U radu programskog paketa ManiaDrive, za operacijske sustave Fedora 13 i 14, otkriveno je više sigurnosnih ranjivosti. Riječ je o računalnoj igrici za sudjelovanje u utrkama automobila. Pojedini propusti nastaju zbog pogrešaka u radu niza funkcija, datoteke "ext/xml/xml.c" te neodgovarajućeg rukovanja memorijom. Napadaču omogućuju izvođenje DoS i XSS napada, zaobilaženje pojedinih ograničenja, otkrivanje osjetljivih informacija ili pokretanje zlonamjernog programskog koda. Svi se korisnici potiču na primjenu novih, ispravljenih inačica.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-18976
2010-12-17 07:51:56
--------------------------------------------------------------------------------
Name : maniadrive
Product : Fedora 14
Version : 1.2
Release : 23.fc14
URL : http://maniadrive.raydium.org/
Summary : 3D stunt driving game
Description :
ManiaDrive is an arcade car game on acrobatic tracks, with a quick and nervous
gameplay (tracks almost never exceed one minute). Features: Complex car
physics, Challenging "story mode", LAN and Internet mode, Live scores,
Track editor, Dedicated server with HTTP interface and More than 30 blocks.
--------------------------------------------------------------------------------
Update Information:
Security Enhancements and Fixes in PHP 5.3.4:
* Fixed crash in zip extract method (possible CWE-170).
* Paths with NULL in them (foo bar.txt) are now considered as invalid
(CVE-2006-7243).
* Fixed a possible double free in imap extension (Identified by Mateusz
Kocielski). (CVE-2010-4150).
* Fixed NULL pointer dereference in ZipArchive::getArchiveComment.
(CVE-2010-3709).
* Fixed possible flaw in open_basedir (CVE-2010-3436).
* Fixed MOPS-2010-24, fix string validation. (CVE-2010-2950).
* Fixed symbolic resolution support when the target is a DFS share.
* Fixed bug #52929 (Segfault in filter_var with FILTER_VALIDATE_EMAIL with
large amount of data) (CVE-2010-3710).
Key Bug Fixes in PHP 5.3.4 include:
* Added stat support for zip stream.
* Added follow_location (enabled by default) option for the http stream
support.
* Added a 3rd parameter to get_html_translation_table. It now takes a charset
hint, like htmlentities et al.
* Implemented FR #52348, added new constant ZEND_MULTIBYTE to detect zend
multibyte at runtime.
Full upstream Changelog : http://www.php.net/ChangeLog-5.php#5.3.4
This update also provides php-eaccelerator and maniadrive packages rebuild
against update php.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Dec 12 2010 Remi Collet <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.2-23
- Rebuild for new php 5.3.4
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #649056 - CVE-2010-3870 php: XSS mitigation bypass via
utf8_decode()
https://bugzilla.redhat.com/show_bug.cgi?id=649056
[ 2 ] Bug #651206 - CVE-2010-3709 php: NULL pointer dereference in
ZipArchive::getArchiveComment
https://bugzilla.redhat.com/show_bug.cgi?id=651206
[ 3 ] Bug #651682 - CVE-2010-4156 php information disclosure via mb_strcut()
https://bugzilla.redhat.com/show_bug.cgi?id=651682
[ 4 ] Bug #652836 - CVE-2009-5016 php: XSS and SQL injection bypass via
crafted overlong UTF-8 encoded string
https://bugzilla.redhat.com/show_bug.cgi?id=652836
[ 5 ] Bug #660382 - CVE-2010-4409 php: getSymbol() integer overflow
vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=660382
[ 6 ] Bug #656917 - CVE-2010-4150 php: Double free in the imap extension
https://bugzilla.redhat.com/show_bug.cgi?id=656917
[ 7 ] Bug #646684 - CVE-2010-3710 php: DoS in filter_var() via long email
string
https://bugzilla.redhat.com/show_bug.cgi?id=646684
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update maniadrive' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-19011
2010-12-17 07:53:09
--------------------------------------------------------------------------------
Name : maniadrive
Product : Fedora 13
Version : 1.2
Release : 23.fc13
URL : http://maniadrive.raydium.org/
Summary : 3D stunt driving game
Description :
ManiaDrive is an arcade car game on acrobatic tracks, with a quick and nervous
gameplay (tracks almost never exceed one minute). Features: Complex car
physics, Challenging "story mode", LAN and Internet mode, Live scores,
Track editor, Dedicated server with HTTP interface and More than 30 blocks.
--------------------------------------------------------------------------------
Update Information:
Security Enhancements and Fixes in PHP 5.3.4:
* Fixed crash in zip extract method (possible CWE-170).
* Paths with NULL in them (foo�bar.txt) are now considered as invalid
(CVE-2006-7243).
* Fixed a possible double free in imap extension (Identified by Mateusz
Kocielski). (CVE-2010-4150).
* Fixed NULL pointer dereference in ZipArchive::getArchiveComment.
(CVE-2010-3709).
* Fixed possible flaw in open_basedir (CVE-2010-3436).
* Fixed MOPS-2010-24, fix string validation. (CVE-2010-2950).
* Fixed symbolic resolution support when the target is a DFS share.
* Fixed bug #52929 (Segfault in filter_var with FILTER_VALIDATE_EMAIL with
large amount of data) (CVE-2010-3710).
Key Bug Fixes in PHP 5.3.4 include:
* Added stat support for zip stream.
* Added follow_location (enabled by default) option for the http stream
support.
* Added a 3rd parameter to get_html_translation_table. It now takes a charset
hint, like htmlentities et al.
* Implemented FR #52348, added new constant ZEND_MULTIBYTE to detect zend
multibyte at runtime.
Full upstream Changelog : http://www.php.net/ChangeLog-5.php#5.3.4
This update also provides php-eaccelerator and maniadrive packages rebuild
against update php.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Dec 12 2010 Remi Collet <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.2-23
- Rebuild for new php 5.3.4
* Thu Jul 22 2010 Remi Collet <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.2-22
- Rebuild for new php 5.3.3
* Sat Mar 6 2010 Remi Collet <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.2-21
- Rebuild for new php 5.3.2
* Mon Feb 22 2010 Hans de Goede <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> 1.2-20
- Fix FTBFS (#564773)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #649056 - CVE-2010-3870 php: XSS mitigation bypass via
utf8_decode()
https://bugzilla.redhat.com/show_bug.cgi?id=649056
[ 2 ] Bug #651206 - CVE-2010-3709 php: NULL pointer dereference in
ZipArchive::getArchiveComment
https://bugzilla.redhat.com/show_bug.cgi?id=651206
[ 3 ] Bug #651682 - CVE-2010-4156 php information disclosure via mb_strcut()
https://bugzilla.redhat.com/show_bug.cgi?id=651682
[ 4 ] Bug #652836 - CVE-2009-5016 php: XSS and SQL injection bypass via
crafted overlong UTF-8 encoded string
https://bugzilla.redhat.com/show_bug.cgi?id=652836
[ 5 ] Bug #660382 - CVE-2010-4409 php: getSymbol() integer overflow
vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=660382
[ 6 ] Bug #656917 - CVE-2010-4150 php: Double free in the imap extension
https://bugzilla.redhat.com/show_bug.cgi?id=656917
[ 7 ] Bug #646684 - CVE-2010-3710 php: DoS in filter_var() via long email
string
https://bugzilla.redhat.com/show_bug.cgi?id=646684
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update maniadrive' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke