You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa setroubleshoot

Sigurnosni nedostatak programskog paketa setroubleshoot

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2016-047a86f5b1
2016-06-23 17:12:03.993281
——————————————————————————–

Name : setroubleshoot
Product : Fedora 24
Version : 3.3.9.1
Release : 1.fc24
URL : https://fedorahosted.org/setroubleshoot
Summary : Helps troubleshoot SELinux problems
Description :
setroubleshoot GUI. Application that allows you to view setroubleshoot-server
messages.
Provides tools to help diagnose SELinux problems. When AVC messages
are generated an alert can be generated that will give information
about the problem and help track its resolution. Alerts can be configured
to user preference. The same tools can be run on existing log files.

——————————————————————————–
Update Information:

Security fix for CVE-2016-4446
——————————————————————————–
References:

[ 1 ] Bug #1339250 – CVE-2016-4446 setroubleshoot-plugins: insecure commands.getoutput use in the allow_execstack plugin
https://bugzilla.redhat.com/show_bug.cgi?id=1339250
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update setroubleshoot’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2016-75ca94dee3
2016-06-23 17:12:03.992734
——————————————————————————–

Name : setroubleshoot-plugins
Product : Fedora 24
Version : 3.3.5.1
Release : 1.fc24
URL : https://github.com/fedora-selinux/setroubleshoot
Summary : Analysis plugins for use with setroubleshoot
Description :
This package provides a set of analysis plugins for use with
setroubleshoot. Each plugin has the capacity to analyze SELinux AVC
data and system data to provide user friendly reports describing how
to interpret SELinux AVC denials.

——————————————————————————–
Update Information:

Security fix for CVE-2016-4446
——————————————————————————–
References:

[ 1 ] Bug #1339250 – CVE-2016-4446 setroubleshoot-plugins: insecure commands.getoutput use in the allow_execstack plugin
https://bugzilla.redhat.com/show_bug.cgi?id=1339250
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update setroubleshoot-plugins’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce@lists.fedoraproject.org

 

 

 

 

——————————————————————————–
Fedora Update Notification
FEDORA-2016-f597359bf2
2016-06-29 11:13:11.067861
——————————————————————————–

Name        : setroubleshoot
Product     : Fedora 22
Version     : 3.2.27.1
Release     : 1.fc22
URL         : https://fedorahosted.org/setroubleshoot
Summary     : Helps troubleshoot SELinux problems
Description :
setroubleshoot GUI. Application that allows you to view setroubleshoot-server
messages.
Provides tools to help diagnose SELinux problems. When AVC messages
are generated an alert can be generated that will give information
about the problem and help track its resolution. Alerts can be configured
to user preference. The same tools can be run on existing log files.

——————————————————————————–
Update Information:

Security fix for CVE-2016-4446
——————————————————————————–
References:

  [ 1 ] Bug #1339250 – CVE-2016-4446 setroubleshoot-plugins: insecure commands.getoutput use in the allow_execstack plugin
        https://bugzilla.redhat.com/show_bug.cgi?id=1339250
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update setroubleshoot’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2016-f2493c754a
2016-06-29 11:14:22.189089
——————————————————————————–

Name        : setroubleshoot
Product     : Fedora 23
Version     : 3.3.9.1
Release     : 1.fc23
URL         : https://fedorahosted.org/setroubleshoot
Summary     : Helps troubleshoot SELinux problems
Description :
setroubleshoot GUI. Application that allows you to view setroubleshoot-server
messages.
Provides tools to help diagnose SELinux problems. When AVC messages
are generated an alert can be generated that will give information
about the problem and help track its resolution. Alerts can be configured
to user preference. The same tools can be run on existing log files.

——————————————————————————–
Update Information:

Security fix for CVE-2016-4446
——————————————————————————–
References:

  [ 1 ] Bug #1339250 – CVE-2016-4446 setroubleshoot-plugins: insecure commands.getoutput use in the allow_execstack plugin
        https://bugzilla.redhat.com/show_bug.cgi?id=1339250
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update setroubleshoot’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce@lists.fedoraproject.org
 

 

 

setroubleshoot

——————————————————————————–
Fedora Update Notification
FEDORA-2016-b68f69b086
2016-07-02 13:23:23.483604
——————————————————————————–

Name        : setroubleshoot-plugins
Product     : Fedora 23
Version     : 3.3.5.1
Release     : 1.fc23
URL         : https://github.com/fedora-selinux/setroubleshoot
Summary     : Analysis plugins for use with setroubleshoot
Description :
This package provides a set of analysis plugins for use with
setroubleshoot. Each plugin has the capacity to analyze SELinux AVC
data and system data to provide user friendly reports describing how
to interpret SELinux AVC denials.

——————————————————————————–
Update Information:

Security fix for CVE-2016-4446
——————————————————————————–
References:

  [ 1 ] Bug #1339250 – CVE-2016-4446 setroubleshoot-plugins: insecure commands.getoutput use in the allow_execstack plugin
        https://bugzilla.redhat.com/show_bug.cgi?id=1339250
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update setroubleshoot-plugins’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce@lists.fedoraproject.org

 

AutorTomislav Protega
Cert idNCERT-REF-2016-06-0132-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa libxml2

Otkriveni su sigurnosni nedostaci u programskom paketu libxml2 za operativni sustav RHEL. Otkriven je veći broj prekoračenja spremnika gomile i...

Close