| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2012-0277: ganglia-3.1.7-5.1.mga1
(1/core), ganglia-3.1.7-7.1.mga2 (2/core) |
| Date: |
| Sun, 30 Sep 2012 21:14:42 +0200 |
| Message-ID: |
| <20120930191442.GA3639@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2012-0277
Date: September 30th, 2012
Affected releases: 1, 2
Description:
Updated ganglia packages fix security vulnerability:
There is a security issue in Ganglia Web going back to at least 3.1.7
which can lead to arbitrary script being executed with web user
privileges possibly leading to a machine compromise.
Additionally, an issue where active NFS mounts caused gmond to not
start has also been corrected.
Updated Packages:
Mageia 1:
ganglia-core-3.1.7-5.1.mga1
ganglia-gmetad-3.1.7-5.1.mga1
ganglia-script-3.1.7-5.1.mga1
ganglia-webfrontend-3.1.7-5.1.mga1
lib(64)ganglia1-3.1.7-5.1.mga1
lib(64)ganglia1-devel-3.1.7-5.1.mga1
Mageia 2:
ganglia-core-3.1.7-7.1.mga2
ganglia-gmetad-3.1.7-7.1.mga2
ganglia-script-3.1.7-7.1.mga2
ganglia-webfrontend-3.1.7-7.1.mga2
lib(64)ganglia1-3.1.7-7.1.mga2
lib(64)ganglia1-devel-3.1.7-7.1.mga2
References:
http://ganglia.info/?p=549
https://bugs.launchpad.net/ubuntu/+source/ganglia/+bug/91...
http://lists.fedoraproject.org/pipermail/package-announce...
https://bugs.mageia.org/show_bug.cgi?id=6874
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...
(
Log in to post comments)