Sorties
Dons

Fait une donation pour aider à nos efforts de développement.

Mises à jours récentes
chroot-core/
 libarchive
2.8.3-1-ppc
apps-extra/etckeeper
0.43-1-ppc
base/os-prober
1.36-1-ppc
base/mdadm
3.1.2-1-ppc
gnome-extra/exaile
0.3.1.0-1-ppc
network-extra/
 bitlbee
1.2.5-1-ppc
xorg-drivers/
 xf86-video-nouveau
0.0.15.g6b8b157-2-ppc
base/
 nouveau-firmware
20091212-1-ppc
gnome-extra/
 monodevelop
2.2.2-1-ppc
xlib/gtk2-sharp
2.12.10-1-ppc

RSS
Langues
Changer de langue | Changer de langue | Changer de langue | Changer de langue | Changer de langue | Changer de langue | Changer de langue
Information
Go Frugalware, Go
Valid XHTML 1.0!
Valid CSS!
Valid RSS!
Informations serveur
Temps de fonctionnement:
98 jour(s) 23 h 2 m 6 s
Annonces de Sécurité Frugalware (FSAs)
Ceci est la liste des annonces de sécurité qui ont été faites pour la version stable actuelle de Frugalware
FSA643 - libesmtp
Paquet:libesmtp
Date:2010-03-16
Posté par:Miklos Vajna
Version vulnérable:1.0.4-1
Version non affectée:1.0.4-2locris1
Entrée de suivi des bugs:http://bugs.frugalware.org/task/4141
CVEs:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2408
Description:libesmtp did not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
FSA642 - drupal6-i18n
Paquet:drupal6-i18n
Date:2010-03-12
Posté par:Miklos Vajna
Version vulnérable:6.x_1.2-1
Version non affectée:6.x_1.3-1locris1
Entrée de suivi des bugs:http://bugs.frugalware.org/task/4134
CVEs:No CVE references, see http://drupal.org/node/731632.
Description:See FSA641 for details.
FSA641 - drupal-i18n
Paquet:drupal-i18n
Date:2010-03-12
Posté par:Miklos Vajna
Version vulnérable:5.x_2.5-1
Version non affectée:5.x_2.6-1locris1
Entrée de suivi des bugs:http://bugs.frugalware.org/task/4134
CVEs:No CVE references, see http://drupal.org/node/731632.
Description:A vulnerability has been reported in the Internationalization module for Drupal, which can be exploited by malicious users to compromise a vulnerable system. Certain unspecified input is not properly sanitised before being used to translate the text. This can be exploited to execute arbitrary PHP code by passing a malicious string to the input filter.
FSA640 - drupal6
Paquet:drupal6
Date:2010-03-11
Posté par:Miklos Vajna
Version vulnérable:6.15-1
Version non affectée:6.16-1locris1
Entrée de suivi des bugs:http://bugs.frugalware.org/task/4133
CVEs:No CVE references, see http://drupal.org/node/731710.
Description:See FSA639 for details.
FSA639 - drupal
Paquet:drupal
Date:2010-03-11
Posté par:Miklos Vajna
Version vulnérable:5.21-1
Version non affectée:5.22-2locris1
Entrée de suivi des bugs:http://bugs.frugalware.org/task/4132
CVEs:No CVE references, see http://drupal.org/node/731710.
Description:Some vulnerabilities have been reported in Drupal, which can be exploited by malicious users to conduct script insertion attacks and bypass certain security restrictions. 1) Input passed via the "langcode", "name", and "native" parameters in the languages interface while using the Locale module is not properly sanitised before being displayed to the user. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed. Successful exploitation requires "administer languages" permissions. 2) An error in the handling of certain sessions can be exploited to maintain an open session despite the user being blocked.
FSA638 - wordpress
Paquet:wordpress
Date:2010-03-10
Posté par:Miklos Vajna
Version vulnérable:2.9.1-1
Version non affectée:2.9.2-1locris1
Entrée de suivi des bugs:http://bugs.frugalware.org/task/4131
CVEs:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0682
Description:A vulnerability has been discovered in WordPress, which can be exploited by malicious users to bypass certain security restrictions. The vulnerability is caused due to WordPress not properly restricting access to trashed posts, which can be exploited to e.g. view a trashed post by accessing it's page directly. Successful exploitation requires a valid user account.
FSA637 - xar
Paquet:xar
Date:2010-03-09
Posté par:Miklos Vajna
Version vulnérable:1.5.2-1
Version non affectée:1.5.2-2locris1
Entrée de suivi des bugs:http://bugs.frugalware.org/task/4128
CVEs:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0055
Description:Braden Thomas from Apple has discovered a signature verification bypass issue in xar. The issue is that xar_open assumes that the checksum is stored at offset 0, but xar_signature_copy_signed_data uses xar property "checksum/offset" to find the offset to the checksum when validating the signature. As a result, a modified xar archive can pass signature validation by putting the checksum for the modified TOC at offset 0, pointing "checksum/offset" at the non-modified checksum at a higher offset, and using the original non-modified signature.
© 2003-2010. The Frugalware Developer Team