U radu programskog modula perl-File-FcntlLock, namijenjenog radu na operacijskom sustavu Fedora 13, uvedena je nova sigurnosna funkcionalnost. Riječ je o modulu koji omogućuje zaključavanje datoteka koristeći fcntl(2) sistemske pozive. Funkcionalnost je vezana uz paket perl-Mail-Box koji u novoj inačici uvodi slučajne vrijednosti koje se koriste za određivanje memorijskih granica kako bi se izbjegli mogući rizici kod napada pogađanjem granica. Izdana je nova inačica paketa pa se svim korisnicima savjetuje njezina instalacija.

--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-2531
2011-03-03 07:54:02
--------------------------------------------------------------------------------

Name        : perl-File-FcntlLock
Product     : Fedora 13
Version     : 0.12
Release     : 1.fc13
URL         : http://search.cpan.org/dist/File-FcntlLock/
Summary     : Perl module for file locking with fcntl
Description :
FcntlLock is a module to do file locking in an object oriented
fashion using the fcntl(2) system call. This allows locks on parts
of a file as well as on the whole file and overcomes some known
problems with flock(2), on which Perl's flock() function is based.

--------------------------------------------------------------------------------
Update Information:

Update perl-Mail-Box to 2.097.
No longer require spamassassin.
2.097 now randomizes boundary string to avoid (undemonstrated) security risks
with boundary guessing.

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #647783 - perl-Mail-Box shouldn't force spamassassin to be
installed
        https://bugzilla.redhat.com/show_bug.cgi?id=647783
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update perl-File-FcntlLock' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce

Idi na vrh