Objavljena je nadogradnja za programski paket boost kojom su ispravljene sigurnosne ranjivosti. Napadači su ih mogli iskoristiti za napad uskraćivanjem usluga (DoS).
Paket:
boost 1.x
Operacijski sustavi:
Fedora 17
Problem:
pogreška u programskoj komponenti
Iskorištavanje:
lokalno/udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
Izvorni ID preporuke:
FEDORA-2012-9818
Izvor:
Fedora
Problem:
Uočena su greške u programskim komponentama "Boost.Pool" i "boost_locale".
Posljedica:
Zlonamjeni korisnici mogu iskoristiti nedostatke za DoS napad.
Rješenje:
Svim korisnicima se preporučuje nadogradnja sustava.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-9818
2012-06-22 18:23:49
--------------------------------------------------------------------------------
Name : boost
Product : Fedora 17
Version : 1.48.0
Release : 13.fc17
URL : http://www.boost.org
Summary : The free peer-reviewed portable C++ source libraries
Description :
Boost provides free peer-reviewed portable C++ source libraries. The
emphasis is on libraries which work well with the C++ Standard
Library, in the hopes of establishing "existing practice" for
extensions and providing reference implementations so that the Boost
libraries are suitable for eventual standardization. (Some of the
libraries have already been proposed for inclusion in the C++
Standards Committee's upcoming C++ Standard Library Technical Report.)
--------------------------------------------------------------------------------
Update Information:
- This update fixes a bug in Boost.Pool, which could under certain circumstances
overflow allocated chunk size. This could have security implications for
applications that use Boost pool without sanitizing pool parameters.
- Boost.Locale library now contains backend code, which was left out before by
mistake.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jun 21 2012 Petr Machata <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.48.0-13
- Build Boost.Locale backends
- Resolves: #832265
* Wed Jun 6 2012 Petr Machata <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.48.0-12
- In Boost.Pool, be careful not to overflow allocated chunk size.
- Resolves: #828857
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #832265 - Fails to build when linking with libboost_locale
https://bugzilla.redhat.com/show_bug.cgi?id=832265
[ 2 ] Bug #828857 - boost: ordered_malloc() overflow [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=828857
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update boost' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke