Multiple vulnerabilities have been found in Namazu, worst of which allows remote attackers to cause a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201311-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Namazu: Multiple vulnerabilities Date: November 28, 2013 Bugs: #391259 ID: 201311-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Namazu, worst of which allows remote attackers to cause a Denial of Service condition. Background ========= Namazu is a full-text search engine intended for easy use. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/namazu < 2.0.21 > = 2.0.21 Description ========== Multiple vulnerabilities have been discovered in Namazu. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could execute arbitrary code or cause a Denial of Service condition. Furthermore, a remote attacker may be able to inject arbitrary web script or HTML via a cookie. Workaround ========= There is no known workaround at this time. Resolution ========= All Namazu users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/namazu-2.0.21" References ========= [ 1 ] CVE-2009-5028 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-5028 [ 2 ] CVE-2011-4345 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4345 [ 3 ] CVE-2011-4711 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4711 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201311-22 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Security fix release.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-557 2004-12-20 ---------------------------------------------------------------------Product : Fedora Core 2 Name : namazu Version : 2.0.14 Release : 0.FC2.0 Summary : Namazu is a full-text search engine Description : Namazu is a full-text search engine software intended for easy use. Not only it works as CGI program for small or medium scale WWW search engine, but also works as personal use such as search system for local HDD. ---------------------------------------------------------------------* Sat Dec 18 2004 Akira TAGOH - 2.0.14-0.FC2.0 - Security fix release. http://namazu.org/security.html * Wed Jun 16 2004 Elliot Lee - rebuilt ---------------------------------------------------------------------This update can be downloaded from: 90abd557765322435a0c266fc9f45d44 SRPMS/namazu-2.0.14-0.FC2.0.src.rpm ba3e3457104abd61f83f39097a969cef x86_64/namazu-cgi-2.0.14-0.FC2.0.x86_64.rpm e1719508769ff15e7e3c50ea205a8e95 x86_64/namazu-2.0.14-0.FC2.0.x86_64.rpm b5f86c95c88d97c5d64fb8409b40ea2e x86_64/debug/namazu-debuginfo-2.0.14-0.FC2.0.x86_64.rpm 3f7742a6e95dcfb3340f24b9f7735ca2 x86_64/namazu-devel-2.0.14-0.FC2.0.x86_64.rpm 365245ac8efaf43043fffc07583e0430 i386/namazu-cgi-2.0.14-0.FC2.0.i386.rpm 9d7d1777e9628201980776bf1c3adfab i386/namazu-2.0.14-0.FC2.0.i386.rpm c153985afd1bc0463b03bb7e94e47119 i386/debug/namazu-debuginfo-2.0.14-0.FC2.0.i386.rpm 49189cc07b0ebf93c155dec09c7b0ff7 i386/namazu-devel-2.0.14-0.FC2.0.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Security fix release.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-558 2004-12-20 ---------------------------------------------------------------------Product : Fedora Core 3 Name : namazu Version : 2.0.14 Release : 0.FC3.0 Summary : Namazu is a full-text search engine Description : Namazu is a full-text search engine software intended for easy use. Not only it works as CGI program for small or medium scale WWW search engine, but also works as personal use such as search system for local HDD. ---------------------------------------------------------------------* Sat Dec 18 2004 Akira TAGOH - 2.0.14-0.FC3.0 - Security fix release. http://namazu.org/security.html ---------------------------------------------------------------------This update can be downloaded from: 75a5758a50c08939a000e8267d959ead SRPMS/namazu-2.0.14-0.FC3.0.src.rpm be0bfdaaa1d3bc50cf417cfd067347d6 x86_64/namazu-cgi-2.0.14-0.FC3.0.x86_64.rpm 8a778ca73e82070eb00bbe98535ce37c x86_64/namazu-2.0.14-0.FC3.0.x86_64.rpm b44c29bdfd49959bc464d13b959b36e4 x86_64/debug/namazu-debuginfo-2.0.14-0.FC3.0.x86_64.rpm 05b0e64dc65e40ce977aacca8c4b64db x86_64/namazu-devel-2.0.14-0.FC3.0.x86_64.rpm 4091b05eb2bb939ea45e8cac5f7ea3d4 i386/namazu-cgi-2.0.14-0.FC3.0.i386.rpm 71980c31c8a5ed2b82cb089405cb337f i386/namazu-2.0.14-0.FC3.0.i386.rpm f6c979c009ae51b15e85ff9bc8cc832c i386/debug/namazu-debuginfo-2.0.14-0.FC3.0.i386.rpm a808fed4d8d8535d1aea4ae789f82566 i386/namazu-devel-2.0.14-0.FC3.0.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Updated namazu packages are available for Red Hat Linux 7.0J. Thesepackages fix cross-site scripting vulnerabilities. It also fixes a possiblebuffer overflow.. `` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated namazu packages are available Advisory ID: RHSA-2001:179-05 Issue date: 2001-12-27 Updated on: 2002-01-09 Product: Red Hat Linux Keywords: namazu cross-site scripting buffer overflow Cross references: Obsoletes: RHSA-2001:162 --------------------------------------------------------------------- 1. Topic: Updated namazu packages are available for Red Hat Linux 7.0J. These packages fix cross-site scripting vulnerabilities. It also fixes a possible buffer overflow. 2. Relevant releases/architectures: Red Hat Linux 7.0J - i386 3. Problem description: Namazu is a full-text search engine. Namazu 2.0.9 and earlier may inadvertently include malicious HTML tags or scripts in a dynamically generated page, based on unvalidated input from untrustworthy sources. Also, a buffer overflow vulnerability exists in the buffer size of an environment variable. These packages update Namazu to version 2.0.10 which is not vulnerable to these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the followingcommand: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 7.0J: SRPMS: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 521c9faef31dcd865d3e0090cd023d70 7.0/ja/os/SRPMS/namazu-2.0.10-0j1.src.rpm ae5d586caf2098a0b9aefcc7af6522a9 7.0/ja/os/i386/namazu-2.0.10-0j1.i386.rpm 904dc3993c140794373471e8a1c64c61 7.0/ja/os/i386/namazu-cgi-2.0.10-0j1.i386.rpm af30f16968c527ac9e7669c812618cde 7.0/ja/os/i386/namazu-devel-2.0.10-0j1.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Namazu: a Full-Text Search Engine Copyright(c) 2000, 2001, 2002 Red Hat, Inc. _______________________________________________ Red Hat-watch-list mailing list To unsubscribe, visit: ``. The latest patches from Red Hat target security flaws such as cross-site scripting and a potential buffer overflow in the Namazu search feature.. Namazu Update, Red Hat Advisory, Security Fixes, Linux Packages. . Severity: Critical. LinuxSecurity.com Team
Updated namazu packages are available for Red Hat Linux 7.0J. Thesepackages fix cross-site scripting vulnerability.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated namazu packages are available Advisory ID: RHSA-2001:162-04 Issue date: 2001-12-03 Updated on: 2001-12-07 Product: Red Hat Linux Keywords: namazu cross-site scripting Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: Updated namazu packages are available for Red Hat Linux 7.0J. These packages fix cross-site scripting vulnerability. 2. Relevant releases/architectures: Red Hat Linux 7.0J - i386, noarch 3. Problem description: namazu may inadvertently include malicious HTML tags or script in a dynamically generated page based on unvalidated input from untrustworthy sources. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 7.0J: SRPMS: i386: noarch: 7. Verification: MD5 sum PackageName -------------------------------------------------------------------------- f91af7ba66f038d4a6ba310843ff8a47 7.0/ja/os/SRPMS/namazu-2.0.9-0j1.src.rpm 2e625ba5c4903cc7323bb47c5ecae74e 7.0/ja/os/SRPMS/perl-File-MMagic-1.13-1.src.rpm 3ccdb16142a0ae0db0a1abf1985d037e 7.0/ja/os/i386/namazu-2.0.9-0j1.i386.rpm 7de1feeb554ab8ce7c8ec8fc52d177f2 7.0/ja/os/i386/namazu-cgi-2.0.9-0j1.i386.rpm e34d70e1b82e2625a2b9f58998bbb7c1 7.0/ja/os/i386/namazu-devel-2.0.9-0j1.i386.rpm 7f68abfae1549924effa98fb3ce194f8 7.0/ja/os/noarch/perl-File-MMagic-1.13-1.noarch.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. Fresh namazu patches are rolled out for Red Hat Linux 7.0J, addressing a critical cross-site scripting flaw.. Namazu Security Update,Cross-Site Scripting Fix,Red Hat Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.