Mageia alert MGASA-2012-0277 (ganglia)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2012-0277: ganglia-3.1.7-5.1.mga1 (1/core), ganglia-3.1.7-7.1.mga2 (2/core) | |
Date: | Sun, 30 Sep 2012 21:14:42 +0200 | |
Message-ID: | <20120930191442.GA3639@valstar.mageia.org> |
MGASA-2012-0277 Date: September 30th, 2012 Affected releases: 1, 2 Description: Updated ganglia packages fix security vulnerability: There is a security issue in Ganglia Web going back to at least 3.1.7 which can lead to arbitrary script being executed with web user privileges possibly leading to a machine compromise. Additionally, an issue where active NFS mounts caused gmond to not start has also been corrected. Updated Packages: Mageia 1: ganglia-core-3.1.7-5.1.mga1 ganglia-gmetad-3.1.7-5.1.mga1 ganglia-script-3.1.7-5.1.mga1 ganglia-webfrontend-3.1.7-5.1.mga1 lib(64)ganglia1-3.1.7-5.1.mga1 lib(64)ganglia1-devel-3.1.7-5.1.mga1 Mageia 2: ganglia-core-3.1.7-7.1.mga2 ganglia-gmetad-3.1.7-7.1.mga2 ganglia-script-3.1.7-7.1.mga2 ganglia-webfrontend-3.1.7-7.1.mga2 lib(64)ganglia1-3.1.7-7.1.mga2 lib(64)ganglia1-devel-3.1.7-7.1.mga2 References: http://ganglia.info/?p=549 https://bugs.launchpad.net/ubuntu/+source/ganglia/+bug/91... http://lists.fedoraproject.org/pipermail/package-announce... https://bugs.mageia.org/show_bug.cgi?id=6874 https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...