U radu programskog paketa globus-gridftp-server uočen je propust kojeg su zlonamjerni napadači mogli iskoristiti za zaobilaženje postavljenih ograničenja i otkrivanje osjetljivih informacija.
Paket: | globus-gridftp-server 6.x |
Operacijski sustavi: | Fedora 15, Fedora 16, Fedora 17 |
Problem: | pogreška u programskoj funkciji |
Iskorištavanje: | lokalno/udaljeno |
Posljedica: | otkrivanje osjetljivih informacija, zaobilaženje postavljenih ograničenja |
Rješenje: | programska zakrpa proizvođača |
Izvorni ID preporuke: | FEDORA-2012-8461 |
Izvor: | Fedora |
Problem: | |
Ranjivosti su vezane uz funkciju "getpwnam_r()" i neodgovarajuću obradu vrijednosti koje vraća funkcija "getpw*". |
|
Posljedica: | |
Potencijalni napadači mogu iskoristiti propuste za zaobilaženje postavljenih ograničenja i čitanje povjerljivih podataka. |
|
Rješenje: | |
Svim korisnicima se savjetuje korištenje službenih programskih rješenja proizvođača. |
Izvorni tekst preporuke
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-8461
2012-05-27 01:33:28
--------------------------------------------------------------------------------
Name : globus-gridftp-server
Product : Fedora 16
Version : 6.10
Release : 2.fc16
URL : http://www.globus.org/
Summary : Globus Toolkit - Globus GridFTP Server
Description :
The Globus Toolkit is an open source software toolkit used for building Grid
systems and applications. It is being developed by the Globus Alliance and
many others all over the world. A growing number of projects and companies are
using the Globus Toolkit to unlock the potential of grids for their cause.
The globus-gridftp-server package contains:
Globus GridFTP Server
--------------------------------------------------------------------------------
Update Information:
Fix for http://jira.globus.org/browse/GT-195
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 25 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.10-2
- Backport security fix for JIRA ticket GT-195
* Fri Apr 27 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.10-1
- Update to Globus Toolkit 5.2.1
- Drop patches globus-gridftp-server-deps.patch,
globus-gridftp-server-funcgrp.patch, globus-gridftp-server-pathmax.patch
and globus-gridftp-server-compat.patch (fixed upstream)
- Drop globus-gridftp-server man page from packaging since it is now included
in upstream sources
- Add additional contributed man pages
* Sat Mar 10 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.5-4
- Restore enum and struct member order for improved backward compatibility
* Mon Mar 5 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.5-3
- The last update broke backward compatibility and should have bumped
the soname - so bump it now
- Add patch from upstream to reduce the chance of backward incompatible
changes in the future
* Wed Jan 18 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.5-2
- Portability fixes
- Fix broken links in README file
* Wed Dec 14 2011 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.5-1
- Update to Globus Toolkit 5.2.0
- Drop patches globus-gridftp-server-etc.patch,
globus-gridftp-server-pathmax.patch and globus-gridftp-server-usr.patch
(fixed upstream)
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update globus-gridftp-server' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-8445
2012-05-26 22:05:49
--------------------------------------------------------------------------------
Name : globus-gridftp-server
Product : Fedora 17
Version : 6.10
Release : 2.fc17
URL : http://www.globus.org/
Summary : Globus Toolkit - Globus GridFTP Server
Description :
The Globus Toolkit is an open source software toolkit used for building Grid
systems and applications. It is being developed by the Globus Alliance and
many others all over the world. A growing number of projects and companies are
using the Globus Toolkit to unlock the potential of grids for their cause.
The globus-gridftp-server package contains:
Globus GridFTP Server
--------------------------------------------------------------------------------
Update Information:
Fix for http://jira.globus.org/browse/GT-195
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 25 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.10-2
- Backport security fix for JIRA ticket GT-195
* Fri Apr 27 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.10-1
- Update to Globus Toolkit 5.2.1
- Drop patches globus-gridftp-server-deps.patch,
globus-gridftp-server-funcgrp.patch, globus-gridftp-server-pathmax.patch
and globus-gridftp-server-compat.patch (fixed upstream)
- Drop globus-gridftp-server man page from packaging since it is now included
in upstream sources
- Add additional contributed man pages
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update globus-gridftp-server' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-8488
2012-05-27 06:56:40
--------------------------------------------------------------------------------
Name : globus-gridftp-server
Product : Fedora 15
Version : 6.10
Release : 2.fc15
URL : http://www.globus.org/
Summary : Globus Toolkit - Globus GridFTP Server
Description :
The Globus Toolkit is an open source software toolkit used for building Grid
systems and applications. It is being developed by the Globus Alliance and
many others all over the world. A growing number of projects and companies are
using the Globus Toolkit to unlock the potential of grids for their cause.
The globus-gridftp-server package contains:
Globus GridFTP Server
--------------------------------------------------------------------------------
Update Information:
Fix for http://jira.globus.org/browse/GT-195
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 25 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.10-2
- Backport security fix for JIRA ticket GT-195
* Fri Apr 27 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.10-1
- Update to Globus Toolkit 5.2.1
- Drop patches globus-gridftp-server-deps.patch,
globus-gridftp-server-funcgrp.patch, globus-gridftp-server-pathmax.patch
and globus-gridftp-server-compat.patch (fixed upstream)
- Drop globus-gridftp-server man page from packaging since it is now included
in upstream sources
- Add additional contributed man pages
* Sat Mar 10 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.5-4
- Restore enum and struct member order for improved backward compatibility
* Mon Mar 5 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.5-3
- The last update broke backward compatibility and should have bumped
the soname - so bump it now
- Add patch from upstream to reduce the chance of backward incompatible
changes in the future
* Wed Jan 18 2012 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.5-2
- Portability fixes
- Fix broken links in README file
* Wed Dec 14 2011 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 6.5-1
- Update to Globus Toolkit 5.2.0
- Drop patches globus-gridftp-server-etc.patch,
globus-gridftp-server-pathmax.patch and globus-gridftp-server-usr.patch
(fixed upstream)
* Sun Oct 2 2011 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.33-2
- Update contributed manpage
* Sun Jun 5 2011 Mattias Ellert <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.33-1
- Update to Globus Toolkit 5.0.4
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update globus-gridftp-server' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke