Segurunça Mandriva http://www.mandriva.com/br/support/security/advisories Alertas de segurança Mandriva pt-br MDVSA-2012:016: glpi http://www.mandriva.com/br/support/security/advisories?name=MDVSA-2012:016 A File Inclusion vulnerability was discovered and corrected in<br /> GLPI. This advisory provides the latest version of GLPI (0.80.7)<br /> that is not vulnerable to this issue. MDVA-2012:016: mysql http://www.mandriva.com/br/support/security/advisories?name=MDVA-2012:016 This is a maintenance and bugfix release that upgrades mysql to the<br /> latest 5.5 version which solves numerous upstream bugs.<br /> <br /> The updated packages have been upgraded to mysql 5.5.20. MDVSA-2012:015: wireshark http://www.mandriva.com/br/support/security/advisories?name=MDVSA-2012:015 Multiple file parser and NULL pointer vulnerabilities including a<br /> RLC dissector buffer overflow was found and corrected in Wireshark.<br /> <br /> This advisory provides the latest version of Wireshark (1.6.5 )<br /> which is not vulnerable to these issues. MDVA-2012:015: dkms http://www.mandriva.com/br/support/security/advisories?name=MDVA-2012:015 The dkms package was still requiring the kernel-devel-latest<br /> package. But since kernel 2.6.39, this latest package is no more used.<br /> <br /> This new release removes this old requirement and the dkms package<br /> simply requires kernel-devel package now. MDVA-2012:014: firefox http://www.mandriva.com/br/support/security/advisories?name=MDVA-2012:014 This is a maintenance and bugfix release for firefox 10.0 which<br /> utilizes slightlty better compilation optimizarions and fixes a<br /> problem with an empty printer list on Mandriva Linux 2011 (#65237). MDVSA-2012:014: glpi http://www.mandriva.com/br/support/security/advisories?name=MDVSA-2012:014 A vulnerability has been found and corrected in GLPI:<br /> <br /> The autocompletion functionality in GLPI before 0.80.2 does not<br /> blacklist certain username and password fields, which allows remote<br /> attackers to obtain sensitive information via a crafted POST request<br /> (CVE-2011-2720).<br /> <br /> This advisory provides the latest version of GLPI (0.80.6) which are<br /> not vulnerable to this issue. Additionally the latest versions of<br /> the corresponding plugins are also being provided. MDVA-2012:013: kdepim4-runtime http://www.mandriva.com/br/support/security/advisories?name=MDVA-2012:013 This fix remove rarely used akonadi icon from systray. MDVA-2012:012: kdegraphics4 http://www.mandriva.com/br/support/security/advisories?name=MDVA-2012:012 Okular currently has two menu entries, one on the Graphics section and<br /> other in the Office section. This update, removes the okular from the<br /> Graphic menu section entry, cleaning up the menu and avoid confusion. MDVA-2012:011: qt4 http://www.mandriva.com/br/support/security/advisories?name=MDVA-2012:011 The current Mandriva 2011 Qt4 4.7.4 packages don&#039;t package qt4<br /> private-headers needed for qt-creator update. This update adds<br /> this missing package so other updates that requires it can be done<br /> in future. MDVA-2012:010: libmsn http://www.mandriva.com/br/support/security/advisories?name=MDVA-2012:010 The include xmlParser.h is missing in default libmsn-devel<br /> installation, this causes trouble wen building other kde packages. This<br /> update adds this missing include.