1 2 3 4 5 6

Vulnerabilidades rss pdf

Coordinación de Seguridad de la Información - UNAM-CERT -- DGTIC-UNAM

Vulnerabilidad de Seguridad UNAM-CERT-2005-304 Actualización de Mandriva para Mozilla.

Mandriva liberó una actualización para Mozilla. Esta repara varias vulnerabilidades que pueden explotarse para burlar ciertas restricciones de seguridad, realizar ataques de Cross-Site Scripting y spoofing y comprometer el sistema de un usuario.

  • Fecha de Liberación: 3-Ago-2005
  • Fuente:

    Mandriva Security Advisories
    MDKSA-2005:128

  • CVE ID: CAN-2005-1937 CAN-2005-2260 CAN-2005-2261 CAN-2005-2263 CAN-2005-2265 CAN-2005-2266 CAN-2005-2267 CAN-2005-2268 CAN-2005-2269 CAN-2005-2270
  • Riesgo Altamente crítico
  • Problema de Vulnerabilidad Remoto
  • Tipo de Vulnerabilidad Múltiples vulnerabilidades

Sistemas Afectados

Mandrake 10.0 Mozilla Suite < 1.7.10
Mandrake CS3.0 Mozilla Suite < 1.7.10
  1. Descripción

    Mandriva liberó una actualización para Mozilla. Esta repara varias vulnerabilidades que pueden explotarse por personas maliciosas para burlar ciertas restricciones de seguridad, realizar ataques de Cross-Site Scripting y spoofing y comprometer el sistema de un usuario.

    Uno de los problemas radica en que los scripts dentro de controles XBL de correos electrónicos pueden ser ejecutados incluso cuando esta deshabilitado JavaScript. Esto no representa un riesgo de seguridad en si mismo, pero podria permitir la explotación de vulnerabilidades que requieren de JavaScript.

    Un error de validación en la entrada del manejo de objetos de JavaScript no considerados cuando pasan a la función "InstallVersion.compareTo()" puede ser explotado para ejecutar código arbitrario.

  2. Impacto

    Security Bypass.

    Spoofing.

    Cross-Site Scripting.

    Acceso al sistema.

  3. Solución

    Aplicar los paquetes actualizados.

    Mandrakelinux 10.1

    b1ed603e1d571bf55b35dcf3934715f0 10.1/RPMS/epiphany-1.2.8-4.3.101mdk.i586.rpm
    1b7a293fd2ad206ccbc8774c439c0a4f 10.1/RPMS/epiphany-devel-1.2.8-4.3.101mdk.i586.rpm
    b749ecba69520e77411144fb1019acd3 10.1/RPMS/galeon-1.3.17-3.3.101mdk.i586.rpm
    0f50b3f9e0c34be38517114f488da47e 10.1/RPMS/libnspr4-1.7.8-0.2.101mdk.i586.rpm
    c7e2ffd0049ee31f24462406990521be 10.1/RPMS/libnspr4-devel-1.7.8-0.2.101mdk.i586.rpm
    5afe6299791f9b02ebe9ca50ad5af4f2 10.1/RPMS/libnss3-1.7.8-0.2.101mdk.i586.rpm
    08dacfc4d6041f0ad91effb7620bfbb4 10.1/RPMS/libnss3-devel-1.7.8-0.2.101mdk.i586.rpm
    b13923d572288eaf34db5ce21f84ca8a 10.1/RPMS/mozilla-1.7.8-0.2.101mdk.i586.rpm
    f9434ca544adf8c81b5269206323e49d 10.1/RPMS/mozilla-devel-1.7.8-0.2.101mdk.i586.rpm
    bb6fa6a7a6320a494f7406c97d56e18b 10.1/RPMS/mozilla-dom-inspector-1.7.8-0.2.101mdk.i586.rpm
    a3f4980a03dba6247483413402605e1f 10.1/RPMS/mozilla-enigmail-1.7.8-0.2.101mdk.i586.rpm
    94d9b3e19fe4386918dba744691d5e23 10.1/RPMS/mozilla-enigmime-1.7.8-0.2.101mdk.i586.rpm
    904c348ecbee1bf452de597df8f59062 10.1/RPMS/mozilla-irc-1.7.8-0.2.101mdk.i586.rpm
    ff0ca565c69e6773fd83d8b7cc625245 10.1/RPMS/mozilla-js-debugger-1.7.8-0.2.101mdk.i586.rpm
    2a6f2bb208251f8d47697eb25e856d02 10.1/RPMS/mozilla-mail-1.7.8-0.2.101mdk.i586.rpm
    cdd099b62c2b2144ac9c9f129f1256f1 10.1/RPMS/mozilla-spellchecker-1.7.8-0.2.101mdk.i586.rpm
    b7f5fe1866b17d72281aacefce238eab 10.1/SRPMS/epiphany-1.2.8-4.3.101mdk.src.rpm
    8464ea621f75482c3a08fedb00729767 10.1/SRPMS/galeon-1.3.17-3.3.101mdk.src.rpm
    9c8dea4d7f4b532329afb3cc945c654b 10.1/SRPMS/mozilla-1.7.8-0.2.101mdk.src.rpm
    

    Mandrakelinux 10.1/X86_64

    66b5ba7351c0dde849b78fb41720f7b3 x86_64/10.1/RPMS/epiphany-1.2.8-4.3.101mdk.x86_64.rpm
    8d6f0504e88642e71104aa38dfdb801d x86_64/10.1/RPMS/epiphany-devel-1.2.8-4.3.101mdk.x86_64.rpm
    9ed6595f414b7595c3e8c6b5c70fc8cd x86_64/10.1/RPMS/galeon-1.3.17-3.3.101mdk.x86_64.rpm
    e781ff913b57bb5f1becce7934d03691 x86_64/10.1/RPMS/lib64nspr4-1.7.8-0.2.101mdk.x86_64.rpm
    26c709082cb2a8dfc62603a5ee4226bc x86_64/10.1/RPMS/lib64nspr4-devel-1.7.8-0.2.101mdk.x86_64.rpm
    0f50b3f9e0c34be38517114f488da47e x86_64/10.1/RPMS/libnspr4-1.7.8-0.2.101mdk.i586.rpm
    2d53455b98bd04cc956bf76e7ca03fdf x86_64/10.1/RPMS/lib64nss3-1.7.8-0.2.101mdk.x86_64.rpm
    fe938a6a0af7244498b117705185351c x86_64/10.1/RPMS/lib64nss3-devel-1.7.8-0.2.101mdk.x86_64.rpm
    5afe6299791f9b02ebe9ca50ad5af4f2 x86_64/10.1/RPMS/libnss3-1.7.8-0.2.101mdk.i586.rpm
    6c4326edda0d2a238b10cceccafa315a x86_64/10.1/RPMS/mozilla-1.7.8-0.2.101mdk.x86_64.rpm
    2e04f350de4c50d8ce0c08a8802358d3 x86_64/10.1/RPMS/mozilla-devel-1.7.8-0.2.101mdk.x86_64.rpm
    625797aba9d415f5a1e82f976491faf4 x86_64/10.1/RPMS/mozilla-dom-inspector-1.7.8-0.2.101mdk.x86_64.rpm
    a6b9add7c5e4a9047f53cae48d7cc8ad x86_64/10.1/RPMS/mozilla-enigmail-1.7.8-0.2.101mdk.x86_64.rpm
    d8ec50e909d4870d8123ce945c4cf70e x86_64/10.1/RPMS/mozilla-enigmime-1.7.8-0.2.101mdk.x86_64.rpm
    ea35499ad0e70efa833a3acf1ea4a2c1 x86_64/10.1/RPMS/mozilla-irc-1.7.8-0.2.101mdk.x86_64.rpm
    493381959561ef841fc6335cb8bdace8 x86_64/10.1/RPMS/mozilla-js-debugger-1.7.8-0.2.101mdk.x86_64.rpm
    d39ad6dbe8fb3684ae2fbc511dd227b4 x86_64/10.1/RPMS/mozilla-mail-1.7.8-0.2.101mdk.x86_64.rpm
    89ed0af6fbd5f8353bf0c359499280a3 x86_64/10.1/RPMS/mozilla-spellchecker-1.7.8-0.2.101mdk.x86_64.rpm
    b7f5fe1866b17d72281aacefce238eab x86_64/10.1/SRPMS/epiphany-1.2.8-4.3.101mdk.src.rpm
    8464ea621f75482c3a08fedb00729767 x86_64/10.1/SRPMS/galeon-1.3.17-3.3.101mdk.src.rpm
    9c8dea4d7f4b532329afb3cc945c654b x86_64/10.1/SRPMS/mozilla-1.7.8-0.2.101mdk.src.rpm
    

    Corporate Server 3.0

    8481048cca68509bad7bec7298dbb984 corporate/3.0/RPMS/libnspr4-1.7.8-0.2.C30mdk.i586.rpm
    7bf9e70298786c06a13dd8cd07a85421 corporate/3.0/RPMS/libnspr4-devel-1.7.8-0.2.C30mdk.i586.rpm
    1c07227eafcb128b05f885120aacaa94 corporate/3.0/RPMS/libnss3-1.7.8-0.2.C30mdk.i586.rpm
    c691c7d158de44ebc0123cbf30bb3ba1 corporate/3.0/RPMS/libnss3-devel-1.7.8-0.2.C30mdk.i586.rpm
    44df63b1c3460ad588e8b3f8834880b5 corporate/3.0/RPMS/mozilla-1.7.8-0.2.C30mdk.i586.rpm
    f1f9d9153ecbb4085680920b09cc7148 corporate/3.0/RPMS/mozilla-devel-1.7.8-0.2.C30mdk.i586.rpm
    710865bf9ed1fe59fe3f8bda48bc9330 corporate/3.0/RPMS/mozilla-dom-inspector-1.7.8-0.2.C30mdk.i586.rpm
    8b1830ef05ef943a6472aaf643feef5e corporate/3.0/RPMS/mozilla-enigmail-1.7.8-0.2.C30mdk.i586.rpm
    b48ed83052a17e52b6fceaf326be1c78 corporate/3.0/RPMS/mozilla-enigmime-1.7.8-0.2.C30mdk.i586.rpm
    d87d974c52fb46bacc24920d8ca4f621 corporate/3.0/RPMS/mozilla-irc-1.7.8-0.2.C30mdk.i586.rpm
    115ce3ac351361140a8169b0b34db304 corporate/3.0/RPMS/mozilla-js-debugger-1.7.8-0.2.C30mdk.i586.rpm
    43f2921fafc8c9d822d381380ea1b919 corporate/3.0/RPMS/mozilla-mail-1.7.8-0.2.C30mdk.i586.rpm
    9fa6f4ee933d024cf38caa5e0575d263 corporate/3.0/RPMS/mozilla-spellchecker-1.7.8-0.2.C30mdk.i586.rpm
    2a768ee57f740885cf246a9e466c1b71 corporate/3.0/SRPMS/mozilla-1.7.8-0.2.C30mdk.src.rpm
    

    Corporate Server 3.0/X86_64

    9e3cdf2eeafbe11ff0c8509916661276 x86_64/corporate/3.0/RPMS/lib64nspr4-1.7.8-0.2.C30mdk.x86_64.rpm
    6330410729f516564d598494f81a4a44 x86_64/corporate/3.0/RPMS/lib64nspr4-devel-1.7.8-0.2.C30mdk.x86_64.rpm
    d35b405b54428febe6d9545ef5104fce x86_64/corporate/3.0/RPMS/lib64nss3-1.7.8-0.2.C30mdk.x86_64.rpm
    2b3e8b026301699e213492f34fe79428 x86_64/corporate/3.0/RPMS/lib64nss3-devel-1.7.8-0.2.C30mdk.x86_64.rpm
    f28fc77e7d2af12c6579b0511fcad969 x86_64/corporate/3.0/RPMS/mozilla-1.7.8-0.2.C30mdk.x86_64.rpm
    218b54e477e066bcdc4500e8bdf90c13 x86_64/corporate/3.0/RPMS/mozilla-devel-1.7.8-0.2.C30mdk.x86_64.rpm
    00c9c9d1bfca743e6be4edd1fab0fb5d x86_64/corporate/3.0/RPMS/mozilla-dom-inspector-1.7.8-0.2.C30mdk.x86_64.rpm
    23ccbc4b1d1572a0bda25c8497a83a5d x86_64/corporate/3.0/RPMS/mozilla-enigmail-1.7.8-0.2.C30mdk.x86_64.rpm
    3ae747ee09d81dcceb435032db500c41 x86_64/corporate/3.0/RPMS/mozilla-enigmime-1.7.8-0.2.C30mdk.x86_64.rpm
    178e7551a893522351cdb633b3a251ff x86_64/corporate/3.0/RPMS/mozilla-irc-1.7.8-0.2.C30mdk.x86_64.rpm
    1431f59d6dfaabfcf9c74f0e52f30527 x86_64/corporate/3.0/RPMS/mozilla-js-debugger-1.7.8-0.2.C30mdk.x86_64.rpm
    996537a7b1b60bbe53557a1da658470a x86_64/corporate/3.0/RPMS/mozilla-mail-1.7.8-0.2.C30mdk.x86_64.rpm
    d95814a734933529dd23656837e080f9 x86_64/corporate/3.0/RPMS/mozilla-spellchecker-1.7.8-0.2.C30mdk.x86_64.rpm
    2a768ee57f740885cf246a9e466c1b71 x86_64/corporate/3.0/SRPMS/mozilla-1.7.8-0.2.C30mdk.src.rpm
    
  4. Apéndices

    Mayor información.

    http://www.mandriva.com/security/

La Coordinación de Seguridad de la Información/UNAM-CERT agradece el apoyo en la elaboración ó traducción y revisión de éste Documento a:

  • Floriberto López Velázquez (flopez at seguridad dot unam dot mx)

UNAM-CERT
Equipo de Respuesta a Incidentes UNAM
Coordinación de Seguridad de la Información

incidentes at seguridad.unam.mx
phishing at seguridad.unam.mx
http://www.cert.org.mx
http://www.seguridad.unam.mx
ftp://ftp.seguridad.unam.mx
Tel: 56 22 81 69
Fax: 56 22 80 47


Universidad Nacional Autonoma de México Aviso legal |  Créditos |  Staff |  Administración
Copyright © Todos los derechos reservados
UNAM - CERT