U radu programskog paketa wicd, otkriven je sigurnosni propust koji zlonamjernom korisniku omogućuje stjecanje većih privilegija i umetanje proizvoljnog programskog koda.
Paket:
wicd 1.x
Operacijski sustavi:
Fedora 15, Fedora 16
Kritičnost:
4.6
Problem:
neodgovarajuća provjera ulaznih podataka
Iskorištavanje:
udaljeno
Posljedica:
dobivanje većih privilegija, proizvoljno izvršavanje programskog koda
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-2095
Izvorni ID preporuke:
FEDORA-2012-5909
Izvor:
Fedora
Problem:
Uzrok ranjivosti je nedovoljna provjera ulaznih podataka u "D-Bus" sučelju.
Posljedica:
Napadačima omogućuje pokretanje proizvoljnog programskog koda i stjecanje većih privilegija.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-5909
2012-04-14 22:41:56
--------------------------------------------------------------------------------
Name : wicd
Product : Fedora 16
Version : 1.7.0
Release : 13.fc16
URL : http://wicd.sourceforge.net/
Summary : Wireless and wired network connection manager
Description :
Wicd is designed to give the user as much control over behavior of network
connections as possible. Every network, both wired and wireless, has its
own profile with its own configuration options and connection behavior.
Wicd will try to automatically connect only to networks the user specifies
it should try, with a preference first to a wired network, then to wireless.
This package provides the architecture-dependent components of wicd.
--------------------------------------------------------------------------------
Update Information:
This update fixes CVE-2012-2095. The wicd daemon suffered from a local
privilege escalation flaw due to incomplete input sanitization. A local
attacker sould use this to inject arbitrary code through the D-Bus interface.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Apr 13 2012 David Cantrell <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.7.0-13
- Fix CVE-2012-2095 (#811763)
* Mon Mar 26 2012 David Cantrell <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.7.0-12
- Ensure wpath.etc is set to /etc/wicd, not /etc/dhcp (#754412)
- Initialize child_pid to None in wicd-daemon.py (#798692)
- Make wicd-gtk subpackage require notify-python (#748258)
- Work around no-op problem in DaemonClosing calls (#740317)
- dhclient.conf.template is now in /etc/wicd, correct %files (#754412)
* Wed Mar 21 2012 David Cantrell <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.7.0-11
- Fix usage of is_mouse_event() in wicd-curses (#800617)
- Make wicd-common require pygobject2 (#799537)
* Fri Jan 27 2012 David Cantrell <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.7.0-10
- Fix CVS-2012-0813 (#785147)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #811762 - CVE-2012-2095 wicd: broken filtering leads to arbitrary
code execution
https://bugzilla.redhat.com/show_bug.cgi?id=811762
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update wicd' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-5923
2012-04-14 22:42:36
--------------------------------------------------------------------------------
Name : wicd
Product : Fedora 15
Version : 1.7.0
Release : 12.fc15
URL : http://wicd.sourceforge.net/
Summary : Wireless and wired network connection manager
Description :
Wicd is designed to give the user as much control over behavior of network
connections as possible. Every network, both wired and wireless, has its
own profile with its own configuration options and connection behavior.
Wicd will try to automatically connect only to networks the user specifies
it should try, with a preference first to a wired network, then to wireless.
This package provides the architecture-dependent components of wicd.
--------------------------------------------------------------------------------
Update Information:
This update fixes CVE-2012-2095. The wicd daemon suffered from a local
privilege escalation flaw due to incomplete input sanitization. A local
attacker sould use this to inject arbitrary code through the D-Bus interface.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Apr 13 2012 David Cantrell <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.7.0-12
- Fix CVE-2012-2095 (#811763)
* Fri Jan 27 2012 David Cantrell <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.7.0-11
- Fix CVE-2012-0813 (#785147)
* Fri Aug 19 2011 David Cantrell <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.7.0-10
- Initialize appGui._wired_showing in __init__ (#723553)
- Make sure check and message in wicd-cli are a lambda (#712435)
* Thu Aug 11 2011 David Cantrell <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.7.0-9
- Correct systemd unit file for wicd, add D-Bus service file (#699116)
- Move docs to the wicd-common subpackage
- Correct /etc/dbus-1/system.d/wicd.conf (#699116)
* Mon May 9 2011 Bill Nottingham <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.7.0-8
- fix systemd scriptlets for upgrade
* Mon Feb 7 2011 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.>
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #811762 - CVE-2012-2095 wicd: broken filtering leads to arbitrary
code execution
https://bugzilla.redhat.com/show_bug.cgi?id=811762
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update wicd' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke