Mandriva Security http://www.mandriva.com/en/security/advisories Mandriva security advisories en-us MDVSA-2010:171: lvm2 http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:171 A vulnerability has been found and corrected in lvm2:<br /> <br /> The cluster logical volume manager daemon (clvmd) in lvm2-cluster<br /> in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS)<br /> and other products, does not verify client credentials upon a socket<br /> connection, which allows local users to cause a denial of service<br /> (daemon exit or logical-volume change) or possibly have unspecified<br /> other impact via crafted control commands (CVE-2010-2526).<br /> <br /> The updated packages have been patched to correct this issue. MDVA-2010:189: cairo http://www.mandriva.com/en/security/advisories?name=MDVA-2010:189 The version of cairo shipped with Mandriva 2010.1 prevented several<br /> PDF viewers from working. This updates cairo to the newest version<br /> to fix these problems. MDVSA-2010:170: wget http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:170 A vulnerability has been found and corrected in wget:<br /> <br /> GNU Wget 1.12 and earlier uses a server-provided filename instead of<br /> the original URL to determine the destination filename of a download,<br /> which allows remote servers to create or overwrite arbitrary files<br /> via a 3xx redirect to a URL with a .wgetrc filename followed by a<br /> 3xx redirect to a URL with a crafted filename, and possibly execute<br /> arbitrary code as a consequence of writing to a dotfile in a home<br /> directory (CVE-2010-2252).<br /> <br /> Packages for 2008.0 and 2009.0 are provided as of the Extended<br /> Maintenance Program. Please visit this link to learn more:<br /> http://store.mandriva.com/product_info.php?cPath=149&products_id=490<br /> <br /> The updated packages have been patched to correct this issue. MDVSA-2010:169: mozilla-thunderbird http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:169 Multiple vulnerabilities has been found and corrected in<br /> mozilla-thunderbird:<br /> <br /> dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11<br /> and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x<br /> before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress<br /> a script's URL in certain circumstances involving a redirect and an<br /> error message, which allows remote attackers to obtain sensitive<br /> information about script parameters via a crafted HTML document,<br /> related to the window.onerror handler (CVE-2010-2754).<br /> <br /> Mozilla Firefox permits cross-origin loading of CSS stylesheets<br /> even when the stylesheet download has an incorrect MIME type and the<br /> stylesheet document is malformed, which allows remote HTTP servers<br /> to obtain sensitive information via a crafted document (CVE-2010-0654).<br /> <br /> The importScripts Web Worker method in Mozilla Firefox 3.5.x before<br /> 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and<br /> 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that<br /> content is valid JavaScript code, which allows remote attackers to<br /> bypass the Same Origin Policy and obtain sensitive information via<br /> a crafted HTML document (CVE-2010-1213).<br /> <br /> Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x<br /> before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before<br /> 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute<br /> arbitrary code via a large selection attribute in a XUL tree element<br /> (CVE-2010-2753).<br /> <br /> Integer overflow in an array class in Mozilla Firefox 3.5.x before<br /> 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x<br /> before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to<br /> execute arbitrary code by placing many Cascading Style Sheets (CSS)<br /> values in an array (CVE-2010-2752).<br /> <br /> Multiple unspecified vulnerabilities in the browser engine in Mozilla<br /> Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x<br /> before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow<br /> remote attackers to cause a denial of service (memory corruption and<br /> application crash) or possibly execute arbitrary code via unknown<br /> vectors (CVE-2010-1211).<br /> <br /> Packages for 2008.0 and 2009.0 are provided as of the Extended<br /> Maintenance Program. Please visit this link to learn more:<br /> http://store.mandriva.com/product_info.php?cPath=149&products_id=490<br /> <br /> Additionally, some packages which require so, have been rebuilt and<br /> are being provided as updates. MDVSA-2010:168: openssl http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:168 A vulnerability has been found and corrected in openssl:<br /> <br /> Double free vulnerability in the ssl3_get_key_exchange function in<br /> the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7,<br /> and possibly other versions, when using ECDH, allows context-dependent<br /> attackers to cause a denial of service (crash) and possibly execute<br /> arbitrary code via a crafted private key with an invalid prime. NOTE:<br /> some sources refer to this as a use-after-free issue (CVE-2010-2939).<br /> <br /> The updated packages have been patched to correct this issue. MDVSA-2010:167: perl-libwww-perl http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:167 A vulnerability has been found and corrected in perl-libwww-perl:<br /> <br /> lwp-download in libwww-perl before 5.835 does not reject downloads to<br /> filenames that begin with a . (dot) character, which allows remote<br /> servers to create or overwrite files via (1) a 3xx redirect to a<br /> URL with a crafted filename or (2) a Content-Disposition header<br /> that suggests a crafted filename, and possibly execute arbitrary<br /> code as a consequence of writing to a dotfile in a home directory<br /> (CVE-2010-2253).<br /> <br /> Packages for 2008.0 and 2009.0 are provided as of the Extended<br /> Maintenance Program. Please visit this link to learn more:<br /> http://store.mandriva.com/product_info.php?cPath=149&products_id=490<br /> <br /> The updated packages have been patched to correct this issue. MDVSA-2010:166: libgdiplus http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:166 A vulnerability has been found and corrected in libgdiplus:<br /> <br /> Multiple integer overflows in libgdiplus 2.6.7, as used in Mono,<br /> allow attackers to execute arbitrary code via (1) a crafted TIFF<br /> file, related to the gdip_load_tiff_image function in tiffcodec.c;<br /> (2) a crafted JPEG file, related to the gdip_load_jpeg_image_internal<br /> function in jpegcodec.c; or (3) a crafted BMP file, related to the<br /> gdip_read_bmp_image function in bmpcodec.c, leading to heap-based<br /> buffer overflows (CVE-2010-1526).<br /> <br /> The updated packages have been patched to correct this issue. MDVSA-2010:165: libHX http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:165 A vulnerability has been found and corrected in libHX:<br /> <br /> Heap-based buffer overflow in the HX_split function in string.c in<br /> libHX before 3.6 allows remote attackers to execute arbitrary code<br /> or cause a denial of service (application crash) via a string that<br /> is inconsistent with the expected number of fields (CVE-2010-2947).<br /> <br /> The updated packages have been patched to correct this issue. MDVSA-2010:164: phpmyadmin http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:164 A vulnerability has been found and corrected in phpmyadmin:<br /> <br /> It was possible to conduct a XSS attack using crafted URLs or POST<br /> parameters on several pages (CVE-2010-3056).<br /> <br /> This upgrade provides phpmyadmin 3.3.5.1 which is not vulnerable for<br /> this security issue. MDVSA-2010:163: phpmyadmin http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:163 Multiple vulnerabilities has been found and corrected in phpmyadmin:<br /> <br /> The setup script used to generate configuration can be fooled using<br /> a crafted POST request to include arbitrary PHP code in generated<br /> configuration file. Combined with the ability to save files on the<br /> server, this can allow unauthenticated users to execute arbitrary<br /> PHP code (CVE-2010-3055).<br /> <br /> It was possible to conduct a XSS attack using crafted URLs or POST<br /> parameters on several pages (CVE-2010-3056).<br /> <br /> This upgrade provides phpmyadmin 2.11.10.1 which is not vulnerable<br /> for these security issues.