| From: |
| opensuse-security@opensuse.org |
| To: |
| opensuse-updates@opensuse.org |
| Subject: |
| openSUSE-SU-2013:0143-1: moderate: libqt4: security fixes for XMLHttpRequest redirect and ssl compression |
| Date: |
| Wed, 23 Jan 2013 14:05:31 +0100 (CET) |
| Message-ID: |
| <20130123130531.93CC5321CD@maintenance.suse.de> |
| Archive-link: |
| Article, Thread
|
openSUSE Security Update: libqt4: security fixes for XMLHttpRequest redirect and ssl
compression
______________________________________________________________________________
Announcement ID: openSUSE-SU-2013:0143-1
Rating: moderate
References: #793194
Cross-References: CVE-2012-4929 CVE-2012-5624
Affected Products:
openSUSE 11.4/standard/i586/patchinfo.38
______________________________________________________________________________
An update that fixes two vulnerabilities is now available.
Description:
libqt4 received security fixes for:
- XMLHttpRequest could redirect to a file: URL
(CVE-2012-5624, bnc#793194)
- Disable SSL compression by default to mitigate CRIME
attack (CVE-2012-4929)
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 11.4/standard/i586/patchinfo.38:
zypper in -t patch 2013-6
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 11.4/standard/i586/patchinfo.38 (i586 x86_64):
libQtWebKit-devel-4.7.1-8.63.1
libQtWebKit4-4.7.1-8.63.1
libQtWebKit4-debuginfo-4.7.1-8.63.1
libqt4-4.7.1-8.63.1
libqt4-debuginfo-4.7.1-8.63.1
libqt4-debugsource-4.7.1-8.63.1
libqt4-devel-4.7.1-8.63.1
libqt4-devel-debuginfo-4.7.1-8.63.1
libqt4-qt3support-4.7.1-8.63.1
libqt4-qt3support-debuginfo-4.7.1-8.63.1
libqt4-sql-4.7.1-8.63.1
libqt4-sql-debuginfo-4.7.1-8.63.1
libqt4-sql-sqlite-4.7.1-8.63.1
libqt4-sql-sqlite-debuginfo-4.7.1-8.63.1
libqt4-x11-4.7.1-8.63.1
libqt4-x11-debuginfo-4.7.1-8.63.1
- openSUSE 11.4/standard/i586/patchinfo.38 (x86_64):
libQtWebKit4-32bit-4.7.1-8.63.1
libQtWebKit4-debuginfo-32bit-4.7.1-8.63.1
libqt4-32bit-4.7.1-8.63.1
libqt4-debuginfo-32bit-4.7.1-8.63.1
libqt4-qt3support-32bit-4.7.1-8.63.1
libqt4-qt3support-debuginfo-32bit-4.7.1-8.63.1
libqt4-sql-32bit-4.7.1-8.63.1
libqt4-sql-debuginfo-32bit-4.7.1-8.63.1
libqt4-sql-sqlite-32bit-4.7.1-8.63.1
libqt4-sql-sqlite-debuginfo-32bit-4.7.1-8.63.1
libqt4-x11-32bit-4.7.1-8.63.1
libqt4-x11-debuginfo-32bit-4.7.1-8.63.1
- openSUSE 11.4/standard/i586/patchinfo.38 (ia64):
libQtWebKit4-debuginfo-x86-4.7.1-8.63.1
libQtWebKit4-x86-4.7.1-8.63.1
libqt4-debuginfo-x86-4.7.1-8.63.1
libqt4-qt3support-debuginfo-x86-4.7.1-8.63.1
libqt4-qt3support-x86-4.7.1-8.63.1
libqt4-sql-debuginfo-x86-4.7.1-8.63.1
libqt4-sql-sqlite-debuginfo-x86-4.7.1-8.63.1
libqt4-sql-sqlite-x86-4.7.1-8.63.1
libqt4-sql-x86-4.7.1-8.63.1
libqt4-x11-debuginfo-x86-4.7.1-8.63.1
libqt4-x11-x86-4.7.1-8.63.1
libqt4-x86-4.7.1-8.63.1
References:
http://support.novell.com/security/cve/CVE-2012-4929.html
http://support.novell.com/security/cve/CVE-2012-5624.html
https://bugzilla.novell.com/793194
(
Log in to post comments)