U radu programskog paketa roundcubemail uočena su tri nova sigurnosna propusta. Potencijalni ih napadač može iskoristiti za otkrivanje osjetljivih podataka te umetanje proizvoljnog HTML i skriptnog koda.
Paket:
roundcubemail 0.x
Operacijski sustavi:
Fedora 15, Fedora 16
Kritičnost:
5.5
Problem:
CSRF, pogreška u programskoj komponenti, XSS
Iskorištavanje:
udaljeno
Posljedica:
otkrivanje osjetljivih informacija, umetanje HTML i skriptnog koda
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-1491, CVE-2011-1492, CVE-2012-1253
Izvorni ID preporuke:
FEDORA-2012-9337
Izvor:
Fedora
Problem:
Sigurnosni nedostaci se javljaju zbog CSRF (eng. Cross-site request forgery) ranjivosti prilikom zahtjeva za autentikacijom, XSS (eng. Cross-site scripting) ranjivosti prilikom otvaranja dodataka sa slikama te pogreške u implementaciji komponente "steps/utils/modcss.inc".
Posljedica:
Udaljeni napadač spomenute ranjivosti može iskoristiti za umetanje HTML i skriptnog koda, te otkrivanje povjerljivih informacija.
Rješenje:
Rješenje problema sigurnosti je korištenje najnovije inačice programskog paketa.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-9337
2012-06-13 20:59:00
--------------------------------------------------------------------------------
Name : roundcubemail
Product : Fedora 16
Version : 0.7.2
Release : 2.fc16
URL : http://www.roundcube.net
Summary : Round Cube Webmail is a browser-based multilingual IMAP client
Description :
RoundCube Webmail is a browser-based multilingual IMAP client
with an application-like user interface. It provides full
functionality you expect from an e-mail client, including MIME
support, address book, folder manipulation, message searching
and spell checking. RoundCube Webmail is written in PHP and
requires the MySQL database or the PostgreSQL database. The user
interface is fully skinnable using XHTML and CSS 2.
--------------------------------------------------------------------------------
Update Information:
Resolves:
CVE-2011-1491
CVE-2011-1492
CVE-2012-1253
--------------------------------------------------------------------------------
ChangeLog:
* Mon Mar 12 2012 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.2-2
- Rediffed strict patch.
* Mon Mar 12 2012 Adam Williamson <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.2-1
- new upstream release 0.7.2
* Thu Feb 16 2012 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.1-2
- Fix logrotate, BZ 789552.
- Modify error logging for strict, BZ 789576.
* Wed Feb 1 2012 Adam Williamson <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.1-1
- new upstream release
* Sat Jan 14 2012 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> -
0.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Wed Dec 14 2011 Adam Williamson <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7-1
- new upstream release
- drop all patches except confpath.patch:
+ html2text.patch and all CVE fixes were merged upstream
+ pg-mdb2.patch no longer necessary as all currently supported
Fedora releases have a php-pear-MDB2-Driver-pgsql package new
enough to work with this option
* Fri Oct 7 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> = 0.6-1
- New upstream.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #828558 - CVE-2012-1253 roundcubemail: XSS flaw fixed in 0.7
[fedora-16]
https://bugzilla.redhat.com/show_bug.cgi?id=828558
[ 2 ] Bug #772351 - Upgrade to 0.7
https://bugzilla.redhat.com/show_bug.cgi?id=772351
[ 3 ] Bug #828557 - CVE-2012-1253 roundcubemail: XSS flaw fixed in 0.7
[epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=828557
[ 4 ] Bug #690458 - CVE-2011-1491 CVE-2011-1492 roundcubemail: v0.5.1 two
security fixes [epel-6]
https://bugzilla.redhat.com/show_bug.cgi?id=690458
[ 5 ] Bug #816914 - Where is the maintainer?
https://bugzilla.redhat.com/show_bug.cgi?id=816914
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update roundcubemail' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-9329
2012-06-13 20:58:35
--------------------------------------------------------------------------------
Name : roundcubemail
Product : Fedora 15
Version : 0.7.2
Release : 2.fc15
URL : http://www.roundcube.net
Summary : Round Cube Webmail is a browser-based multilingual IMAP client
Description :
RoundCube Webmail is a browser-based multilingual IMAP client
with an application-like user interface. It provides full
functionality you expect from an e-mail client, including MIME
support, address book, folder manipulation, message searching
and spell checking. RoundCube Webmail is written in PHP and
requires the MySQL database or the PostgreSQL database. The user
interface is fully skinnable using XHTML and CSS 2.
--------------------------------------------------------------------------------
Update Information:
Resolves:
CVE-2011-1491
CVE-2011-1492
CVE-2012-1253
--------------------------------------------------------------------------------
ChangeLog:
* Mon Mar 12 2012 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.2-2
- Rediffed strict patch.
* Mon Mar 12 2012 Adam Williamson <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.2-1
- new upstream release 0.7.2
* Thu Feb 16 2012 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.1-2
- Fix logrotate, BZ 789552.
- Modify error logging for strict, BZ 789576.
* Wed Feb 1 2012 Adam Williamson <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.1-1
- new upstream release
* Sat Jan 14 2012 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> -
0.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Wed Dec 14 2011 Adam Williamson <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7-1
- new upstream release
- drop all patches except confpath.patch:
+ html2text.patch and all CVE fixes were merged upstream
+ pg-mdb2.patch no longer necessary as all currently supported
Fedora releases have a php-pear-MDB2-Driver-pgsql package new
enough to work with this option
* Fri Oct 7 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> = 0.6-1
- New upstream.
* Tue Sep 6 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> = 0.5.4-1
- New upstream, fixes multiple security issues.
* Tue Jul 5 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> = 0.5.3-1
- New upstream.
* Tue May 17 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> = 0.5.2-1
- New upstream.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #828558 - CVE-2012-1253 roundcubemail: XSS flaw fixed in 0.7
[fedora-16]
https://bugzilla.redhat.com/show_bug.cgi?id=828558
[ 2 ] Bug #772351 - Upgrade to 0.7
https://bugzilla.redhat.com/show_bug.cgi?id=772351
[ 3 ] Bug #828557 - CVE-2012-1253 roundcubemail: XSS flaw fixed in 0.7
[epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=828557
[ 4 ] Bug #690458 - CVE-2011-1491 CVE-2011-1492 roundcubemail: v0.5.1 two
security fixes [epel-6]
https://bugzilla.redhat.com/show_bug.cgi?id=690458
[ 5 ] Bug #816914 - Where is the maintainer?
https://bugzilla.redhat.com/show_bug.cgi?id=816914
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update roundcubemail' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke