Uočena su i otklonjena dva nova sigurnosna propusta kod paketa openttd koja su omogućavala napadaču uskraćivanje usluge (DoS).
Paket:
openttd 1.x
Operacijski sustavi:
Fedora 17
Kritičnost:
7.5
Problem:
pogreška u programskoj komponenti
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2012-3436, CVE-2012-0049
Izvorni ID preporuke:
FEDORA-2012-12208
Izvor:
Fedora
Problem:
Do propusta dolazi zbog nepravilnosti koje nastaju prilikom spajanja korisnika te neodgovarajućeg rukovanja vezom kod sporog preuzimanja mape s poslužitelja.
Posljedica:
Napadač je mogao iskoristiti navedene probleme kako bi sporim preuzimanjem pojedine mape onemogućio ostalim legitimnim korisnicima spajanje na poslužitelj ili kako bi doveo isti u nedopušteno stanje te time uzrokovao uskraćivanje usluge.
Rješenje:
Korisnicima se preporuča primjena odgovarajuće nadogradnje.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-12208
2012-08-19 00:09:07
--------------------------------------------------------------------------------
Name : openttd
Product : Fedora 17
Version : 1.2.2
Release : 1.fc17
URL : http://www.openttd.org
Summary : Transport system simulation game
Description :
OpenTTD is modeled after a popular transportation business simulation game
by Chris Sawyer and enhances the game experience dramatically. Many features
were inspired by TTDPatch while others are original.
--------------------------------------------------------------------------------
Update Information:
Security update fixing Bug 844471 - (CVE-2012-3436):
Denial of service (server) using ships on half tiles and landscaping
--------------------------------------------------------------------------------
ChangeLog:
* Sat Aug 18 2012 Felix Kaechele <heffer@xxxxxxxxxxxxxxxxx> - 1.2.2-1
- fixes CVE-2012-3436
- many other bugfixes
* Fri Jul 20 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx>
- 1.2.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
* Tue Jun 26 2012 Felix Kaechele <heffer@xxxxxxxxxxxxxxxxx> - 1.2.1-1
- update to 1.2.1
* Mon Apr 23 2012 Felix Kaechele <heffer@xxxxxxxxxxxxxxxxx> - 1.2.0-2
- rebuild for new icu
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #844471 - CVE-2012-3436 OpenTTD: Denial of service (server) using
ships on half tiles and landscaping
https://bugzilla.redhat.com/show_bug.cgi?id=844471
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update openttd' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-12198
2012-08-19 00:08:33
--------------------------------------------------------------------------------
Name : openttd
Product : Fedora 16
Version : 1.2.2
Release : 1.fc16
URL : http://www.openttd.org
Summary : Transport system simulation game
Description :
OpenTTD is modeled after a popular transportation business simulation game
by Chris Sawyer and enhances the game experience dramatically. Many features
were inspired by TTDPatch while others are original.
--------------------------------------------------------------------------------
Update Information:
Security update fixing Bug 844471 - (CVE-2012-3436):
Denial of service (server) using ships on half tiles and landscaping
--------------------------------------------------------------------------------
ChangeLog:
* Sat Aug 18 2012 Felix Kaechele <heffer@xxxxxxxxxxxxxxxxx> - 1.2.2-1
- fixes CVE-2012-3436
- many other bugfixes
* Fri Jul 20 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx>
- 1.2.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
* Tue Jun 26 2012 Felix Kaechele <heffer@xxxxxxxxxxxxxxxxx> - 1.2.1-1
- update to 1.2.1
* Mon Apr 23 2012 Felix Kaechele <heffer@xxxxxxxxxxxxxxxxx> - 1.2.0-2
- rebuild for new icu
* Sun Apr 15 2012 Felix Kaechele <heffer@xxxxxxxxxxxxxxxxx> - 1.2.0-1
- update to stable 1.2.0
* Tue Apr 3 2012 Felix Kaechele <heffer@xxxxxxxxxxxxxxxxx> - 1.2.0-0.1.RC4
- Update to 1.2.0-RC4
- builds in F17 and rawhide again
* Sun Jan 15 2012 Felix Kaechele <heffer@xxxxxxxxxxxxxxxxx> - 1.1.5-1
- update to 1.1.5
- fixes CVE-2012-0049 (bz #782179)
* Fri Jan 13 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx>
- 1.1.3-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Tue Dec 6 2011 Adam Jackson <ajax@xxxxxxxxxx> - 1.1.3-2
- Rebuild for new libpng
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #844471 - CVE-2012-3436 OpenTTD: Denial of service (server) using
ships on half tiles and landscaping
https://bugzilla.redhat.com/show_bug.cgi?id=844471
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update openttd' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke