nedostatak za napad uskraćivanja usluga (DoS napad).
Rješenje:
Savjetuje se instalacija programskih rješenja koja otklanjaju opisane greške.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-5035
2012-03-31 02:14:54
--------------------------------------------------------------------------------
Name : perl-YAML-LibYAML
Product : Fedora 16
Version : 0.38
Release : 2.fc16
URL : http://search.cpan.org/dist/YAML-LibYAML/
Summary : Perl YAML Serialization using XS and libyaml
Description :
Kirill Siminov's "libyaml" is arguably the best YAML implementation. The C
library is written precisely to the YAML 1.1 specification. It was originally
bound to Python and was later bound to Ruby.
--------------------------------------------------------------------------------
Update Information:
This update fixes various format string vulnerabilities (CVE-2012-1152, CPAN
RT#46507).
The Fedora 15 and Fedora 16 builds also include some bug-fixes from upstream:
* Fix for broken deparse test
* Fix LoadFile on empty file failure
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 29 2012 Paul Howarth <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.38-2
- Fix various format string vulnerabilities (CVE-2012-1152, CPAN RT#46507)
- De-duplicate buildreqs, with Module>Install>Tests priority
- Install to vendor directories
- Don't need to remove empty directories from buildroot
- Don't use macros for commands
- Make %files list more explicit
- Tidy %description
* Fri Jan 13 2012 Marcela MaĹÄ
Posljednje sigurnosne preporuke