LWN.net Logo

Mageia alert MGASA-2013-0262 (nagstamon)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2013-0262: Updated nagstamon package fixes security vulnerability
Date:  Fri, 30 Aug 2013 19:19:36 +0200
Message-ID:  <20130830171936.C5AC643AD2@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2013-0262 - Updated nagstamon package fixes security vulnerability Publication date: 30 Aug 2013 URL: http://advisories.mageia.org/MGASA-2013-0262.html Type: security Affected Mageia releases: 3 CVE: CVE-2013-4114 Description: A user details information exposure flaw was found in the way Nagstamon performed automated requests to get information about available updates. Remote attackers could use this flaw to obtain user credentials for servers monitored by the desktop status monitor due to their improper (base64 encoding-based) encoding in the HTTP request, when the HTTP Basic authentication scheme was used (CVE-2013-4114). References: - https://bugs.mageia.org/show_bug.cgi?id=10779 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4114 - https://lists.fedoraproject.org/pipermail/package-announc... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4114 SRPMS: - 3/core/nagstamon-0.9.9-1.2.mga3


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds