Mandriva Security http://www.mandriva.com/en/support/security/advisories Mandriva security advisories en-us MDVSA-2012:079: sudo http://www.mandriva.com/en/support/security/advisories?name=MDVSA-2012:079 A vulnerability has been found and corrected in sudo:<br /> <br /> A flaw exists in the IP network matching code in sudo versions 1.6.9p3<br /> through 1.8.4p4 that may result in the local host being matched<br /> even though it is not actually part of the network described by the<br /> IP address and associated netmask listed in the sudoers file or in<br /> LDAP. As a result, users authorized to run commands on certain IP<br /> networks may be able to run commands on hosts that belong to other<br /> networks not explicitly listed in sudoers (CVE-2012-2337<br /> <br /> The updated packages have been patched to correct this issue. MDVSA-2012:078: imagemagick http://www.mandriva.com/en/support/security/advisories?name=MDVSA-2012:078 Multiple vulnerabilities has been found and corrected in imagemagick:<br /> <br /> A flaw was found in the way ImageMagick processed images with malformed<br /> Exchangeable image file format (Exif) metadata. An attacker could<br /> create a specially-crafted image file that, when opened by a victim,<br /> would cause ImageMagick to crash or, potentially, execute arbitrary<br /> code (CVE-2012-0247).<br /> <br /> A denial of service flaw was found in the way ImageMagick processed<br /> images with malformed Exif metadata. An attacker could create a<br /> specially-crafted image file that, when opened by a victim, could<br /> cause ImageMagick to enter an infinite loop (CVE-2012-0248).<br /> <br /> The original fix for CVE-2012-0247 failed to check for the possibility<br /> of an integer overflow when computing the sum of number_bytes and<br /> offset. This resulted in a wrap around into a value smaller than<br /> length, making original CVE-2012-0247 introduced length check still<br /> to be possible to bypass, leading to memory corruption (CVE-2012-1185).<br /> <br /> An integer overflow flaw was found in the way ImageMagick processed<br /> certain Exif tags with a large components count. An attacker<br /> could create a specially-crafted image file that, when opened by a<br /> victim, could cause ImageMagick to access invalid memory and crash<br /> (CVE-2012-0259).<br /> <br /> A denial of service flaw was found in the way ImageMagick decoded<br /> certain JPEG images. A remote attacker could provide a JPEG image with<br /> specially-crafted sequences of RST0 up to RST7 restart markers (used<br /> to indicate the input stream to be corrupted), which once processed<br /> by ImageMagick, would cause it to consume excessive amounts of memory<br /> and CPU time (CVE-2012-0260).<br /> <br /> An out-of-bounds buffer read flaw was found in the way ImageMagick<br /> processed certain TIFF image files. A remote attacker could provide<br /> a TIFF image with a specially-crafted Exif IFD value (the set of tags<br /> for recording Exif-specific attribute information), which once opened<br /> by ImageMagick, would cause it to crash (CVE-2012-1798).<br /> <br /> The updated packages have been patched to correct these issues. MDVSA-2012:077: imagemagick http://www.mandriva.com/en/support/security/advisories?name=MDVSA-2012:077 Multiple vulnerabilities has been found and corrected in imagemagick:<br /> <br /> Untrusted search path vulnerability in configure.c in ImageMagick<br /> before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows<br /> local users to gain privileges via a Trojan horse configuration file<br /> in the current working directory (CVE-2010-4167).<br /> <br /> A flaw was found in the way ImageMagick processed images with malformed<br /> Exchangeable image file format (Exif) metadata. An attacker could<br /> create a specially-crafted image file that, when opened by a victim,<br /> would cause ImageMagick to crash or, potentially, execute arbitrary<br /> code (CVE-2012-0247).<br /> <br /> A denial of service flaw was found in the way ImageMagick processed<br /> images with malformed Exif metadata. An attacker could create a<br /> specially-crafted image file that, when opened by a victim, could<br /> cause ImageMagick to enter an infinite loop (CVE-2012-0248).<br /> <br /> The original fix for CVE-2012-0247 failed to check for the possibility<br /> of an integer overflow when computing the sum of number_bytes and<br /> offset. This resulted in a wrap around into a value smaller than<br /> length, making original CVE-2012-0247 introduced length check still<br /> to be possible to bypass, leading to memory corruption (CVE-2012-1185).<br /> <br /> An integer overflow flaw was found in the way ImageMagick processed<br /> certain Exif tags with a large components count. An attacker<br /> could create a specially-crafted image file that, when opened by a<br /> victim, could cause ImageMagick to access invalid memory and crash<br /> (CVE-2012-0259).<br /> <br /> A denial of service flaw was found in the way ImageMagick decoded<br /> certain JPEG images. A remote attacker could provide a JPEG image with<br /> specially-crafted sequences of RST0 up to RST7 restart markers (used<br /> to indicate the input stream to be corrupted), which once processed<br /> by ImageMagick, would cause it to consume excessive amounts of memory<br /> and CPU time (CVE-2012-0260).<br /> <br /> An out-of-bounds buffer read flaw was found in the way ImageMagick<br /> processed certain TIFF image files. A remote attacker could provide<br /> a TIFF image with a specially-crafted Exif IFD value (the set of tags<br /> for recording Exif-specific attribute information), which once opened<br /> by ImageMagick, would cause it to crash (CVE-2012-1798).<br /> <br /> The updated packages have been patched to correct these issues. MDVSA-2012:076: ffmpeg http://www.mandriva.com/en/support/security/advisories?name=MDVSA-2012:076 Multiple vulnerabilities has been found and corrected in ffmpeg:<br /> <br /> The Matroska format decoder in FFmpeg does not properly allocate<br /> memory, which allows remote attackers to execute arbitrary code via<br /> a crafted file (CVE-2011-3362, CVE-2011-3504).<br /> <br /> cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause<br /> a denial of service (incorrect write operation and application<br /> crash) via an invalid bitstream in a Chinese AVS video (aka CAVS)<br /> file, related to the decode_residual_block, check_for_slice,<br /> and cavs_decode_frame functions, a different vulnerability than<br /> CVE-2011-3362 (CVE-2011-3973).<br /> <br /> Integer signedness error in the decode_residual_inter function in<br /> cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a<br /> denial of service (incorrect write operation and application crash)<br /> via an invalid bitstream in a Chinese AVS video (aka CAVS) file,<br /> a different vulnerability than CVE-2011-3362 (CVE-2011-3974).<br /> <br /> Double free vulnerability in the Theora decoder in FFmpeg allows remote<br /> attackers to cause a denial of service or possibly have unspecified<br /> other impact via a crafted stream (CVE-2011-3892).<br /> <br /> FFmpeg does not properly implement the MKV and Vorbis media<br /> handlers, which allows remote attackers to cause a denial of service<br /> (out-of-bounds read) via unspecified vectors (CVE-2011-3893).<br /> <br /> Heap-based buffer overflow in the Vorbis decoder in FFmpeg allows<br /> remote attackers to cause a denial of service or possibly have<br /> unspecified other impact via a crafted stream (CVE-2011-3895).<br /> <br /> An error within the QDM2 decoder (libavcodec/qdm2.c) can be exploited<br /> to cause a buffer overflow (CVE-2011-4351).<br /> <br /> An integer overflow error within the &quot;vp3_dequant()&quot; function<br /> (libavcodec/vp3.c) can be exploited to cause a buffer overflow<br /> (CVE-2011-4352).<br /> <br /> Errors within the &quot;av_image_fill_pointers()&quot;, the &quot;vp5_parse_coeff()&quot;,<br /> and the &quot;vp6_parse_coeff()&quot; functions can be exploited to trigger<br /> out-of-bounds reads (CVE-2011-4353).<br /> <br /> It was discovered that Libav incorrectly handled certain malformed<br /> VMD files. If a user were tricked into opening a crafted VMD file,<br /> an attacker could cause a denial of service via application crash,<br /> or possibly execute arbitrary code with the privileges of the user<br /> invoking the program (CVE-2011-4364).<br /> <br /> It was discovered that Libav incorrectly handled certain malformed SVQ1<br /> streams. If a user were tricked into opening a crafted SVQ1 stream<br /> file, an attacker could cause a denial of service via application<br /> crash, or possibly execute arbitrary code with the privileges of the<br /> user invoking the program (CVE-2011-4579).<br /> <br /> Multiple input validations in the decoders/ demuxers for Westwood<br /> Studios VQA, Apple MJPEG-B, Theora, Matroska, Vorbis, Sony ATRAC3,<br /> DV, NSV, files could lead to the execution of arbitrary code<br /> (CVE-2011-3929, CVE-2011-3936, CVE-2011-3937, CVE-2011-3940,<br /> CVE-2011-3945, CVE-2011-3947, CVE-2012-0853, CVE-2012-0858).<br /> <br /> The updated packages have been upgraded to the 0.7.12 version where<br /> these issues has been corrected. MDVSA-2012:075: ffmpeg http://www.mandriva.com/en/support/security/advisories?name=MDVSA-2012:075 Multiple vulnerabilities has been found and corrected in ffmpeg:<br /> <br /> The Matroska format decoder in FFmpeg does not properly allocate<br /> memory, which allows remote attackers to execute arbitrary code via<br /> a crafted file (CVE-2011-3362, CVE-2011-3504).<br /> <br /> cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause<br /> a denial of service (incorrect write operation and application<br /> crash) via an invalid bitstream in a Chinese AVS video (aka CAVS)<br /> file, related to the decode_residual_block, check_for_slice,<br /> and cavs_decode_frame functions, a different vulnerability than<br /> CVE-2011-3362 (CVE-2011-3973).<br /> <br /> Integer signedness error in the decode_residual_inter function in<br /> cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a<br /> denial of service (incorrect write operation and application crash)<br /> via an invalid bitstream in a Chinese AVS video (aka CAVS) file,<br /> a different vulnerability than CVE-2011-3362 (CVE-2011-3974).<br /> <br /> Double free vulnerability in the Theora decoder in FFmpeg allows remote<br /> attackers to cause a denial of service or possibly have unspecified<br /> other impact via a crafted stream (CVE-2011-3892).<br /> <br /> FFmpeg does not properly implement the MKV and Vorbis media<br /> handlers, which allows remote attackers to cause a denial of service<br /> (out-of-bounds read) via unspecified vectors (CVE-2011-3893).<br /> <br /> Heap-based buffer overflow in the Vorbis decoder in FFmpeg allows<br /> remote attackers to cause a denial of service or possibly have<br /> unspecified other impact via a crafted stream (CVE-2011-3895).<br /> <br /> An error within the QDM2 decoder (libavcodec/qdm2.c) can be exploited<br /> to cause a buffer overflow (CVE-2011-4351).<br /> <br /> An integer overflow error within the &quot;vp3_dequant()&quot; function<br /> (libavcodec/vp3.c) can be exploited to cause a buffer overflow<br /> (CVE-2011-4352).<br /> <br /> Errors within the &quot;av_image_fill_pointers()&quot;, the &quot;vp5_parse_coeff()&quot;,<br /> and the &quot;vp6_parse_coeff()&quot; functions can be exploited to trigger<br /> out-of-bounds reads (CVE-2011-4353).<br /> <br /> It was discovered that Libav incorrectly handled certain malformed<br /> VMD files. If a user were tricked into opening a crafted VMD file,<br /> an attacker could cause a denial of service via application crash,<br /> or possibly execute arbitrary code with the privileges of the user<br /> invoking the program (CVE-2011-4364).<br /> <br /> It was discovered that Libav incorrectly handled certain malformed SVQ1<br /> streams. If a user were tricked into opening a crafted SVQ1 stream<br /> file, an attacker could cause a denial of service via application<br /> crash, or possibly execute arbitrary code with the privileges of the<br /> user invoking the program (CVE-2011-4579).<br /> <br /> The updated packages have been upgraded to the 0.6.5 version where<br /> these issues has been corrected. MDVA-2012:042: libdc1394 http://www.mandriva.com/en/support/security/advisories?name=MDVA-2012:042 It was discovered a linker namespace conflict caused Digikam to<br /> crash. This advisory resolves this problem. MDVSA-2012:074: ffmpeg http://www.mandriva.com/en/support/security/advisories?name=MDVSA-2012:074 Multiple vulnerabilities has been found and corrected in ffmpeg:<br /> <br /> The Matroska format decoder in FFmpeg does not properly allocate<br /> memory, which allows remote attackers to execute arbitrary code via<br /> a crafted file (CVE-2011-3362, CVE-2011-3504).<br /> <br /> cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause<br /> a denial of service (incorrect write operation and application<br /> crash) via an invalid bitstream in a Chinese AVS video (aka CAVS)<br /> file, related to the decode_residual_block, check_for_slice,<br /> and cavs_decode_frame functions, a different vulnerability than<br /> CVE-2011-3362 (CVE-2011-3973).<br /> <br /> Integer signedness error in the decode_residual_inter function in<br /> cavsdec.c in libavcodec in FFmpeg allows remote attackers to cause a<br /> denial of service (incorrect write operation and application crash)<br /> via an invalid bitstream in a Chinese AVS video (aka CAVS) file,<br /> a different vulnerability than CVE-2011-3362 (CVE-2011-3974).<br /> <br /> FFmpeg does not properly implement the MKV and Vorbis media<br /> handlers, which allows remote attackers to cause a denial of service<br /> (out-of-bounds read) via unspecified vectors (CVE-2011-3893).<br /> <br /> Heap-based buffer overflow in the Vorbis decoder in FFmpeg allows<br /> remote attackers to cause a denial of service or possibly have<br /> unspecified other impact via a crafted stream (CVE-2011-3895).<br /> <br /> An error within the QDM2 decoder (libavcodec/qdm2.c) can be exploited<br /> to cause a buffer overflow (CVE-2011-4351).<br /> <br /> An integer overflow error within the &quot;vp3_dequant()&quot; function<br /> (libavcodec/vp3.c) can be exploited to cause a buffer overflow<br /> (CVE-2011-4352).<br /> <br /> Errors within the &quot;av_image_fill_pointers()&quot;, the &quot;vp5_parse_coeff()&quot;,<br /> and the &quot;vp6_parse_coeff()&quot; functions can be exploited to trigger<br /> out-of-bounds reads (CVE-2011-4353).<br /> <br /> It was discovered that Libav incorrectly handled certain malformed<br /> VMD files. If a user were tricked into opening a crafted VMD file,<br /> an attacker could cause a denial of service via application crash,<br /> or possibly execute arbitrary code with the privileges of the user<br /> invoking the program (CVE-2011-4364).<br /> <br /> It was discovered that Libav incorrectly handled certain malformed SVQ1<br /> streams. If a user were tricked into opening a crafted SVQ1 stream<br /> file, an attacker could cause a denial of service via application<br /> crash, or possibly execute arbitrary code with the privileges of the<br /> user invoking the program (CVE-2011-4579).<br /> <br /> The updated packages have been upgraded to the 0.5.9 version where<br /> these issues has been corrected.<br /> <br /> Additionally a couple of packages needed to be rebuilt for the new<br /> ffmpeg version and is also being provided with this advisory. MDVA-2012:041: mysql http://www.mandriva.com/en/support/security/advisories?name=MDVA-2012:041 This is a maintenance and bugfix release that upgrades mysql to the<br /> latest version which resolves various upstream bugs. MDVSA-2012:073: openssl http://www.mandriva.com/en/support/security/advisories?name=MDVSA-2012:073 A vulnerability has been found and corrected in openssl:<br /> <br /> A flaw in the OpenSSL handling of CBC mode ciphersuites in DTLS can<br /> be exploited in a denial of service attack on both clients and servers<br /> (CVE-2012-2333).<br /> <br /> The updated packages have been patched to correct this issue. MDVSA-2012:072: roundcubemail http://www.mandriva.com/en/support/security/advisories?name=MDVSA-2012:072 Multiple vulnerabilities has been found and corrected in roundcubemail:<br /> <br /> The login form in Roundcube Webmail before 0.5.1 does not properly<br /> handle a correctly authenticated but unintended login attempt, which<br /> makes it easier for remote authenticated users to obtain sensitive<br /> information by arranging for a victim to login to the attacker&#039;s<br /> account and then compose an e-mail message, related to a login CSRF<br /> issue (CVE-2011-1491).<br /> <br /> steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does<br /> not properly verify that a request is an expected request for an<br /> external Cascading Style Sheets (CSS) stylesheet, which allows remote<br /> authenticated users to trigger arbitrary outbound TCP connections<br /> from the server, and possibly obtain sensitive information, via a<br /> crafted request (CVE-2011-1492).<br /> <br /> Cross-site scripting (XSS) vulnerability in the UI messages<br /> functionality in Roundcube Webmail before 0.5.4 allows remote attackers<br /> to inject arbitrary web script or HTML via the _mbox parameter to<br /> the default URI (CVE-2011-2937).<br /> <br /> include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP<br /> 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET<br /> request for an arbitrary URL, and cause a denial of service (resource<br /> consumption and inbox outage), via a Subject header containing only<br /> a URL, a related issue to CVE-2011-3379 (CVE-2011-4078).<br /> <br /> The updated packages have been upgraded to the 0.7.2 version which<br /> is not affected by these issues.