Vissza a www.andrews.hu-ra

    [guru] Gentoo biztonsagi frissitesek


    DATE: Tue, 17 Jan 2012 15:39:51 +0100
    Több biztonsági hibát (köztük PHP kód futtatást is lehetővé tevőt) találtak a
    phpMyAdmin csomagban.
    
    Több biztonsági hibát (köztük kód futtatásit is lehetővé tevőt) találtak a
    MySQL csomagban.
    
    Több biztonsági hibát találtak a Chromium és V8 csomagokban.
    
    
    --- Begin Message ---
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory                           GLSA 201201-01
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    
     Severity: High
        Title: phpMyAdmin: Multiple vulnerabilities
         Date: January 04, 2012
         Bugs: #302745, #335490, #336462, #354227, #373951, #376369,
               #387413, #389427, #395715
           ID: 201201-01
    
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    
    Synopsis
    ========
    
    Multiple vulnerabilities were found in phpMyAdmin, the most severe of
    which allows the execution of arbitrary PHP code.
    
    Background
    ==========
    
    phpMyAdmin is a web-based management tool for MySQL databases.
    
    Affected packages
    =================
    
        -------------------------------------------------------------------
         Package              /     Vulnerable     /            Unaffected
        -------------------------------------------------------------------
      1  dev-db/phpmyadmin            < 3.4.9                    >= 3.4.9
    
    Description
    ===========
    
    Multiple vulnerabilities have been discovered in phpMyAdmin. Please
    review the CVE identifiers and phpMyAdmin Security Advisories
    referenced below for details.
    
    Impact
    ======
    
    Remote attackers might be able to insert and execute PHP code, include
    and execute local PHP files, or perform Cross-Site Scripting (XSS)
    attacks via various vectors.
    
    Workaround
    ==========
    
    There is no known workaround at this time.
    
    Resolution
    ==========
    
    All phpMyAdmin users should upgrade to the latest version:
    
      # emerge --sync
      # emerge --ask --oneshot --verbose ">=dev-db/phpmyadmin-3.4.9"
    
    References
    ==========
    
    [  1 ] CVE-2008-7251
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7251
    [  2 ] CVE-2008-7252
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7252
    [  3 ] CVE-2010-2958
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2958
    [  4 ] CVE-2010-3055
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3055
    [  5 ] CVE-2010-3056
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3056
    [  6 ] CVE-2010-3263
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3263
    [  7 ] CVE-2011-0986
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0986
    [  8 ] CVE-2011-0987
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0987
    [  9 ] CVE-2011-2505
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2505
    [ 10 ] CVE-2011-2506
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2506
    [ 11 ] CVE-2011-2507
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2507
    [ 12 ] CVE-2011-2508
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2508
    [ 13 ] CVE-2011-2642
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2642
    [ 14 ] CVE-2011-2643
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2643
    [ 15 ] CVE-2011-2718
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2718
    [ 16 ] CVE-2011-2719
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2719
    [ 17 ] CVE-2011-3646
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3646
    [ 18 ] CVE-2011-4064
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4064
    [ 19 ] CVE-2011-4107
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4107
    [ 20 ] CVE-2011-4634
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4634
    [ 21 ] CVE-2011-4780
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4780
    [ 22 ] CVE-2011-4782
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4782
    [ 23 ] PMASA-2010-1
           http://www.phpmyadmin.net/home_page/security/PMASA-2010-1.php
    [ 24 ] PMASA-2010-2
           http://www.phpmyadmin.net/home_page/security/PMASA-2010-2.php
    [ 25 ] PMASA-2010-4
           http://www.phpmyadmin.net/home_page/security/PMASA-2010-4.php
    [ 26 ] PMASA-2010-5
           http://www.phpmyadmin.net/home_page/security/PMASA-2010-5.php
    [ 27 ] PMASA-2010-6
           http://www.phpmyadmin.net/home_page/security/PMASA-2010-6.php
    [ 28 ] PMASA-2010-7
           http://www.phpmyadmin.net/home_page/security/PMASA-2010-7.php
    [ 29 ] PMASA-2011-1
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-1.php
    [ 30 ] PMASA-2011-10
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-10.php
    [ 31 ] PMASA-2011-11
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-11.php
    [ 32 ] PMASA-2011-12
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-12.php
    [ 33 ] PMASA-2011-15
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-15.php
    [ 34 ] PMASA-2011-16
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-16.php
    [ 35 ] PMASA-2011-17
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-17.php
    [ 36 ] PMASA-2011-18
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-18.php
    [ 37 ] PMASA-2011-19
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-19.php
    [ 38 ] PMASA-2011-2
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-2.php
    [ 39 ] PMASA-2011-20
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-20.php
    [ 40 ] PMASA-2011-5
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-5.php
    [ 41 ] PMASA-2011-6
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-6.php
    [ 42 ] PMASA-2011-7
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-7.php
    [ 43 ] PMASA-2011-8
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-8.php
    [ 44 ] PMASA-2011-9
           http://www.phpmyadmin.net/home_page/security/PMASA-2011-9.php
    
    Availability
    ============
    
    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:
    
     http://security.gentoo.org/glsa/glsa-201201-01.xml
    
    Concerns?
    =========
    
    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    https://bugs.gentoo.org.
    
    License
    =======
    
    Copyright 2012 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).
    
    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.
    
    http://creativecommons.org/licenses/by-sa/2.5
    
    
    

    Attachment: signature.asc
    Description: OpenPGP digital signature


    --- End Message ---
    --- Begin Message ---
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory                           GLSA 201201-02
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    
     Severity: High
        Title: MySQL: Multiple vulnerabilities
         Date: January 05, 2012
         Bugs: #220813, #229329, #237166, #238117, #240407, #277717,
               #294187, #303747, #319489, #321791, #339717, #344987, #351413
           ID: 201201-02
    
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    
    Synopsis
    ========
    
    Multiple vulnerabilities were found in MySQL, some of which may allow
    execution of arbitrary code.
    
    Background
    ==========
    
    MySQL is a popular open-source multi-threaded, multi-user SQL database
    server.
    
    Affected packages
    =================
    
        -------------------------------------------------------------------
         Package              /     Vulnerable     /            Unaffected
        -------------------------------------------------------------------
      1  dev-db/mysql                 < 5.1.56                  >= 5.1.56
    
    Description
    ===========
    
    Multiple vulnerabilities have been discovered in MySQL. Please review
    the CVE identifiers referenced below for details.
    
    Impact
    ======
    
    An unauthenticated remote attacker may be able to execute arbitrary
    code with the privileges of the MySQL process, cause a Denial of
    Service condition, bypass security restrictions, uninstall arbitrary
    MySQL plugins, or conduct Man-in-the-Middle and Cross-Site Scripting
    attacks.
    
    Workaround
    ==========
    
    There is no known workaround at this time.
    
    Resolution
    ==========
    
    All MySQL users should upgrade to the latest version:
    
      # emerge --sync
      # emerge --ask --oneshot --verbose ">=dev-db/mysql-5.1.56"
    
    NOTE: This is a legacy GLSA. Updates for all affected architectures are
    available since May 14, 2011. It is likely that your system is already
    no longer affected by this issue.
    
    References
    ==========
    
    [  1 ] CVE-2008-3963
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3963
    [  2 ] CVE-2008-4097
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4097
    [  3 ] CVE-2008-4098
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4098
    [  4 ] CVE-2008-4456
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4456
    [  5 ] CVE-2008-7247
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-7247
    [  6 ] CVE-2009-2446
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2446
    [  7 ] CVE-2009-4019
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4019
    [  8 ] CVE-2009-4028
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4028
    [  9 ] CVE-2009-4484
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4484
    [ 10 ] CVE-2010-1621
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1621
    [ 11 ] CVE-2010-1626
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1626
    [ 12 ] CVE-2010-1848
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1848
    [ 13 ] CVE-2010-1849
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1849
    [ 14 ] CVE-2010-1850
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1850
    [ 15 ] CVE-2010-2008
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2008
    [ 16 ] CVE-2010-3676
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3676
    [ 17 ] CVE-2010-3677
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3677
    [ 18 ] CVE-2010-3678
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3678
    [ 19 ] CVE-2010-3679
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3679
    [ 20 ] CVE-2010-3680
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3680
    [ 21 ] CVE-2010-3681
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3681
    [ 22 ] CVE-2010-3682
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3682
    [ 23 ] CVE-2010-3683
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3683
    [ 24 ] CVE-2010-3833
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3833
    [ 25 ] CVE-2010-3834
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3834
    [ 26 ] CVE-2010-3835
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3835
    [ 27 ] CVE-2010-3836
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3836
    [ 28 ] CVE-2010-3837
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3837
    [ 29 ] CVE-2010-3838
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3838
    [ 30 ] CVE-2010-3839
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3839
    [ 31 ] CVE-2010-3840
           http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3840
    
    Availability
    ============
    
    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:
    
     http://security.gentoo.org/glsa/glsa-201201-02.xml
    
    Concerns?
    =========
    
    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    https://bugs.gentoo.org.
    
    License
    =======
    
    Copyright 2012 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).
    
    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.
    
    http://creativecommons.org/licenses/by-sa/2.5
    
    
    

    Attachment: signature.asc
    Description: OpenPGP digital signature


    --- End Message ---
    --- Begin Message ---
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory                           GLSA 201201-03
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    
     Severity: Normal
        Title: Chromium, V8: Multiple vulnerabilities
         Date: January 08, 2012
         Bugs: #394587, #397907
           ID: 201201-03
    
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    
    Synopsis
    ========
    
    Multiple vulnerabilities have been reported in Chromium and V8, some of
    which may allow execution of arbitrary code.
    
    Background
    ==========
    
    Chromium is an open source web browser project. V8 is Google's open
    source JavaScript engine.
    
    Affected packages
    =================
    
        -------------------------------------------------------------------
         Package              /     Vulnerable     /            Unaffected
        -------------------------------------------------------------------
      1  www-client/chromium       < 16.0.912.75           >= 16.0.912.75
      2  dev-lang/v8                 < 3.6.6.11               >= 3.6.6.11
        -------------------------------------------------------------------
         2 affected packages
        -------------------------------------------------------------------
    
    Description
    ===========
    
    Multiple vulnerabilities have been discovered in Chromium and V8.
    Please review the CVE identifiers and release notes referenced below
    for details.
    
    Impact
    ======
    
    A context-dependent attacker could entice a user to open a specially
    crafted web site or JavaScript program using Chromium or V8, possibly
    resulting in the execution of arbitrary code with the privileges of the
    process, or a Denial of Service condition.
    
    The attacker could also perform URL bar spoofing.
    
    Workaround
    ==========
    
    There is no known workaround at this time.
    
    Resolution
    ==========
    
    All Chromium users should upgrade to the latest version:
    
      # emerge --sync
      # emerge --ask --oneshot -v ">=www-client/chromium-16.0.912.75"
    
    All V8 users should upgrade to the latest version:
    
      # emerge --sync
      # emerge --ask --oneshot --verbose ">=dev-lang/v8-3.6.6.11"
    
    References
    ==========
    
    [  1 ] CVE-2011-3903
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3903
    [  2 ] CVE-2011-3904
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3904
    [  3 ] CVE-2011-3906
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3906
    [  4 ] CVE-2011-3907
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3907
    [  5 ] CVE-2011-3908
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3908
    [  6 ] CVE-2011-3909
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3909
    [  7 ] CVE-2011-3910
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3910
    [  8 ] CVE-2011-3912
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3912
    [  9 ] CVE-2011-3913
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3913
    [ 10 ] CVE-2011-3914
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3914
    [ 11 ] CVE-2011-3917
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3917
    [ 12 ] CVE-2011-3921
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3921
    [ 13 ] CVE-2011-3922
           http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3922
    [ 14 ] Release Notes 16.0.912.63
    
    http://googlechromereleases.blogspot.com/2011/12/stable-channel-update.html
    [ 15 ] Release Notes 16.0.912.75
    
    http://googlechromereleases.blogspot.com/2012/01/stable-channel-update.html
    
    Availability
    ============
    
    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:
    
     http://security.gentoo.org/glsa/glsa-201201-03.xml
    
    Concerns?
    =========
    
    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    https://bugs.gentoo.org.
    
    License
    =======
    
    Copyright 2012 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).
    
    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.
    
    http://creativecommons.org/licenses/by-sa/2.5
    
    
    

    Attachment: signature.asc
    Description: OpenPGP digital signature


    --- End Message ---

    Vissza a www.andrews.hu-ra