Pronađeni su i otklonjeni brojni sigurnosni propusti paketa GIMP za editiranje slika. Zlonamjerni korisnik mogao je iskoristiti ove sigurnosne ranjivosti kako bi nasilno ugasio paket ili izveo proizvoljan kod s ovlastima korisnika koji je pokrenuo program.
Paket:
gimp 2.x
Operacijski sustavi:
CentOS , Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6
Ovi višestruki nedostaci mogu se iskoristiti zbog nepravilne implementacije dodataka za rukovanje s PSD, GIF i KiSS CEL datotekama te implementacije Lempel-Ziv-Welch algoritma.
Posljedica:
Zlonamjerni korisnik mogao je podmetnuti posebno oblikovane datoteke čijim bi otvaranjem nasilno ugasio paket ili bi mogao pokrenuti proizvoljan programski kod.
CentOS Errata and Security Advisory 2012:1180 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1180.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
bf77c78603120e7763f561e53f9d0f05a4a43cf4f9ae5ca310aa47bd1cea3875
gimp-2.6.9-4.el6_3.3.i686.rpm
afdfc47cea6baf3f805915c88377f01fd158cfc95f3384fb3ff6910b92dbfeb6
gimp-devel-2.6.9-4.el6_3.3.i686.rpm
bae1bc702fccecd530ca5ce023fd27b8faebfe8502c1db8754098033d214c5de
gimp-devel-tools-2.6.9-4.el6_3.3.i686.rpm
50a7d1a29b521fb183db906330a30db193d1b253e61c7eb5651b4c9cd1fdb2d4
gimp-help-browser-2.6.9-4.el6_3.3.i686.rpm
7c49f7125b1d6921c72fcbd5e39b82cc738868728ea6ad69bf627d8224cb46a7
gimp-libs-2.6.9-4.el6_3.3.i686.rpm
x86_64:
700bff613b9c5ec262ccf2f1fa307e9c0250c73fbc712582962f7939ef811cbe
gimp-2.6.9-4.el6_3.3.x86_64.rpm
afdfc47cea6baf3f805915c88377f01fd158cfc95f3384fb3ff6910b92dbfeb6
gimp-devel-2.6.9-4.el6_3.3.i686.rpm
afbfdc0c694c04ded8e7631aedb90732b82fc572ef08cd91d59e51601e2d31c3
gimp-devel-2.6.9-4.el6_3.3.x86_64.rpm
7e9d7bbedf7af8738f87ef7d8973c855b4a4cfdade3e0319053225ac4000c6d4
gimp-devel-tools-2.6.9-4.el6_3.3.x86_64.rpm
91f6461858e878872dadee1c95e568fcac38e5ab556efe3b1aed91569b383fd6
gimp-help-browser-2.6.9-4.el6_3.3.x86_64.rpm
7c49f7125b1d6921c72fcbd5e39b82cc738868728ea6ad69bf627d8224cb46a7
gimp-libs-2.6.9-4.el6_3.3.i686.rpm
ab390738da10d9ddd6e6688498c595903a4a5cb3937777e06ec916686627c33d
gimp-libs-2.6.9-4.el6_3.3.x86_64.rpm
Source:
a4642047bd08241fc1fa97418861fe733761ec0babef53aaef3241227590838c
gimp-2.6.9-4.el6_3.3.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2012:1181 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1181.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
c44b76b8d8dc3913934f6196450bb9301d9df6b7aec601384a8268c7f92e90d5
gimp-2.2.13-2.0.7.el5_8.5.i386.rpm
e6c3cd9a0a73365bd85f6d2c009b14bd9a1ac322a96e383496f05cfb98921f17
gimp-devel-2.2.13-2.0.7.el5_8.5.i386.rpm
25071e1980de80b9c1ff245bf771c3d4146528ec36c7ab563e70e3f44fafe344
gimp-libs-2.2.13-2.0.7.el5_8.5.i386.rpm
x86_64:
89770f7bd126caf4aec4985547cb826369e59fee508ab4762d9491030a285b37
gimp-2.2.13-2.0.7.el5_8.5.x86_64.rpm
e6c3cd9a0a73365bd85f6d2c009b14bd9a1ac322a96e383496f05cfb98921f17
gimp-devel-2.2.13-2.0.7.el5_8.5.i386.rpm
6cc4a74f6c4836cd184f1b7d74badb7be5da4f6bdbb76307d994eec1db307acf
gimp-devel-2.2.13-2.0.7.el5_8.5.x86_64.rpm
25071e1980de80b9c1ff245bf771c3d4146528ec36c7ab563e70e3f44fafe344
gimp-libs-2.2.13-2.0.7.el5_8.5.i386.rpm
f140eca53b571b18ab36f4376925894eb11b1ee67754d4c17cfd2d4b19764076
gimp-libs-2.2.13-2.0.7.el5_8.5.x86_64.rpm
Source:
5537a6bc1099f8c59a05d79936e885788c3f49b6f6c42e9920149d5cfa75b58e
gimp-2.2.13-2.0.7.el5_8.5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
Posljednje sigurnosne preporuke