Une vulnérabilité a été identifiée dans Mandriva, elle pourrait être exploitée afin de conduire des attaques par cross site scripting [...]
Solution
Installer les mises à jour :
Mandriva Linux 2007.0:
2b4013e38c4bbc2624150cf8b859d97b 2007.0/i586/mailman-2.1.9-1.1mdv2007.0.i586.rpm
84e8a6a1a78093bcdcf041450309993a 2007.0/SRPMS/mailman-2.1.9-1.1mdv2007.0.src.rpm
Mandriva Linux 2007.0/X86_64:
7f70c499712449927c501eec60f7257e 2007.0/x86_64/mailman-2.1.9-1.1mdv2007.0.x86_64.rpm
84e8a6a1a78093bcdcf041450309993a 2007.0/SRPMS/mailman-2.1.9-1.1mdv2007.0.src.rpm
Mandriva Linux 2007.1:
3e66e56114c272d5ebdfc143e317ff86 2007.1/i586/mailman-2.1.9-2.1mdv2007.1.i586.rpm
83d478c788bfda009a1ad9dce97e4916 2007.1/SRPMS/mailman-2.1.9-2.1mdv2007.1.src.rpm
Mandriva Linux 2007.1/X86_64:
e3215c27c2ce3f0857bc81ba67e9caaa 2007.1/x86_64/mailman-2.1.9-2.1mdv2007.1.x86_64.rpm
83d478c788bfda009a1ad9dce97e4916 2007.1/SRPMS/mailman-2.1.9-2.1mdv2007.1.src.rpm
Mandriva Linux 2008.0:
c2ffce2a1332f7125f37c05fb5fc7acd 2008.0/i586/mailman-2.1.9-2.1mdv2008.0.i586.rpm
d2cb3d3c79bb91a81f1cace90213384e 2008.0/SRPMS/mailman-2.1.9-2.1mdv2008.0.src.rpm
Mandriva Linux 2008.0/X86_64:
f01417a5626e86aae6678f5ea67c3aac 2008.0/x86_64/mailman-2.1.9-2.1mdv2008.0.x86_64.rpm
d2cb3d3c79bb91a81f1cace90213384e 2008.0/SRPMS/mailman-2.1.9-2.1mdv2008.0.src.rpm
Corporate 3.0:
61fc3c66164c9c3880d49e477bc75fcd corporate/3.0/i586/mailman-2.1.4-2.9.C30mdk.i586.rpm
842647b66f6a5e6e6674533bbb45fa3e corporate/3.0/SRPMS/mailman-2.1.4-2.9.C30mdk.src.rpm
Corporate 3.0/X86_64:
9ff6c3bf000084730904b9b1e944cf69 corporate/3.0/x86_64/mailman-2.1.4-2.9.C30mdk.x86_64.rpm
842647b66f6a5e6e6674533bbb45fa3e corporate/3.0/SRPMS/mailman-2.1.4-2.9.C30mdk.src.rpm
Corporate 4.0:
5bdf3f1a62de4d8088cd3f8409fdd525 corporate/4.0/i586/mailman-2.1.6-6.3.20060mlcs4.i586.rpm
fc6132d963989c475ddaed436b234039 corporate/4.0/SRPMS/mailman-2.1.6-6.3.20060mlcs4.src.rpm
Corporate 4.0/X86_64:
209d068b958d077e2102c42052a5a72a corporate/4.0/x86_64/mailman-2.1.6-6.3.20060mlcs4.x86_64.rpm
fc6132d963989c475ddaed436b234039 corporate/4.0/SRPMS/mailman-2.1.6-6.3.20060mlcs4.src.rpm
Historique
2008-03-07 : Version Initiale
Recevez les bulletins FrSIRT
Le service FrSIRT VNS permet aux professionnels de la sécurité (RSSI, DSI, administrateurs et consultants) de recevoir en temps-réel, par email, SMS et flux RSS/XML, des bulletins de vulnérabilités complets, détaillés et personnalisés.