-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --- english/security/2016/dsa-3450.wml 2016-01-21 00:06:50.000000000 +0500 +++ russian/security/2016/dsa-3450.wml 2016-01-21 00:41:21.011936607 +0500 @@ -1,17 +1,18 @@ - -<define-tag description>security update</define-tag> +#use wml::debian::translation-check translation="1.1" maintainer="Lev Lamberov" +<define-tag description>обновление безопаÑноÑÑи</define-tag> <define-tag moreinfo> - -<p>Jann Horn discovered that the setuid-root mount.ecryptfs_private helper - -in the ecryptfs-utils would mount over any target directory that the - -user owns, including a directory in procfs. A local attacker could use - -this flaw to escalate his privileges.</p> +<p>Ян ХоÑн обнаÑÑжил, ÑÑо вÑпомогаÑелÑÐ½Ð°Ñ ÑÑилиÑа mount.ecryptfs_private, имеÑÑÐ°Ñ +Ñлаг пÑав доÑÑÑпа, позволÑÑÑий запÑÑкаÑÑ ÐµÑ Ð¾Ñ Ð»Ð¸Ñа ÑÑпеÑполÑзоваÑелÑ, из ÑоÑÑава ecryptfs-utils вÑполнÑÐµÑ +монÑиÑование в лÑбой Ñелевой каÑалог, владелÑÑем коÑоÑого ÑвлÑеÑÑÑ Ð¿Ð¾Ð»ÑзоваÑелÑ, вклÑÑÐ°Ñ ÐºÐ°Ñалог +в procfs. ÐокалÑнÑй злоÑмÑÑленник Ð¼Ð¾Ð¶ÐµÑ Ð¸ÑполÑзоваÑÑ ÑÑÑ ÑÑзвимоÑÑÑ Ð´Ð»Ñ Ð¿Ð¾Ð²ÑÑÐµÐ½Ð¸Ñ Ð¿Ñивилегий.</p> - -<p>For the oldstable distribution (wheezy), this problem has been fixed - -in version 99-1+deb7u1.</p> +<p>РпÑедÑдÑÑем ÑÑабилÑном вÑпÑÑке (wheezy) ÑÑа пÑоблема бÑла иÑпÑавлена +в веÑÑии 99-1+deb7u1.</p> - -<p>For the stable distribution (jessie), this problem has been fixed in - -version 103-5+deb8u1.</p> +<p>Ð ÑÑабилÑном вÑпÑÑке (jessie) ÑÑа пÑоблема бÑла иÑпÑавлена в +веÑÑии 103-5+deb8u1.</p> - -<p>We recommend that you upgrade your ecryptfs-utils packages.</p> +<p>РекомендÑеÑÑÑ Ð¾Ð±Ð½Ð¾Ð²Ð¸ÑÑ Ð¿Ð°ÐºÐµÑÑ ecryptfs-utils.</p> </define-tag> # do not modify the following line -----BEGIN PGP SIGNATURE-----
iQIcBAEBCgAGBQJWn+L+AAoJEF7nbuICFtKlUOkQAJwEhFlEFFBBk6nxkEz9JNdv jvr3ablbAxeMwiqoSTc4dJ/2m2g0NveSTmyQWgjrkUJDC01e7opTXuCAuJq6joMQ BMtvUOwcffObByLUb1r96JpmoTz99DYkxXtWQk9d+gg0HPuVCiJtxxMYxbpZ7Py6 oMOagaAp6w4Xkv2c8RmhgVERlWkemib02TbSPpWmOgnpVx3ksWEnyrbVjnzvOJcC ED//BM1E3tjgxtYPsJ5eQ8nXeXCyrDEOs/BIwzEtMwfjCLCJhfHd7wcrL1DvPL0m vfUxMQuI0URU6wPDgWSYrLA1a7eFyqgQmsmWnFP13u9t6rO7RgPY5YuFsDyF8QiI 1xueFeBrBONxzZJ46691dAMCJzfp+o/3PUQP11p0Cd61b5lrgBRYRPI0kL+5g9rp JVwCOAlp+hcW3wAbtfCncDrCXTYuKhLH6EYQVFZScl2k+lhZ2jXmnk/AgE36fIL5 9CLh4DGiiSBWJcEhynmwNjOuivLVua3NKjoGgxCrg1nIovIXklPUfPClzQLXBaFj izTYF2O+2CyrqM1SaunXNDH8mYaab60RNcYsBralLtt+HNGckfLwpTrgUyYSG+jY YRoBzlKlErkrzxvjZgUTYkVTxPC//HKsgN3Z8xxMufjKQkSpk8qVu5d9l8JDix17 4EP1VdH18XwNBNV0Xp2H =F0yV -----END PGP SIGNATURE-----

