[<prev] [next>] [day] [month] [year] [list]
Message-Id: <E1KP1Xc-00059s-W7@titan.mandriva.com>
Date: Fri, 01 Aug 2008 14:48:00 -0600
From: security@...driva.com
To: full-disclosure@...ts.grok.org.uk
Subject: [ MDVSA-2008:160 ] libxslt
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDVSA-2008:160
http://www.mandriva.com/security/
_______________________________________________________________________
Package : libxslt
Date : August 1, 2008
Affected: 2007.1, 2008.0, 2008.1, Corporate 4.0
_______________________________________________________________________
Problem Description:
Chris Evans of the Google Security Team found a vulnerability in the
RC4 processing code in libxslt that did not properly handle corrupted
key information. A remote attacker able to make an application
linked against libxslt process malicious XML input could cause the
application to crash or possibly execute arbitrary code with the
privileges of the application in question (CVE-2008-2935).
The updated packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2935
_______________________________________________________________________
Updated Packages:
Mandriva Linux 2007.1:
9582b6a5a85d8a4fde0be6113565cd9d 2007.1/i586/libxslt1-1.1.20-2.2mdv2007.1.i586.rpm
5205ec749db53b73cbec782d507686df 2007.1/i586/libxslt1-devel-1.1.20-2.2mdv2007.1.i586.rpm
64a810f8ac91b49c80c38e33f2750f85 2007.1/i586/libxslt-proc-1.1.20-2.2mdv2007.1.i586.rpm
bb9f876808ec910122977f7166112245 2007.1/i586/python-libxslt-1.1.20-2.2mdv2007.1.i586.rpm
fa2168576c9baedb55b2577f913fbdec 2007.1/SRPMS/libxslt-1.1.20-2.2mdv2007.1.src.rpm
Mandriva Linux 2007.1/X86_64:
1bd1a4df038c3c4a5b753537854afd17 2007.1/x86_64/lib64xslt1-1.1.20-2.2mdv2007.1.x86_64.rpm
aaecaefb1c25c1838199058ffbec4bf9 2007.1/x86_64/lib64xslt1-devel-1.1.20-2.2mdv2007.1.x86_64.rpm
e39afe30c9f38113fde7e1fd060de05b 2007.1/x86_64/libxslt-proc-1.1.20-2.2mdv2007.1.x86_64.rpm
dfa8806c560c888f225b557622f3e10c 2007.1/x86_64/python-libxslt-1.1.20-2.2mdv2007.1.x86_64.rpm
fa2168576c9baedb55b2577f913fbdec 2007.1/SRPMS/libxslt-1.1.20-2.2mdv2007.1.src.rpm
Mandriva Linux 2008.0:
01d8d7608c3c74e8aa862f79907e07cc 2008.0/i586/libxslt1-1.1.22-2.2mdv2008.0.i586.rpm
4da832fd851d55b48b80341d7c3bc4ee 2008.0/i586/libxslt-devel-1.1.22-2.2mdv2008.0.i586.rpm
58e5f582472d1e28dce386c2bd5d9de4 2008.0/i586/libxslt-proc-1.1.22-2.2mdv2008.0.i586.rpm
74141e240b0e2a3b19790cb9addc0151 2008.0/i586/python-libxslt-1.1.22-2.2mdv2008.0.i586.rpm
85c0d64608fb55944316a2ac46096d13 2008.0/SRPMS/libxslt-1.1.22-2.2mdv2008.0.src.rpm
Mandriva Linux 2008.0/X86_64:
7ff6d48c755e2907846f9a6b6378b5b9 2008.0/x86_64/lib64xslt1-1.1.22-2.2mdv2008.0.x86_64.rpm
f026cc563722e6847d58b0e1e6f0f6ce 2008.0/x86_64/lib64xslt-devel-1.1.22-2.2mdv2008.0.x86_64.rpm
bc530cb61a211a50155c59c52de543c3 2008.0/x86_64/libxslt-proc-1.1.22-2.2mdv2008.0.x86_64.rpm
458c1d9d588b4a3a435eb26dcf23e2f5 2008.0/x86_64/python-libxslt-1.1.22-2.2mdv2008.0.x86_64.rpm
85c0d64608fb55944316a2ac46096d13 2008.0/SRPMS/libxslt-1.1.22-2.2mdv2008.0.src.rpm
Mandriva Linux 2008.1:
c8cab87e462864b9d575613630500965 2008.1/i586/libxslt1-1.1.22-2.2mdv2008.1.i586.rpm
2fb2120f868e093a73c766537eca4c4c 2008.1/i586/libxslt-devel-1.1.22-2.2mdv2008.1.i586.rpm
c9322ae81ff3e2bcbadef36a1d3f29ec 2008.1/i586/libxslt-proc-1.1.22-2.2mdv2008.1.i586.rpm
fa11c933fa71ffe7dffd869454809523 2008.1/i586/python-libxslt-1.1.22-2.2mdv2008.1.i586.rpm
126fa9767b486afdddd09ead4b9f5841 2008.1/SRPMS/libxslt-1.1.22-2.2mdv2008.1.src.rpm
Mandriva Linux 2008.1/X86_64:
d7eeca6bfa273ff8d3995144272825e8 2008.1/x86_64/lib64xslt1-1.1.22-2.2mdv2008.1.x86_64.rpm
cf74a4e8440e324e776d00162784da57 2008.1/x86_64/lib64xslt-devel-1.1.22-2.2mdv2008.1.x86_64.rpm
b6ff1bbf9fc5c56421b4cd2c60515c21 2008.1/x86_64/libxslt-proc-1.1.22-2.2mdv2008.1.x86_64.rpm
9507d84c1b2338ac8a06a76efd9cd94d 2008.1/x86_64/python-libxslt-1.1.22-2.2mdv2008.1.x86_64.rpm
126fa9767b486afdddd09ead4b9f5841 2008.1/SRPMS/libxslt-1.1.22-2.2mdv2008.1.src.rpm
Corporate 4.0:
6fddddda1818a68ea24d52e6e181f095 corporate/4.0/i586/libxslt1-1.1.15-1.2.20060mlcs4.i586.rpm
1679fdbdfb7020be4622fae157a2a2b5 corporate/4.0/i586/libxslt1-devel-1.1.15-1.2.20060mlcs4.i586.rpm
3a030cdd0fbadaf26b4871d371fe6f54 corporate/4.0/i586/libxslt-proc-1.1.15-1.2.20060mlcs4.i586.rpm
ecaa9e0beff76328b236a87870274b1d corporate/4.0/i586/libxslt-python-1.1.15-1.2.20060mlcs4.i586.rpm
bf4154eaf3cff4b487a71c9f9edcb60c corporate/4.0/SRPMS/libxslt-1.1.15-1.2.20060mlcs4.src.rpm
Corporate 4.0/X86_64:
953ce3b7b6f9f5be7c2a24d2aef92bbe corporate/4.0/x86_64/lib64xslt1-1.1.15-1.2.20060mlcs4.x86_64.rpm
4ae0c85ebc4d13552b6db13a2067dea4 corporate/4.0/x86_64/lib64xslt1-devel-1.1.15-1.2.20060mlcs4.x86_64.rpm
65d3b3a21d5165b0eb256db4c57d946d corporate/4.0/x86_64/libxslt-proc-1.1.15-1.2.20060mlcs4.x86_64.rpm
645272c4f3c51b3e28a19ff14be17a36 corporate/4.0/x86_64/libxslt-python-1.1.15-1.2.20060mlcs4.x86_64.rpm
bf4154eaf3cff4b487a71c9f9edcb60c corporate/4.0/SRPMS/libxslt-1.1.15-1.2.20060mlcs4.src.rpm
_______________________________________________________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/security/advisories
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iD8DBQFIk0h+mqjQ0CJFipgRAh4bAJ0ZFnPrAmi0ZCs+VmIS3FNbrVq6BQCgmZDa
daQ2pWT0o/xjJuwNSVBtcSI=
=YYmK
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists