==========================================================================
Ubuntu Security Notice USN-1612-1
October 15, 2012
libgssglue vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
Summary:
Privilege escalation via the GSSAPI_MECH_CONF environment variable with setuid
programs.
Software Description:
- libgssglue: header files and docs for libgssglue
Details:
It was discovered that libgssglue incorrectly handled the GSSAPI_MECH_CONF
environment variable when running a privileged binary. A local attacker could
exploit this to gain root privileges. (CVE-2011-2709)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
libgssglue1 0.3-4ubuntu0.1
Ubuntu 11.10:
libgssglue1 0.3-1ubuntu1.1
Ubuntu 11.04:
libgssglue1 0.1-4ubuntu1.1
Ubuntu 10.04 LTS:
libgssglue1 0.1-4ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1612-1
CVE-2011-2709
Package Information:
https://launchpad.net/ubuntu/+source/libgssglue/0.3-4ubuntu0.1
https://launchpad.net/ubuntu/+source/libgssglue/0.3-1ubuntu1.1
https://launchpad.net/ubuntu/+source/libgssglue/0.1-4ubuntu1.1
https://launchpad.net/ubuntu/+source/libgssglue/0.1-4ubuntu0.1
Monday, October 15, 2012
Sunday, October 14, 2012
[Mageia-announce] Mageia 3 alpha 2 is now available for tests
Hi there
After some days of bug hunting, alpha 2 isos are finally available for
tests. You will find both classical installer and live CDs and DVDs.
http://blog.mageia.org/en/2012/10/14/after-a-nice-bug-hunting-mageia-3-alpha-2-is-out/
As usual we need as many reports as possible to improve the next release.
Enjoy!
--
Anne
http://mageia.org
_______________________________________________
Mageia-announce mailing list
Mageia-announce@mageia.org
https://www.mageia.org/mailman/listinfo/mageia-announce
After some days of bug hunting, alpha 2 isos are finally available for
tests. You will find both classical installer and live CDs and DVDs.
http://blog.mageia.org/en/2012/10/14/after-a-nice-bug-hunting-mageia-3-alpha-2-is-out/
As usual we need as many reports as possible to improve the next release.
Enjoy!
--
Anne
http://mageia.org
_______________________________________________
Mageia-announce mailing list
Mageia-announce@mageia.org
https://www.mageia.org/mailman/listinfo/mageia-announce
Saturday, October 13, 2012
[arch-announce] systemd is now the default on new installations
Thomas Bächler wrote:
The base group now contains the `systemd-sysvcompat` package. This means that
all new installations will boot with systemd by default.
As some packages still lack native systemd units, users can install the
`initscripts` package and use the `DAEMONS` array in `/etc/rc.conf` to start
services using the legacy rc.d scripts.
This change does not affect existing installations. For the time being, the
`initscripts` and `sysvinit` packages remain available from our repositories.
However, individual packages may now start relying on the system being booted
with systemd.
Please refer to [the wiki][1] for how to transition an existing installation to
systemd.
[1]: https://wiki.archlinux.org/index.php/Systemd
URL: https://www.archlinux.org/news/systemd-is-now-the-default-on-new-installations/
_______________________________________________
arch-announce mailing list
arch-announce@archlinux.org
http://mailman.archlinux.org/mailman/listinfo/arch-announce
The base group now contains the `systemd-sysvcompat` package. This means that
all new installations will boot with systemd by default.
As some packages still lack native systemd units, users can install the
`initscripts` package and use the `DAEMONS` array in `/etc/rc.conf` to start
services using the legacy rc.d scripts.
This change does not affect existing installations. For the time being, the
`initscripts` and `sysvinit` packages remain available from our repositories.
However, individual packages may now start relying on the system being booted
with systemd.
Please refer to [the wiki][1] for how to transition an existing installation to
systemd.
[1]: https://wiki.archlinux.org/index.php/Systemd
URL: https://www.archlinux.org/news/systemd-is-now-the-default-on-new-installations/
_______________________________________________
arch-announce mailing list
arch-announce@archlinux.org
http://mailman.archlinux.org/mailman/listinfo/arch-announce
Friday, October 12, 2012
[CentOS-announce] CESA-2012:1361 Critical CentOS 6 xulrunner Update
CentOS Errata and Security Advisory 2012:1361 Critical
Upstream details at : http://rhn.redhat.com/errata/RHSA-2012-1361.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
8aa23a90543e93ee6c86f372aca6afd16cbb34bb5e722a4513a9239dbc6b83bd xulrunner-10.0.8-2.el6.centos.i686.rpm
380c9fd816d612458ccbfbc15b1c5dc409332b3ebd05a3ec1b78ca84639ada12 xulrunner-devel-10.0.8-2.el6.centos.i686.rpm
x86_64:
8aa23a90543e93ee6c86f372aca6afd16cbb34bb5e722a4513a9239dbc6b83bd xulrunner-10.0.8-2.el6.centos.i686.rpm
2c9c4aa65eb3d3370f7f784f84a4109cd54c3ab2037114a2047f440514f69eaf xulrunner-10.0.8-2.el6.centos.x86_64.rpm
380c9fd816d612458ccbfbc15b1c5dc409332b3ebd05a3ec1b78ca84639ada12 xulrunner-devel-10.0.8-2.el6.centos.i686.rpm
6db35edb582ebb98e306567d4f8e4cc9278f751be4a4dd6636a516bb46ec8d62 xulrunner-devel-10.0.8-2.el6.centos.x86_64.rpm
Source:
b3f88045de818b05894facfde65e47ca4fe749b49f45312484824a16dad874e2 xulrunner-10.0.8-2.el6.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : http://rhn.redhat.com/errata/RHSA-2012-1361.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
8aa23a90543e93ee6c86f372aca6afd16cbb34bb5e722a4513a9239dbc6b83bd xulrunner-10.0.8-2.el6.centos.i686.rpm
380c9fd816d612458ccbfbc15b1c5dc409332b3ebd05a3ec1b78ca84639ada12 xulrunner-devel-10.0.8-2.el6.centos.i686.rpm
x86_64:
8aa23a90543e93ee6c86f372aca6afd16cbb34bb5e722a4513a9239dbc6b83bd xulrunner-10.0.8-2.el6.centos.i686.rpm
2c9c4aa65eb3d3370f7f784f84a4109cd54c3ab2037114a2047f440514f69eaf xulrunner-10.0.8-2.el6.centos.x86_64.rpm
380c9fd816d612458ccbfbc15b1c5dc409332b3ebd05a3ec1b78ca84639ada12 xulrunner-devel-10.0.8-2.el6.centos.i686.rpm
6db35edb582ebb98e306567d4f8e4cc9278f751be4a4dd6636a516bb46ec8d62 xulrunner-devel-10.0.8-2.el6.centos.x86_64.rpm
Source:
b3f88045de818b05894facfde65e47ca4fe749b49f45312484824a16dad874e2 xulrunner-10.0.8-2.el6.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2012:1362 Critical CentOS 6 thunderbird Update
CentOS Errata and Security Advisory 2012:1362 Critical
Upstream details at : http://rhn.redhat.com/errata/RHSA-2012-1362.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
48ed64ad76d4a9fcefbd21bfde5c682356da2c181add71902457b2c02c175d37 thunderbird-10.0.8-2.el6.centos.i686.rpm
x86_64:
0eb144dc561a655fcdaba713da7ba34ba79525da8d7fd28a586b0f8f8be1ec0f thunderbird-10.0.8-2.el6.centos.x86_64.rpm
Source:
3de262005ece5fe2d41154aae6d9356da1d47c50c2c521ecdcdd2cfa197862ed thunderbird-10.0.8-2.el6.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : http://rhn.redhat.com/errata/RHSA-2012-1362.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
48ed64ad76d4a9fcefbd21bfde5c682356da2c181add71902457b2c02c175d37 thunderbird-10.0.8-2.el6.centos.i686.rpm
x86_64:
0eb144dc561a655fcdaba713da7ba34ba79525da8d7fd28a586b0f8f8be1ec0f thunderbird-10.0.8-2.el6.centos.x86_64.rpm
Source:
3de262005ece5fe2d41154aae6d9356da1d47c50c2c521ecdcdd2cfa197862ed thunderbird-10.0.8-2.el6.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2012:1363 Important CentOS 6 bind Update
CentOS Errata and Security Advisory 2012:1363 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1363.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
a20a602ceb21c13e6f5797c9135511e0c6cd9080883653f6e6b45d7d53e15706 bind-9.8.2-0.10.rc1.el6_3.5.i686.rpm
1e9a79aefeb381e29c15075441d29cfd4d80ad8134fcf1fc86ab30b2c1fe8e20 bind-chroot-9.8.2-0.10.rc1.el6_3.5.i686.rpm
da2c82be708cfe74c736e9cdb14013581335ea785e28a5e12bb5fa5a35202275 bind-devel-9.8.2-0.10.rc1.el6_3.5.i686.rpm
1129e3cf768d1db8b770285571a414494590e332e8947943c5b4ffd99cf8e283 bind-libs-9.8.2-0.10.rc1.el6_3.5.i686.rpm
2b8fffd8e9bdc008c512fb15cdc18d1cb505b467254f1bd97fdee031ff1436df bind-sdb-9.8.2-0.10.rc1.el6_3.5.i686.rpm
4ee97055b1b7883e26757449bcabaeb789a5ef25dd851e691c2f8aac6ff34bd3 bind-utils-9.8.2-0.10.rc1.el6_3.5.i686.rpm
x86_64:
d88ede9b22d7c27f07df841fccdd8eaed9a0dbe85980b21759632ca2c8db230c bind-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
ebfff0bcf21aa2a85e529312d6aff01b8445fced24f22488d41ecda5fd958e9b bind-chroot-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
da2c82be708cfe74c736e9cdb14013581335ea785e28a5e12bb5fa5a35202275 bind-devel-9.8.2-0.10.rc1.el6_3.5.i686.rpm
a31094c895982cdabd95a1c42fe500eb868591f5caeb2bb70704d8d5fbc44393 bind-devel-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
1129e3cf768d1db8b770285571a414494590e332e8947943c5b4ffd99cf8e283 bind-libs-9.8.2-0.10.rc1.el6_3.5.i686.rpm
e55f42f8fb4c4d73684951efd4ec5ac3a9f4501e9fde3c7cb56a32b1b4309cce bind-libs-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
da18b6ad62c10c1c378a94281a763b07105309d742f538011578b7d25e2006c0 bind-sdb-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
40d049080fbcdbf6d3ac0f894e3b757b2159888a76ed83ee4d1338a21d218226 bind-utils-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
Source:
266534fa3fb2497a5d75db5a02be3e767288e30c34fb25382110f747d6d31121 bind-9.8.2-0.10.rc1.el6_3.5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1363.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
a20a602ceb21c13e6f5797c9135511e0c6cd9080883653f6e6b45d7d53e15706 bind-9.8.2-0.10.rc1.el6_3.5.i686.rpm
1e9a79aefeb381e29c15075441d29cfd4d80ad8134fcf1fc86ab30b2c1fe8e20 bind-chroot-9.8.2-0.10.rc1.el6_3.5.i686.rpm
da2c82be708cfe74c736e9cdb14013581335ea785e28a5e12bb5fa5a35202275 bind-devel-9.8.2-0.10.rc1.el6_3.5.i686.rpm
1129e3cf768d1db8b770285571a414494590e332e8947943c5b4ffd99cf8e283 bind-libs-9.8.2-0.10.rc1.el6_3.5.i686.rpm
2b8fffd8e9bdc008c512fb15cdc18d1cb505b467254f1bd97fdee031ff1436df bind-sdb-9.8.2-0.10.rc1.el6_3.5.i686.rpm
4ee97055b1b7883e26757449bcabaeb789a5ef25dd851e691c2f8aac6ff34bd3 bind-utils-9.8.2-0.10.rc1.el6_3.5.i686.rpm
x86_64:
d88ede9b22d7c27f07df841fccdd8eaed9a0dbe85980b21759632ca2c8db230c bind-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
ebfff0bcf21aa2a85e529312d6aff01b8445fced24f22488d41ecda5fd958e9b bind-chroot-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
da2c82be708cfe74c736e9cdb14013581335ea785e28a5e12bb5fa5a35202275 bind-devel-9.8.2-0.10.rc1.el6_3.5.i686.rpm
a31094c895982cdabd95a1c42fe500eb868591f5caeb2bb70704d8d5fbc44393 bind-devel-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
1129e3cf768d1db8b770285571a414494590e332e8947943c5b4ffd99cf8e283 bind-libs-9.8.2-0.10.rc1.el6_3.5.i686.rpm
e55f42f8fb4c4d73684951efd4ec5ac3a9f4501e9fde3c7cb56a32b1b4309cce bind-libs-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
da18b6ad62c10c1c378a94281a763b07105309d742f538011578b7d25e2006c0 bind-sdb-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
40d049080fbcdbf6d3ac0f894e3b757b2159888a76ed83ee4d1338a21d218226 bind-utils-9.8.2-0.10.rc1.el6_3.5.x86_64.rpm
Source:
266534fa3fb2497a5d75db5a02be3e767288e30c34fb25382110f747d6d31121 bind-9.8.2-0.10.rc1.el6_3.5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2012:1362 Critical CentOS 5 thunderbird Update
CentOS Errata and Security Advisory 2012:1362 Critical
Upstream details at : http://rhn.redhat.com/errata/RHSA-2012-1362.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
989659271a649582dc88441f7049ec7dca2d016647c6ee218884d3a6019f9013 thunderbird-10.0.8-2.el5.centos.i386.rpm
x86_64:
ca004d29697749328ecfe921c18444005d52e9b75e0c19d40f8b1ecc2177d7cc thunderbird-10.0.8-2.el5.centos.x86_64.rpm
Source:
5781f63862877016d3909babb49453c42a1676a948985440d10ad28496aa2db2 thunderbird-10.0.8-2.el5.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : http://rhn.redhat.com/errata/RHSA-2012-1362.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
989659271a649582dc88441f7049ec7dca2d016647c6ee218884d3a6019f9013 thunderbird-10.0.8-2.el5.centos.i386.rpm
x86_64:
ca004d29697749328ecfe921c18444005d52e9b75e0c19d40f8b1ecc2177d7cc thunderbird-10.0.8-2.el5.centos.x86_64.rpm
Source:
5781f63862877016d3909babb49453c42a1676a948985440d10ad28496aa2db2 thunderbird-10.0.8-2.el5.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2012:1361 Critical CentOS 5 xulrunner Update
CentOS Errata and Security Advisory 2012:1361 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1361.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
ef4e6d562455f4b02f402fb0cdd183052396ccbba1670c71ca892e57903370a2 xulrunner-10.0.8-2.el5_8.i386.rpm
30f51a4159b2611ccd92b4bdfd18c1c657280366d0b22d6dbb12e3343086be6e xulrunner-devel-10.0.8-2.el5_8.i386.rpm
x86_64:
ef4e6d562455f4b02f402fb0cdd183052396ccbba1670c71ca892e57903370a2 xulrunner-10.0.8-2.el5_8.i386.rpm
0ec67a661511c3e4e57b13da61c4503327d373508eee5d5288099e7b74630149 xulrunner-10.0.8-2.el5_8.x86_64.rpm
30f51a4159b2611ccd92b4bdfd18c1c657280366d0b22d6dbb12e3343086be6e xulrunner-devel-10.0.8-2.el5_8.i386.rpm
dc526f5ee27686017c3343d3334d489f4f42bb50efacb8ce20becde1bab8ab58 xulrunner-devel-10.0.8-2.el5_8.x86_64.rpm
Source:
06c60ad14fd8508dfde4b24ed971cd98d55f8f5d2cb75266336729f16133b137 xulrunner-10.0.8-2.el5_8.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1361.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
ef4e6d562455f4b02f402fb0cdd183052396ccbba1670c71ca892e57903370a2 xulrunner-10.0.8-2.el5_8.i386.rpm
30f51a4159b2611ccd92b4bdfd18c1c657280366d0b22d6dbb12e3343086be6e xulrunner-devel-10.0.8-2.el5_8.i386.rpm
x86_64:
ef4e6d562455f4b02f402fb0cdd183052396ccbba1670c71ca892e57903370a2 xulrunner-10.0.8-2.el5_8.i386.rpm
0ec67a661511c3e4e57b13da61c4503327d373508eee5d5288099e7b74630149 xulrunner-10.0.8-2.el5_8.x86_64.rpm
30f51a4159b2611ccd92b4bdfd18c1c657280366d0b22d6dbb12e3343086be6e xulrunner-devel-10.0.8-2.el5_8.i386.rpm
dc526f5ee27686017c3343d3334d489f4f42bb50efacb8ce20becde1bab8ab58 xulrunner-devel-10.0.8-2.el5_8.x86_64.rpm
Source:
06c60ad14fd8508dfde4b24ed971cd98d55f8f5d2cb75266336729f16133b137 xulrunner-10.0.8-2.el5_8.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2012:1364 Important CentOS 5 bind97 Update
CentOS Errata and Security Advisory 2012:1364 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1364.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
f6e7710824b993e7afff3eba790fe332d12afe3dee68de0c6cc1ebb6e1d00e1b bind97-9.7.0-10.P2.el5_8.4.i386.rpm
5ac0b03ff99e9c48ace3ec7cec25d360f93ab1d2c605e34e6018cb68e7ff0062 bind97-chroot-9.7.0-10.P2.el5_8.4.i386.rpm
bc51803cf0cb874e698cda7c1fd24950461cd0724c5848331614a47e6339d4da bind97-devel-9.7.0-10.P2.el5_8.4.i386.rpm
55f7dd7482011c7a2835b562ebadc5c3f7a26e66115125a127fa3943736c5745 bind97-libs-9.7.0-10.P2.el5_8.4.i386.rpm
68ea08955f35801cb84431b3ed102786d69ccb212d3b2bd66e01b68a3852b0d4 bind97-utils-9.7.0-10.P2.el5_8.4.i386.rpm
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1364.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
f6e7710824b993e7afff3eba790fe332d12afe3dee68de0c6cc1ebb6e1d00e1b bind97-9.7.0-10.P2.el5_8.4.i386.rpm
5ac0b03ff99e9c48ace3ec7cec25d360f93ab1d2c605e34e6018cb68e7ff0062 bind97-chroot-9.7.0-10.P2.el5_8.4.i386.rpm
bc51803cf0cb874e698cda7c1fd24950461cd0724c5848331614a47e6339d4da bind97-devel-9.7.0-10.P2.el5_8.4.i386.rpm
55f7dd7482011c7a2835b562ebadc5c3f7a26e66115125a127fa3943736c5745 bind97-libs-9.7.0-10.P2.el5_8.4.i386.rpm
68ea08955f35801cb84431b3ed102786d69ccb212d3b2bd66e01b68a3852b0d4 bind97-utils-9.7.0-10.P2.el5_8.4.i386.rpm
[CentOS-announce] CESA-2012:1363 Important CentOS 5 bind Update
CentOS Errata and Security Advisory 2012:1363 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1363.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
71797c3280b4b7b539a5494441625679b7aca83a7d969f1b427725245fbbaa06 bind-9.3.6-20.P1.el5_8.5.i386.rpm
90887b9695f108ce0cd30bf776909bd7172a9ec4f3fc6f98b42bbc74ea5efba0 bind-chroot-9.3.6-20.P1.el5_8.5.i386.rpm
c5413797436b3f1706638e835dff69a52af39e3c8a26995fa3cc823b867519ce bind-devel-9.3.6-20.P1.el5_8.5.i386.rpm
9b54d535bd1aa349f1338008ae0e13c12d14105a36fc80024f1902129e7b2d3e bind-libbind-devel-9.3.6-20.P1.el5_8.5.i386.rpm
1e2356fd60b14b32cfe5a5dd399dfe63dab08e96033b97cdf860fb87639142fd bind-libs-9.3.6-20.P1.el5_8.5.i386.rpm
15df25bdec27116221d4b5be58531cec4bd0f78ea3075f0a4d78a6acb29d7ec4 bind-sdb-9.3.6-20.P1.el5_8.5.i386.rpm
70a34f0727dd56757ec669b0aa30e6859f8ae89c66c44ef2cdf31078e7f19789 bind-utils-9.3.6-20.P1.el5_8.5.i386.rpm
1f83b4ab65453a6e376cd81764a23fe8d6d189ab452384179107616cbdf5defb caching-nameserver-9.3.6-20.P1.el5_8.5.i386.rpm
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-1363.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
71797c3280b4b7b539a5494441625679b7aca83a7d969f1b427725245fbbaa06 bind-9.3.6-20.P1.el5_8.5.i386.rpm
90887b9695f108ce0cd30bf776909bd7172a9ec4f3fc6f98b42bbc74ea5efba0 bind-chroot-9.3.6-20.P1.el5_8.5.i386.rpm
c5413797436b3f1706638e835dff69a52af39e3c8a26995fa3cc823b867519ce bind-devel-9.3.6-20.P1.el5_8.5.i386.rpm
9b54d535bd1aa349f1338008ae0e13c12d14105a36fc80024f1902129e7b2d3e bind-libbind-devel-9.3.6-20.P1.el5_8.5.i386.rpm
1e2356fd60b14b32cfe5a5dd399dfe63dab08e96033b97cdf860fb87639142fd bind-libs-9.3.6-20.P1.el5_8.5.i386.rpm
15df25bdec27116221d4b5be58531cec4bd0f78ea3075f0a4d78a6acb29d7ec4 bind-sdb-9.3.6-20.P1.el5_8.5.i386.rpm
70a34f0727dd56757ec669b0aa30e6859f8ae89c66c44ef2cdf31078e7f19789 bind-utils-9.3.6-20.P1.el5_8.5.i386.rpm
1f83b4ab65453a6e376cd81764a23fe8d6d189ab452384179107616cbdf5defb caching-nameserver-9.3.6-20.P1.el5_8.5.i386.rpm
[USN-1611-1] Thunderbird vulnerabilities
========================================================================
Ubuntu Security Notice USN-1611-1
October 12, 2012
thunderbird vulnerabilities
========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others
discovered several memory corruption flaws in Thunderbird. If a user were
tricked into opening a malicious website and had JavaScript enabled, an
attacker could exploit these to execute arbitrary JavaScript code within
the context of another website or arbitrary code as the user invoking the
program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,
CVE-2012-4191)
David Bloom and Jordi Chancel discovered that Thunderbird did not always
properly handle the <select> element. If a user were tricked into opening a
malicious website and had JavaScript enabled, a remote attacker could
exploit this to conduct URL spoofing and clickjacking attacks.
(CVE-2012-3984)
Collin Jackson discovered that Thunderbird did not properly follow the
HTML5 specification for document.domain behavior. If a user were tricked
into opening a malicious website and had JavaScript enabled, a remote
attacker could exploit this to conduct cross-site scripting (XSS) attacks
via JavaScript execution. (CVE-2012-3985)
Johnny Stenback discovered that Thunderbird did not properly perform
security checks on test methods for DOMWindowUtils. (CVE-2012-3986)
Alice White discovered that the security checks for GetProperty could be
bypassed when using JSAPI. If a user were tricked into opening a specially
crafted web page and had JavaScript enabled, a remote attacker could
exploit this to execute arbitrary code as the user invoking the program.
(CVE-2012-3991)
Mariusz Mlynski discovered a history state error in Thunderbird. If a user
were tricked into opening a malicious website and had JavaScript enabled, a
remote attacker could exploit this to spoof the location property to inject
script or intercept posted data. (CVE-2012-3992)
Mariusz Mlynski and others discovered several flaws in Thunderbird that
allowed a remote attacker to conduct cross-site scripting (XSS) attacks.
With cross-site scripting vulnerabilities, if a user were tricked into
viewing a specially crafted page and had JavaScript enabled, a remote
attacker could exploit these to modify the contents, or steal confidential
data, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)
Abhishek Arya, Atte Kettunen and others discovered several memory flaws in
Thunderbird when using the Address Sanitizer tool. If a user were tricked
into opening a malicious website and had JavaScript enabled, an attacker
could exploit these to execute arbitrary JavaScript code within the context
of another website or execute arbitrary code as the user invoking the
program. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,
CVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,
CVE-2012-4187, CVE-2012-4188)
It was discovered that Thunderbird allowed improper access to the Location
object. An attacker could exploit this to obtain sensitive information.
Under certain circumstances, a remote attacker could use this vulnerability
to potentially execute arbitrary code as the user invoking the program.
(CVE-2012-4192, CVE-2012-4193)
Ubuntu Security Notice USN-1611-1
October 12, 2012
thunderbird vulnerabilities
========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Henrik Skupin, Jesse Ruderman, Christian Holler, Soroush Dalili and others
discovered several memory corruption flaws in Thunderbird. If a user were
tricked into opening a malicious website and had JavaScript enabled, an
attacker could exploit these to execute arbitrary JavaScript code within
the context of another website or arbitrary code as the user invoking the
program. (CVE-2012-3982, CVE-2012-3983, CVE-2012-3988, CVE-2012-3989,
CVE-2012-4191)
David Bloom and Jordi Chancel discovered that Thunderbird did not always
properly handle the <select> element. If a user were tricked into opening a
malicious website and had JavaScript enabled, a remote attacker could
exploit this to conduct URL spoofing and clickjacking attacks.
(CVE-2012-3984)
Collin Jackson discovered that Thunderbird did not properly follow the
HTML5 specification for document.domain behavior. If a user were tricked
into opening a malicious website and had JavaScript enabled, a remote
attacker could exploit this to conduct cross-site scripting (XSS) attacks
via JavaScript execution. (CVE-2012-3985)
Johnny Stenback discovered that Thunderbird did not properly perform
security checks on test methods for DOMWindowUtils. (CVE-2012-3986)
Alice White discovered that the security checks for GetProperty could be
bypassed when using JSAPI. If a user were tricked into opening a specially
crafted web page and had JavaScript enabled, a remote attacker could
exploit this to execute arbitrary code as the user invoking the program.
(CVE-2012-3991)
Mariusz Mlynski discovered a history state error in Thunderbird. If a user
were tricked into opening a malicious website and had JavaScript enabled, a
remote attacker could exploit this to spoof the location property to inject
script or intercept posted data. (CVE-2012-3992)
Mariusz Mlynski and others discovered several flaws in Thunderbird that
allowed a remote attacker to conduct cross-site scripting (XSS) attacks.
With cross-site scripting vulnerabilities, if a user were tricked into
viewing a specially crafted page and had JavaScript enabled, a remote
attacker could exploit these to modify the contents, or steal confidential
data, within the same domain. (CVE-2012-3993, CVE-2012-3994, CVE-2012-4184)
Abhishek Arya, Atte Kettunen and others discovered several memory flaws in
Thunderbird when using the Address Sanitizer tool. If a user were tricked
into opening a malicious website and had JavaScript enabled, an attacker
could exploit these to execute arbitrary JavaScript code within the context
of another website or execute arbitrary code as the user invoking the
program. (CVE-2012-3990, CVE-2012-3995, CVE-2012-4179, CVE-2012-4180,
CVE-2012-4181, CVE-2012-4182, CVE-2012-4183, CVE-2012-4185, CVE-2012-4186,
CVE-2012-4187, CVE-2012-4188)
It was discovered that Thunderbird allowed improper access to the Location
object. An attacker could exploit this to obtain sensitive information.
Under certain circumstances, a remote attacker could use this vulnerability
to potentially execute arbitrary code as the user invoking the program.
(CVE-2012-4192, CVE-2012-4193)
[USN-1610-1] Linux kernel vulnerability
========================================================================
Ubuntu Security Notice USN-1610-1
October 12, 2012
linux vulnerability
========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
The system could be made to perform privileged actions as an administrator.
Software Description:
- linux: Linux kernel
Details:
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions.
Ubuntu Security Notice USN-1610-1
October 12, 2012
linux vulnerability
========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
The system could be made to perform privileged actions as an administrator.
Software Description:
- linux: Linux kernel
Details:
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions.
Subscribe to:
Posts (Atom)