|
|
|
>> Fedora Security Update Fixes Libgda Format String Vulnerability
|
Fedora has released updated packages to correct a vulnerability identified in Libgda. This flaw is due to a format string error in the "gda_log_error()" and "gda_log_message()" [gda-log.c] functions when processing log files, which could be exploited by remote attackers to execute arbitrary commands and compromise a vulnerable system. For additional information, see : VUPEN/ADV-2005-2200
Affected Products
Fedora Core 3
Solution
Upgrade the affected package :
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
5bbe1fd316f3d73a69f2bf1d2c91b360 SRPMS/libgda-1.0.4-3.1.src.rpm
4bcd6b4701e97749fc5d4bd4b744b7e4 x86_64/libgda-1.0.4-3.1.x86_64.rpm
dd07589bca360c30e1c31e0977fa4eff x86_64/libgda-devel-1.0.4-3.1.x86_64.rpm
b8eb2c524070622b7710642331b57aa5 x86_64/gda-mysql-1.0.4-3.1.x86_64.rpm
72079129f4d5d7f0e2f84c8b2caefb8e x86_64/gda-odbc-1.0.4-3.1.x86_64.rpm
8b42050ae43d3e66281bce5675bbcee3 x86_64/gda-postgres-1.0.4-3.1.x86_64.rpm
0e58e8eb0a6f9e27a80135664d4accd3 x86_64/debug/libgda-debuginfo-1.0.4-3.1.x86_64.rpm
b5b37d00eef0f7f5b53ae606ec21fc03 x86_64/libgda-1.0.4-3.1.i386.rpm
b5b37d00eef0f7f5b53ae606ec21fc03 i386/libgda-1.0.4-3.1.i386.rpm
bd5eb250a165274fbbae7720ec0c83e8 i386/libgda-devel-1.0.4-3.1.i386.rpm
35b06a0016b2ea5713229a44571b3f4c i386/gda-mysql-1.0.4-3.1.i386.rpm
25c8169519e55fc743625ff790c11c62 i386/gda-odbc-1.0.4-3.1.i386.rpm
12f7f6e510df7dab515f0d18aca90fd1 i386/gda-postgres-1.0.4-3.1.i386.rpm
68ccc27d29771906d33913dd6d14e300 i386/debug/libgda-debuginfo-1.0.4-3.1.i386.rpm
References
http://www.vupen.com/english/advisories/2005/2342 http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00013.html
ChangeLog
2005-11-08 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts with CVE, CWE, and CVSS when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |

|