Otkriven je sigurnosni propust u radu programskog paketa expat, namijenjenog operacijskom sustavu Fedora 17. Udaljenom napadaču omogućuje izvođenje DoS napada.
Paket:
expat 2.x
Operacijski sustavi:
Fedora 17
Kritičnost:
3.7
Problem:
pogreška u programskoj funkciji
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-0876
Izvorni ID preporuke:
FEDORA-2012-4936
Izvor:
Fedora
Problem:
Propust je posljedica kolizija u određenim "hash" funkcijama.
Posljedica:
Napadač ga može iskoristiti za izvođenje DoS (eng. Denial of Service) napada.
Rješenje:
Korisnicima se preporuča korištenje odgovarajuće nadogradnje.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-4936
2012-03-30 17:55:06
--------------------------------------------------------------------------------
Name : expat
Product : Fedora 17
Version : 2.1.0
Release : 1.fc17
URL : http://www.libexpat.org/
Summary : An XML parser library
Description :
This is expat, the C library for parsing XML, written by James Clark. Expat
is a stream oriented XML parser. This means that you register handlers with
the parser prior to starting the parse. These handlers are called when the
parser discovers the associated structures in the document being parsed. A
start tag is an example of the kind of structures for which you may
register handlers.
--------------------------------------------------------------------------------
Update Information:
This update includes expat 2.1.0, which fixes includes a fix for a security
issue.
A specially-crafted set of keys could trigger hash function collisions, which
degrade dictionary performance by changing hash table operations complexity from
an expected/average O(1) to the worst case O(n). Reporters were able to find
colliding strings efficiently using meet in the middle attack. (CVE-2012-0876)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #806602 - expat-2.1.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=806602
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update expat' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke