Otkriveni su propusti u radu paketa firefox, a potom ispravljeni novom zakrpom. Propusti omogućuju pokretanje proizvoljnog programskog koda, rušenje aplikacije, izvođenje XSS i phishing napada, obilaženje postavljenih ograničenja i stjecanje osjetljivih informacija.
Paket:
Firefox 11.x
Operacijski sustavi:
Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6
Ranjivosti su vezane uz višestruku memorijsku ranjivost paketa firefox, nepravilnosti adresne trake, nepravilnog poziva "history.forward" i "history.back" funkcija, pogrešaka u implementaciji Content Security Policy (CSP) i JavaScript sandbox funkcionalnosti, i dr.
Posljedica:
Zlonamjerni, udaljeni korisnici bi mogli iskoristiti propuste za izvođenje DoS, XSS i phishing napada, te pokretanje proizvoljnog programskog koda, pregled/izmjenu podataka, itd.
Rješenje:
Svim se korisnicima savjetuje primjena odgovarajućih zakrpa.
CentOS Errata and Security Advisory 2012:1088 Critical
Upstream details at : http://rhn.redhat.com/errata/RHSA-2012-1088.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
3bef48ed67e96b969455d79a66c17befcf0ba1d69443db3a9873ca9b71c2d254
firefox-10.0.6-1.el6.centos.i686.rpm
2b5ce563c3acb1f9ed4bae1676c89e008e42a9e78d3eaec3bacaf61cacea787d
xulrunner-10.0.6-1.el6.centos.i686.rpm
ba4150dd354c0ce134421a508b21649b601b06cddfd617b9d782ea2f20b9d299
xulrunner-devel-10.0.6-1.el6.centos.i686.rpm
x86_64:
3bef48ed67e96b969455d79a66c17befcf0ba1d69443db3a9873ca9b71c2d254
firefox-10.0.6-1.el6.centos.i686.rpm
99475547b674bc1cb10fef2918ad1e4dbd1ac7abb59b4eb3f18ed30da29a48d3
firefox-10.0.6-1.el6.centos.x86_64.rpm
2b5ce563c3acb1f9ed4bae1676c89e008e42a9e78d3eaec3bacaf61cacea787d
xulrunner-10.0.6-1.el6.centos.i686.rpm
99699f20ef692baeca713aff1366f4b5853745b47930bedf16f95ab67e17ba83
xulrunner-10.0.6-1.el6.centos.x86_64.rpm
ba4150dd354c0ce134421a508b21649b601b06cddfd617b9d782ea2f20b9d299
xulrunner-devel-10.0.6-1.el6.centos.i686.rpm
ad320ba66b766753682de66ce82330ca956286115c6485b5fee852abc594cce3
xulrunner-devel-10.0.6-1.el6.centos.x86_64.rpm
Source:
464bb82aec3da3651499fba9b6e0367b662359fee4537492ac72aaa96342cf6a
firefox-10.0.6-1.el6.centos.src.rpm
a09316b3d88deebe359d56d7776263dcbbe694cfffc71c92fe47362b5c4a4450
xulrunner-10.0.6-1.el6.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2012:1088 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1088.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
50bab9d7f39242bfbba97f499577bf04bd36d5878a824ba56c744f85211df024
firefox-10.0.6-1.el5.centos.i386.rpm
d40fc0c47e08c6d0dc6156dff2244f1b4d43df0e5d9a1665bce704d06d13c257
xulrunner-10.0.6-2.el5_8.i386.rpm
0785267ee1af683df54b929eec6696817554d77c0414d8b40cb289d7ee6cffbc
xulrunner-devel-10.0.6-2.el5_8.i386.rpm
x86_64:
50bab9d7f39242bfbba97f499577bf04bd36d5878a824ba56c744f85211df024
firefox-10.0.6-1.el5.centos.i386.rpm
8b4a0b8b7090ba1d1884e7cfe7d71a9739f68d2af593b4a12e7de726677f23f0
firefox-10.0.6-1.el5.centos.x86_64.rpm
d40fc0c47e08c6d0dc6156dff2244f1b4d43df0e5d9a1665bce704d06d13c257
xulrunner-10.0.6-2.el5_8.i386.rpm
f5744f194e1b168c9912e69123a88853092303be673755cf0e535a11c80b7887
xulrunner-10.0.6-2.el5_8.x86_64.rpm
0785267ee1af683df54b929eec6696817554d77c0414d8b40cb289d7ee6cffbc
xulrunner-devel-10.0.6-2.el5_8.i386.rpm
3a0b22e866f6543303bedf92683b4b2b847d3485f74594ed1c9eed06a68db833
xulrunner-devel-10.0.6-2.el5_8.x86_64.rpm
Source:
e3c999d2ee92d304ec0ff3b78e0aaee752f97638f5a1d8546800c0f8e59d1f4b
firefox-10.0.6-1.el5.centos.src.rpm
c4487bdd91a46c1e41c6d2fd0f49a671c355dfe7cc927b592aeba6d79eae5d53
xulrunner-10.0.6-2.el5_8.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
Posljednje sigurnosne preporuke