Otkriveni su brojni sigurnosni nedostaci u radu programskih paketa Firefox i XULRunner. Udaljeni ih napadači mogu iskoristiti za izvođenje DoS i XSS napada, pokretanje proizvoljnog programskog koda i otkrivanje osjetljivih informacija.
Paket:
Firefox 10.x, Xulrunner 10.x
Operacijski sustavi:
CentOS
Kritičnost:
8.7
Problem:
pogreška u programskoj funkciji, pogreška u programskoj komponenti, preljev međuspremnika, XSS
Iskorištavanje:
udaljeno
Posljedica:
otkrivanje osjetljivih informacija, proizvoljno izvršavanje programskog koda, umetanje HTML i skriptnog koda, uskraćivanje usluga (DoS)
Nedostaci su uzrokovani nespecificiranom ranjivošću u NVIDIA upravljačkom programu (eng. driver), višestrukim nespecificiranim pogreškama u mehanizmu za pretraživanje te nepravilnostima u pojedinim funkcijama. Za više detalja savjetuje se čitanje izvorne preporuke.
Posljedica:
Napadačima omogućuju pokretanje proizvoljnog programskog koda, DoS i XSS napad, te pregled povjerljivih podataka.
CentOS Errata and Security Advisory 2012:0710 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-0710.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
41b523eae8ce14f0b76d5a5ea087253cceb6f9c4e31d26cd690c1945e32faa4b
firefox-10.0.5-1.el5.centos.i386.rpm
8b071da557a36051dedcd18257ed21ff6f2a02a78b27e3dc0b6029f8b65ca0d3
xulrunner-10.0.5-1.el5_8.i386.rpm
70a324fb17a1babb7d38a80be9ea3ff758de444276061bd0cab42ba7c7fa7a6a
xulrunner-devel-10.0.5-1.el5_8.i386.rpm
x86_64:
41b523eae8ce14f0b76d5a5ea087253cceb6f9c4e31d26cd690c1945e32faa4b
firefox-10.0.5-1.el5.centos.i386.rpm
8bff36d3db4e6d04c7ce68063fb8359fe7356adc7290b3a874446733fa6d34e4
firefox-10.0.5-1.el5.centos.x86_64.rpm
8b071da557a36051dedcd18257ed21ff6f2a02a78b27e3dc0b6029f8b65ca0d3
xulrunner-10.0.5-1.el5_8.i386.rpm
b9bf7b391d268e52e26b60e59ac353f08fc560f8e49c0d03fc1d95d09abad5ce
xulrunner-10.0.5-1.el5_8.x86_64.rpm
70a324fb17a1babb7d38a80be9ea3ff758de444276061bd0cab42ba7c7fa7a6a
xulrunner-devel-10.0.5-1.el5_8.i386.rpm
ba03a12a7bb906145114dc9236044525f56e2596d0ba98859b21a383dd560204
xulrunner-devel-10.0.5-1.el5_8.x86_64.rpm
Source:
0b85b141ce762a9fbdbac2cb0cf0cc49f0e63607c0b5bc6bbea1e7c1ef792f24
firefox-10.0.5-1.el5.centos.src.rpm
4b242781f1594ac3912386c19ca8876a930d3cc8c56522e773cd7b6b0ff5c592
xulrunner-10.0.5-1.el5_8.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2012:0710 Critical
Upstream details at : http://rhn.redhat.com/errata/RHSA-2012-0710.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
3e29f2f7aef70c78ab1deffaa576bf84cecb28cdf62d834a2efb1cb3773b1b1d
firefox-10.0.5-1.el6.centos.i686.rpm
81182bf9369d7cd0056ad18124e4b9c9574b98e546b170dee8382e02a0ede4c0
xulrunner-10.0.5-1.el6.centos.i686.rpm
72f081ad8cfc725c567f29e41d583741a640097a333d73ff6c43b8527e883b80
xulrunner-devel-10.0.5-1.el6.centos.i686.rpm
x86_64:
3e29f2f7aef70c78ab1deffaa576bf84cecb28cdf62d834a2efb1cb3773b1b1d
firefox-10.0.5-1.el6.centos.i686.rpm
519d831d70d1754c1f3c62f82312423373360f9ade2b48225fc7d21072e78750
firefox-10.0.5-1.el6.centos.x86_64.rpm
81182bf9369d7cd0056ad18124e4b9c9574b98e546b170dee8382e02a0ede4c0
xulrunner-10.0.5-1.el6.centos.i686.rpm
673923e33d51525ee91cc652c91e5b46ad7c0550e4a70192d5c43254bc9ffe9d
xulrunner-10.0.5-1.el6.centos.x86_64.rpm
72f081ad8cfc725c567f29e41d583741a640097a333d73ff6c43b8527e883b80
xulrunner-devel-10.0.5-1.el6.centos.i686.rpm
4cb836d47f76c47aba11eb926776351d4b22a4cd1b81a5742a961a0e0f206862
xulrunner-devel-10.0.5-1.el6.centos.x86_64.rpm
Source:
81ed8cbecce4f928da7f41a2fd428a7f278ade1a083a930fb7e914a751dd5903
firefox-10.0.5-1.el6.centos.src.rpm
65bbea6ca6b7ef2b7ac06217afce773bb81fffb2e50061673656a1a672e5bd8e
xulrunner-10.0.5-1.el6.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
Posljednje sigurnosne preporuke