| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2012-0127:
perl-Config-IniFiles-2.760.0-1.mga (1,2/core) |
| Date: |
| Wed, 27 Jun 2012 14:15:38 +0200 |
| Message-ID: |
| <20120627121538.GA3211@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2012-0127
Date: June 27th, 2012
Affected releases: 1, 2
Description:
Updated perl-Config-IniFiles package fixes security vulnerability:
perl-Config-IniFiles used a predicatable temporary file name
(${filename}-new) which makes it prone to a symlink attack. If a
malicious user were to create a symlink pointing to another file
writable by the user running an application that used
perl-Config-IniFiles, they could overwrite the contents of that
file (CVE-2012-2451).
Updated Packages:
Mageia 1:
perl-Config-IniFiles-2.760.0-1.mga1
Mageia 2:
perl-Config-IniFiles-2.760.0-1.mga2
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2451
https://bugzilla.redhat.com/show_bug.cgi?id=818386
http://lists.fedoraproject.org/pipermail/package-announce...
https://bugs.mageia.org/show_bug.cgi?id=6024
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...
(
Log in to post comments)