LWN.net Logo

Mageia alert MGASA-2013-0002 (jetty)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2013-0002: jetty-6.1.26-14.1.mga2 (2/core)
Date:  Sat, 5 Jan 2013 19:35:43 +0100
Message-ID:  <20130105183543.GA17622@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2013-0002 Date: January 5th, 2013 Affected releases: 2 Description: Updated jetty packages fix security vulnerability: Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters (CVE-2011-4461). Updated Packages: jetty-6.1.26-14.1.mga2 jetty-javadoc-6.1.26-14.1.mga2 jetty-manual-6.1.26-14.1.mga2 jetty-maven-plugins-6.1.26-14.1.mga2 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4461 http://lists.fedoraproject.org/pipermail/package-announce... https://bugs.mageia.org/show_bug.cgi?id=8465 https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds