http://www.mandriva.com/en/
______________________________
Package : zarafa
Date : September 24, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
Updated zarafa packages fix security vulnerabilities:
Robert Scheck reported that Zarafa's WebAccess stored session
information, including login credentials, on-disk in PHP session
files. This session file would contain a user's username and password
to the Zarafa IMAP server (CVE-2014-0103).
Robert Scheck discovered that the Zarafa Collaboration Platform has
multiple incorrect default permissions (CVE-2014-5447, CVE-2014-5448,
CVE-2014-5449, CVE-2014-5450).
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
______________________________
______________
Updated Packages:
Mandriva Business Server 1/X86_64:
b574e9d3829a2083e0ab6f18f0c03d
3428bccf076a0415a5fcd3a8711d95
3008870b6138647ece3e000f36b6e9
e40348366d018a89a729ee4301c957
48d737652190a274fabdcf2f6d2718
6e19f61e06ea0636e6045755721778
dd43d8a343ca593d19c38bfd99b4a9
07caaec38f12734fa485ec5ac58108
8201924f8a2021a34bf74ccfd6ec57
066260bb283e280e1d2674047816b3
e583d4796a6d98723b4f18bca47744
8b41c886437edce1eb583b91a43971
1347c9d77b5ea8a72ddc13cb94ddb3
581ffb74503a3303782a10935ccc27
ee7a4afd5c4d9a13bc63922555c507
415c6fac59aff2dbfbe61087242d1a
1c3d37d1beea23d73b84fd76bce47f
d31a060121669abda9d720f4991094
00d2043f190032f6a624e0721d2924
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą