| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2013-0262: Updated nagstamon package fixes security vulnerability |
| Date: |
| Fri, 30 Aug 2013 19:19:36 +0200 |
| Message-ID: |
| <20130830171936.C5AC643AD2@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2013-0262 - Updated nagstamon package fixes security vulnerability
Publication date: 30 Aug 2013
URL: http://advisories.mageia.org/MGASA-2013-0262.html
Type: security
Affected Mageia releases: 3
CVE: CVE-2013-4114
Description:
A user details information exposure flaw was found in the way Nagstamon
performed automated requests to get information about available updates.
Remote attackers could use this flaw to obtain user credentials for servers
monitored by the desktop status monitor due to their improper (base64
encoding-based) encoding in the HTTP request, when the HTTP Basic
authentication scheme was used (CVE-2013-4114).
References:
- https://bugs.mageia.org/show_bug.cgi?id=10779
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4114
- https://lists.fedoraproject.org/pipermail/package-announc...
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4114
SRPMS:
- 3/core/nagstamon-0.9.9-1.2.mga3
(
Log in to post comments)