Contact | Site en Français               

 


 

VUPEN VNS v4.0

 
  Features and Options
  Free 14-Day Trial

  Partner Program

  Receive More Information
 
   
 

Latest Intelligence

 
  VUPEN Security Advisories

  Virus and Malware Alerts

  VUPEN Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Fedora Security Update Fixes Libgda Format String Vulnerability

Title : Fedora Security Update Fixes Libgda Format String Vulnerability
VUPEN ID : VUPEN/ADV-2005-2342
CVE ID : CVE-2005-2958
CWE ID : VUPEN VNS Only
CVSS V2 : VUPEN VNS Only
Rated as : High Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-11-08


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

Fedora has released updated packages to correct a vulnerability identified in Libgda. This flaw is due to a format string error in the "gda_log_error()" and "gda_log_message()" [gda-log.c] functions when processing log files, which could be exploited by remote attackers to execute arbitrary commands and compromise a vulnerable system. For additional information, see : VUPEN/ADV-2005-2200

Affected Products

Fedora Core 3

Solution

Upgrade the affected package :
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
5bbe1fd316f3d73a69f2bf1d2c91b360 SRPMS/libgda-1.0.4-3.1.src.rpm
4bcd6b4701e97749fc5d4bd4b744b7e4 x86_64/libgda-1.0.4-3.1.x86_64.rpm
dd07589bca360c30e1c31e0977fa4eff x86_64/libgda-devel-1.0.4-3.1.x86_64.rpm
b8eb2c524070622b7710642331b57aa5 x86_64/gda-mysql-1.0.4-3.1.x86_64.rpm
72079129f4d5d7f0e2f84c8b2caefb8e x86_64/gda-odbc-1.0.4-3.1.x86_64.rpm
8b42050ae43d3e66281bce5675bbcee3 x86_64/gda-postgres-1.0.4-3.1.x86_64.rpm
0e58e8eb0a6f9e27a80135664d4accd3 x86_64/debug/libgda-debuginfo-1.0.4-3.1.x86_64.rpm
b5b37d00eef0f7f5b53ae606ec21fc03 x86_64/libgda-1.0.4-3.1.i386.rpm
b5b37d00eef0f7f5b53ae606ec21fc03 i386/libgda-1.0.4-3.1.i386.rpm
bd5eb250a165274fbbae7720ec0c83e8 i386/libgda-devel-1.0.4-3.1.i386.rpm
35b06a0016b2ea5713229a44571b3f4c i386/gda-mysql-1.0.4-3.1.i386.rpm
25c8169519e55fc743625ff790c11c62 i386/gda-odbc-1.0.4-3.1.i386.rpm
12f7f6e510df7dab515f0d18aca90fd1 i386/gda-postgres-1.0.4-3.1.i386.rpm
68ccc27d29771906d33913dd6d14e300 i386/debug/libgda-debuginfo-1.0.4-3.1.i386.rpm

References

http://www.vupen.com/english/advisories/2005/2342
http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00013.html

ChangeLog

2005-11-08 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts with CVE, CWE, and CVSS when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

VUPEN Vulnerability
Notification Service

 

Latest Advisories

  

   
    





Copyright VUPEN © 2004-2010 - Privacy Policy