Dva sigurnosna nedostatka su otkrivena u radu programskog paketa exim, a mogu se iskoristiti udaljeno za pokretanje proizvoljnog programskog koda.
Paket:
Exim 4.x
Operacijski sustavi:
Fedora 13, Fedora 14
Kritičnost:
6.5
Problem:
pogreška u programskoj funkciji
Iskorištavanje:
udaljeno
Posljedica:
proizvoljno izvršavanje programskog koda
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-1407, CVE-2011-1764
Izvorni ID preporuke:
FEDORA-2011-7059
Izvor:
Fedora
Problem:
Jedan od nedostataka nastaje zbog nepravilnosti u funkciji "dkim_exim_verify_finish()" [src/dkim.c], dok je drugi vezan uz neodgovarajuću obradu određenih DKIM potpisa.
Posljedica:
Zlonamjerni, udaljeni korisnici mogu iskoristiti propust za izvršavanje proizvoljnog programskog koda.
Rješenje:
Dostupna je nadogradnja koja otklanja oba nedostatka te se savjetuje njeno korištenje.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-7059
2011-05-17 00:11:05
--------------------------------------------------------------------------------
Name : exim
Product : Fedora 13
Version : 4.76
Release : 1.fc13
URL : http://www.exim.org/
Summary : The exim mail transfer agent
Description :
Exim is a message transfer agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet. It is
freely available under the terms of the GNU General Public Licence. In
style it is similar to Smail 3, but its facilities are more
general. There is a great deal of flexibility in the way mail can be
routed, and there are extensive facilities for checking incoming
mail. Exim can be installed in place of sendmail, although the
configuration of exim is quite different to that of sendmail.
--------------------------------------------------------------------------------
Update Information:
This update fixes two remote execution exploits in DKIM processing code (CVE-2011-1407, CVE-2011-1764).
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 15 2011 David Woodhouse <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 4.76-1
- Update to 4.76 (fixes CVE-2011-1407, CVE-2011-1764) (#702474)
* Thu Jun 3 2010 David Woodhouse <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 4.72-1
- Update to 4.72 (fixes CVE-2010-2023, CVE-2010-2024)
* Thu Mar 18 2010 Miroslav Lichvar <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 4.71-3
- follow guidelines for alternatives (#570800)
- fix init script LSB compliance (#523238)
- handle undefined NETWORKING in init script (#483528)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #702474 - CVE-2011-1764 exim: improper format string handling in DKIM signatures
https://bugzilla.redhat.com/show_bug.cgi?id=702474
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update exim' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-7047
2011-05-17 00:10:35
--------------------------------------------------------------------------------
Name : exim
Product : Fedora 14
Version : 4.76
Release : 1.fc14
URL : http://www.exim.org/
Summary : The exim mail transfer agent
Description :
Exim is a message transfer agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet. It is
freely available under the terms of the GNU General Public Licence. In
style it is similar to Smail 3, but its facilities are more
general. There is a great deal of flexibility in the way mail can be
routed, and there are extensive facilities for checking incoming
mail. Exim can be installed in place of sendmail, although the
configuration of exim is quite different to that of sendmail.
--------------------------------------------------------------------------------
Update Information:
This update fixes two remote execution exploits in DKIM processing code (CVE-2011-1407, CVE-2011-1764).
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 15 2011 David Woodhouse <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 4.76-1
- Update to 4.76 (fixes CVE-2011-1407, CVE-2011-1764) (#702474)
* Sat Aug 7 2010 David Woodhouse <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 4.72-2
- Fedora infrastructure ate my package; bump release and rebuild
* Thu Jun 3 2010 David Woodhouse <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 4.72-1
- Update to 4.72 (fixes CVE-2010-2023, CVS-2010-2024)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #702474 - CVE-2011-1764 exim: improper format string handling in DKIM signatures
https://bugzilla.redhat.com/show_bug.cgi?id=702474
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update exim' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke