Frugalware Security Announcements (FSAs)

This is a list of security announcments that have been released for the current stable version of Frugalware

django

  • Author: kikadf
  • Vulnerable: 1.5.2-2arcturus2
  • Unaffected: 1.5.9-1arcturus1

Florian Apolloner discovered that in certain situations, URL reversing could generate scheme-relative URLs which could unexpectedly redirect a user to a different host, leading to phishing attacks. David Wilson reported a file upload denial of service vulnerability. David Greisen discovered that under some circumstances, the use of the RemoteUserMiddleware middleware and the RemoteUserBackend authentication backend could result in one user receiving another user’s session, if a change to the REMOTE_USER header occurred without corresponding logout/login actions. Collin Anderson discovered that it is possible to reveal any field’s data by modifying the popup and to_field parameters of the query string on an admin change form page.

cacti

  • Author: kikadf
  • Vulnerable: 0.8.8b-2arcturus1
  • Unaffected: 0.8.8b-2arcturus2

Multiple security issues (cross-site scripting, missing input sanitising and SQL injection) have been discovered in Cacti, a web interface for graphing of monitoring systems.

CVEs:

php

  • Author: kikadf
  • Vulnerable: 5.3.26-2arcturus4
  • Unaffected: 5.3.26-2arcturus5

It was discovered that the CDF parser of the fileinfo module does not properly process malformed files in the Composite Document File (CDF) format, leading to crashes. It was discovered that PHP incorrectly handled certain SPL Iterators. A local attacker could use this flaw to cause PHP to crash, resulting in a denial of service.

CVEs:

apache

  • Author: kikadf
  • Vulnerable: 2.2.23-3arcturus1
  • Unaffected: 2.2.23-3arcturus2

Marek Kroemeke discovered that the mod_proxy module incorrectly handled certain requests. Giancarlo Pellegrino and Davide Balzarotti discovered that the mod_deflate module incorrectly handled body decompression. Marek Kroemeke and others discovered that the mod_status module incorrectly handled certain requests. Rainer Jung discovered that the mod_cgid module incorrectly handled certain scripts.

CVEs:

drupal6

  • Author: kikadf
  • Vulnerable: 6.32-1arcturus1
  • Unaffected: 6.33-1arcturus1

A denial of service vulnerability was discovered in Drupal, a fully-featured content management framework. A remote attacker could exploit this flaw to cause CPU and memory exhaustion and the site’s database to reach the maximum number of open connections, leading to the site becoming unavailable or unresponsive.

CVEs: