| [Security Announce] [ MDVSA-2009:074 ] libneon0.27 |
|
|
|
| Écrit par Administrator |
| Jeudi, 12 Mars 2009 13:49 |
|
_______________________________________________________________________ Mandriva Linux Security Advisory MDVSA-2009:074 http://www.mandriva.com/security/ _______________________________________________________________________ Package : libneon0.27 Date : March 10, 2009 Affected: 2008.1 _______________________________________________________________________ Problem Description: A security vulnerability has been identified and fixed in neon: neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication and Digest domain parameter support (CVE-2008-3746). The updated packages have been upgraded to version 0.28.3 to prevent this. _______________________________________________________________________ References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3746 _______________________________________________________________________ Updated Packages: Mandriva Linux 2008.1: beb5301d9902f1a4d6bb3cab6784b732 2008.1/i586/libneon0.27-0.28.3-0.1mdv2008.1.i586.rpm
Mandriva Linux 2008.1/X86_64: a7091162b22e4cc4867ff14c2e1e148b 2008.1/x86_64/lib64neon0.27-0.28.3-0.1mdv2008.1.x86_64.rpm To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/security/advisories If you want to report vulnerabilities, please contact |



























































