-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --- english/security/2016/dsa-3469.wml 2016-02-09 01:11:45.000000000 +0500 +++ russian/security/2016/dsa-3469.wml 2016-02-09 15:06:22.291101891 +0500 @@ -1,84 +1,85 @@ - -<define-tag description>security update</define-tag> +#use wml::debian::translation-check translation="1.1" maintainer="Lev Lamberov" +<define-tag description>обновление безопаÑноÑÑи</define-tag> <define-tag moreinfo> - -<p>Several vulnerabilities were discovered in qemu, a full virtualization - -solution on x86 hardware.</p> +<p>Ð qemu, полном ÑеÑении Ð´Ð»Ñ Ð²Ð¸ÑÑÑализаÑии на обоÑÑдовании Ñ Ð°ÑÑ Ð¸ÑекÑÑÑой +x86, бÑло обнаÑÑжено неÑколÑко ÑÑзвимоÑÑей.</p> <ul> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7295">CVE-2015-7295</a> - - <p>Jason Wang of Red Hat Inc. discovered that the Virtual Network - - Device support is vulnerable to denial-of-service (via resource - - exhaustion), that could occur when receiving large packets.</p></li> + <p>ÐжейÑон Ðанг из Red Hat Inc. обнаÑÑжил, ÑÑо поддеÑжка Virtual Network + Device ÑÑзвима к оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за ÑÑезмеÑного поÑÑÐµÐ±Ð»ÐµÐ½Ð¸Ñ + ÑеÑÑÑÑов), коÑоÑое Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑоизойÑи пÑи полÑÑении болÑÑÐ¸Ñ Ð¿Ð°ÐºÐµÑов.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7504">CVE-2015-7504</a> - - <p>Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. - - discovered that the PC-Net II ethernet controller is vulnerable to - - a heap-based buffer overflow that could result in - - denial-of-service (via application crash) or arbitrary code - - execution.</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. и Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. + обнаÑÑжили, ÑÑо конÑÑÐ¾Ð»Ð»ÐµÑ PC-Net II ÑÑзвим к + пеÑÐµÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð´Ð¸Ð½Ð°Ð¼Ð¸ÑеÑкой памÑÑи, коÑоÑое пÑÐ¸Ð²Ð¾Ð´Ð¸Ñ Ðº + оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿Ñиложений) или вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ + пÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7512">CVE-2015-7512</a> - - <p>Ling Liu of Qihoo 360 Inc. and Jason Wang of Red Hat Inc. - - discovered that the PC-Net II ethernet controller is vulnerable to - - a buffer overflow that could result in denial-of-service (via - - application crash) or arbitrary code execution.</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. и ÐжейÑон Ðанг из Red Hat Inc. + обнаÑÑжили, ÑÑо конÑÑÐ¾Ð»Ð»ÐµÑ PC-Net II ÑÑзвим к + пеÑÐµÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð±ÑÑеÑа, коÑоÑое Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за + аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ) или вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8345">CVE-2015-8345</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the eepro100 - - emulator contains a flaw that could lead to an infinite loop when - - processing Command Blocks, eventually resulting in - - denial-of-service (via application crash).</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо ÑмÑлÑÑÐ¾Ñ eepro100 + ÑодеÑÐ¶Ð¸Ñ Ð¾ÑибкÑ, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº Ð²Ð¾Ð·Ð½Ð¸ÐºÐ½Ð¾Ð²ÐµÐ½Ð¸Ñ Ð±ÐµÑконеÑного Ñикла пÑи + обÑабоÑке команднÑÑ Ð±Ð»Ð¾ÐºÐ¾Ð² и вÑзÑваÑÑ + оÑказ в обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8504">CVE-2015-8504</a> - - <p>Lian Yihan of Qihoo 360 Inc. discovered that the VNC display - - driver support is vulnerable to an arithmetic exception flaw that - - could lead to denial-of-service (via application crash).</p></li> + <p>ÐÑÐ½Ñ ÐÑ Ð°Ð½Ñ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка диÑплейного дÑайвеÑа + VNC ÑÑзвима к аÑиÑмеÑиÑеÑÐºÐ¾Ð¼Ñ Ð¸ÑклÑÑениÑ, коÑоÑое Ð¼Ð¾Ð¶ÐµÑ + пÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8558">CVE-2015-8558</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the USB EHCI - - emulation support contains a flaw that could lead to an infinite - - loop during communication between the host controller and a device - - driver. This could lead to denial-of-service (via resource - - exhaustion).</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + USB EHCI ÑодеÑÐ¶Ð¸Ñ Ð¾ÑибкÑ, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº Ð²Ð¾Ð·Ð½Ð¸ÐºÐ½Ð¾Ð²ÐµÐ½Ð¸Ñ Ð±ÐµÑконеÑного + Ñикла пÑи взаимодейÑÑвии Ð¼ÐµÐ¶Ð´Ñ ÐºÐ¾Ð½ÑÑоллеÑом Ñзла и дÑайвеÑом + ÑÑÑÑойÑÑва. ÐÑа ÑÑзвимоÑÑÑ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за ÑÑезмеÑного + поÑÑÐµÐ±Ð»ÐµÐ½Ð¸Ñ ÑеÑÑÑÑов).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8743">CVE-2015-8743</a> - - <p>Ling Liu of Qihoo 360 Inc. discovered that the NE2000 emulator is - - vulnerable to an out-of-bound read/write access issue, potentially - - resulting in information leak or memory corruption.</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо ÑмÑлÑÑÐ¾Ñ NE2000 + ÑодеÑÐ¶Ð¸Ñ Ð¿ÑÐ¾Ð±Ð»ÐµÐ¼Ñ Ñ ÑÑением/запиÑÑÑ Ð·Ð° пÑеделами вÑделенного бÑÑеÑа памÑÑи, ÑÑо поÑенÑиалÑно + пÑÐ¸Ð²Ð¾Ð´Ð¸Ñ Ðº ÑÑеÑкам инÑоÑмаÑии или повÑÐµÐ¶Ð´ÐµÐ½Ð¸Ñ ÑодеÑжимого памÑÑи.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1568">CVE-2016-1568</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the IDE AHCI - - emulation support is vulnerable to a use-after-free issue, that - - could lead to denial-of-service (via application crash) or - - arbitrary code execution.</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + IDE AHCI ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² иÑполÑзовании ÑказаÑелей поÑле оÑÐ²Ð¾Ð±Ð¾Ð¶Ð´ÐµÐ½Ð¸Ñ Ð¿Ð°Ð¼ÑÑи, коÑоÑÐ°Ñ + Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ) или + вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1714">CVE-2016-1714</a> - - <p>Donghai Zhu of Alibaba discovered that the Firmware Configuration - - emulation support is vulnerable to an out-of-bound read/write - - access issue, that could lead to denial-of-service (via - - application crash) or arbitrary code execution.</p></li> + <p>ÐÑÐ½Ñ Ð°Ð¹ Ð§Ð¶Ñ Ð¸Ð· Alibaba обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + Firmware Configuration ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² ÑÑении/запиÑи за пÑеделами вÑделенного + бÑÑеÑа памÑÑи, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за + аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ) или вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1922">CVE-2016-1922</a> - - <p>Ling Liu of Qihoo 360 Inc. discovered that 32-bit Windows guests - - support is vulnerable to a null pointer dereference issue, that - - could lead to denial-of-service (via application crash).</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка 32-биÑнÑÑ Ð³Ð¾ÑÑевÑÑ ÑиÑÑем + Windows ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² ÑазÑменовании null-ÑказаÑелÑ, коÑоÑÐ°Ñ + Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> </ul> - -<p>For the oldstable distribution (wheezy), these problems have been fixed - -in version 1.1.2+dfsg-6a+deb7u12.</p> +<p>РпÑедÑдÑÑем ÑÑабилÑном вÑпÑÑке (wheezy) ÑÑи пÑÐ¾Ð±Ð»ÐµÐ¼Ñ Ð±Ñли иÑпÑÐ°Ð²Ð»ÐµÐ½Ñ +в веÑÑии 1.1.2+dfsg-6a+deb7u12.</p> - -<p>We recommend that you upgrade your qemu packages.</p> +<p>РекомендÑеÑÑÑ Ð¾Ð±Ð½Ð¾Ð²Ð¸ÑÑ Ð¿Ð°ÐºÐµÑÑ qemu.</p> </define-tag> # do not modify the following line - --- english/security/2016/dsa-3470.wml 2016-02-09 01:12:00.000000000 +0500 +++ russian/security/2016/dsa-3470.wml 2016-02-09 15:10:50.370880837 +0500 @@ -1,84 +1,85 @@ - -<define-tag description>security update</define-tag> +#use wml::debian::translation-check translation="1.1" maintainer="Lev Lamberov" +<define-tag description>обновление безопаÑноÑÑи</define-tag> <define-tag moreinfo> - -<p>Several vulnerabilities were discovered in qemu-kvm, a full - -virtualization solution on x86 hardware.</p> +<p>Ð qemu-kvm, полном ÑеÑении Ð´Ð»Ñ Ð²Ð¸ÑÑÑализаÑии на обоÑÑдовании Ñ Ð°ÑÑ Ð¸ÑекÑÑÑой +x86, бÑло обнаÑÑжено неÑколÑко ÑÑзвимоÑÑей.</p> <ul> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7295">CVE-2015-7295</a> - - <p>Jason Wang of Red Hat Inc. discovered that the Virtual Network - - Device support is vulnerable to denial-of-service (via resource - - exhaustion), that could occur when receiving large packets.</p></li> + <p>ÐжейÑон Ðанг из Red Hat Inc. обнаÑÑжил, ÑÑо поддеÑжка Virtual Network + Device ÑÑзвима к оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за ÑÑезмеÑного поÑÑÐµÐ±Ð»ÐµÐ½Ð¸Ñ + ÑеÑÑÑÑов), коÑоÑое Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑоизойÑи пÑи полÑÑении болÑÑÐ¸Ñ Ð¿Ð°ÐºÐµÑов.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7504">CVE-2015-7504</a> - - <p>Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. - - discovered that the PC-Net II ethernet controller is vulnerable to - - a heap-based buffer overflow that could result in - - denial-of-service (via application crash) or arbitrary code - - execution.</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. и Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. + обнаÑÑжили, ÑÑо конÑÑÐ¾Ð»Ð»ÐµÑ PC-Net II ÑÑзвим к + пеÑÐµÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð´Ð¸Ð½Ð°Ð¼Ð¸ÑеÑкой памÑÑи, коÑоÑое пÑÐ¸Ð²Ð¾Ð´Ð¸Ñ Ðº + оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿Ñиложений) или вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ + пÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7512">CVE-2015-7512</a> - - <p>Ling Liu of Qihoo 360 Inc. and Jason Wang of Red Hat Inc. - - discovered that the PC-Net II ethernet controller is vulnerable to - - a buffer overflow that could result in denial-of-service (via - - application crash) or arbitrary code execution.</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. и ÐжейÑон Ðанг из Red Hat Inc. + обнаÑÑжили, ÑÑо конÑÑÐ¾Ð»Ð»ÐµÑ PC-Net II ÑÑзвим к + пеÑÐµÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð±ÑÑеÑа, коÑоÑое Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за + аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ) или вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8345">CVE-2015-8345</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the eepro100 - - emulator contains a flaw that could lead to an infinite loop when - - processing Command Blocks, eventually resulting in - - denial-of-service (via application crash).</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо ÑмÑлÑÑÐ¾Ñ eepro100 + ÑодеÑÐ¶Ð¸Ñ Ð¾ÑибкÑ, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº Ð²Ð¾Ð·Ð½Ð¸ÐºÐ½Ð¾Ð²ÐµÐ½Ð¸Ñ Ð±ÐµÑконеÑного Ñикла пÑи + обÑабоÑке команднÑÑ Ð±Ð»Ð¾ÐºÐ¾Ð² и вÑзÑваÑÑ + оÑказ в обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8504">CVE-2015-8504</a> - - <p>Lian Yihan of Qihoo 360 Inc. discovered that the VNC display - - driver support is vulnerable to an arithmetic exception flaw that - - could lead to denial-of-service (via application crash).</p></li> + <p>ÐÑÐ½Ñ ÐÑ Ð°Ð½Ñ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка диÑплейного дÑайвеÑа + VNC ÑÑзвима к аÑиÑмеÑиÑеÑÐºÐ¾Ð¼Ñ Ð¸ÑклÑÑениÑ, коÑоÑое Ð¼Ð¾Ð¶ÐµÑ + пÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8558">CVE-2015-8558</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the USB EHCI - - emulation support contains a flaw that could lead to an infinite - - loop during communication between the host controller and a device - - driver. This could lead to denial-of-service (via resource - - exhaustion).</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + USB EHCI ÑодеÑÐ¶Ð¸Ñ Ð¾ÑибкÑ, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº Ð²Ð¾Ð·Ð½Ð¸ÐºÐ½Ð¾Ð²ÐµÐ½Ð¸Ñ Ð±ÐµÑконеÑного + Ñикла пÑи взаимодейÑÑвии Ð¼ÐµÐ¶Ð´Ñ ÐºÐ¾Ð½ÑÑоллеÑом Ñзла и дÑайвеÑом + ÑÑÑÑойÑÑва. ÐÑа ÑÑзвимоÑÑÑ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за ÑÑезмеÑного + поÑÑÐµÐ±Ð»ÐµÐ½Ð¸Ñ ÑеÑÑÑÑов).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8743">CVE-2015-8743</a> - - <p>Ling Liu of Qihoo 360 Inc. discovered that the NE2000 emulator is - - vulnerable to an out-of-bound read/write access issue, potentially - - resulting in information leak or memory corruption.</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо ÑмÑлÑÑÐ¾Ñ NE2000 + ÑодеÑÐ¶Ð¸Ñ Ð¿ÑÐ¾Ð±Ð»ÐµÐ¼Ñ Ñ ÑÑением/запиÑÑÑ Ð·Ð° пÑеделами вÑделенного бÑÑеÑа памÑÑи, ÑÑо поÑенÑиалÑно + пÑÐ¸Ð²Ð¾Ð´Ð¸Ñ Ðº ÑÑеÑкам инÑоÑмаÑии или повÑÐµÐ¶Ð´ÐµÐ½Ð¸Ñ ÑодеÑжимого памÑÑи.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1568">CVE-2016-1568</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the IDE AHCI - - emulation support is vulnerable to a use-after-free issue, that - - could lead to denial-of-service (via application crash) or - - arbitrary code execution.</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + IDE AHCI ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² иÑполÑзовании ÑказаÑелей поÑле оÑÐ²Ð¾Ð±Ð¾Ð¶Ð´ÐµÐ½Ð¸Ñ Ð¿Ð°Ð¼ÑÑи, коÑоÑÐ°Ñ + Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ) или + вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1714">CVE-2016-1714</a> - - <p>Donghai Zhu of Alibaba discovered that the Firmware Configuration - - emulation support is vulnerable to an out-of-bound read/write - - access issue, that could lead to denial-of-service (via - - application crash) or arbitrary code execution.</p></li> + <p>ÐÑÐ½Ñ Ð°Ð¹ Ð§Ð¶Ñ Ð¸Ð· Alibaba обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + Firmware Configuration ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² ÑÑении/запиÑи за пÑеделами вÑделенного + бÑÑеÑа памÑÑи, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за + аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ) или вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1922">CVE-2016-1922</a> - - <p>Ling Liu of Qihoo 360 Inc. discovered that 32-bit Windows guests - - support is vulnerable to a null pointer dereference issue, that - - could lead to denial-of-service (via application crash).</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка 32-биÑнÑÑ Ð³Ð¾ÑÑевÑÑ ÑиÑÑем + Windows ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² ÑазÑменовании null-ÑказаÑелÑ, коÑоÑÐ°Ñ + Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> </ul> - -<p>For the oldstable distribution (wheezy), these problems have been fixed - -in version 1.1.2+dfsg-6+deb7u12.</p> +<p>РпÑедÑдÑÑем ÑÑабилÑном вÑпÑÑке (wheezy) ÑÑи пÑÐ¾Ð±Ð»ÐµÐ¼Ñ Ð±Ñли иÑпÑÐ°Ð²Ð»ÐµÐ½Ñ +в веÑÑии 1.1.2+dfsg-6+deb7u12.</p> - -<p>We recommend that you upgrade your qemu-kvm packages.</p> +<p>РекомендÑеÑÑÑ Ð¾Ð±Ð½Ð¾Ð²Ð¸ÑÑ Ð¿Ð°ÐºÐµÑÑ qemu-kvm.</p> </define-tag> # do not modify the following line - --- english/security/2016/dsa-3471.wml 2016-02-09 14:11:13.000000000 +0500 +++ russian/security/2016/dsa-3471.wml 2016-02-09 15:22:06.879037056 +0500 @@ -1,133 +1,134 @@ - -<define-tag description>security update</define-tag> +#use wml::debian::translation-check translation="1.3" maintainer="Lev Lamberov" +<define-tag description>обновление безопаÑноÑÑи</define-tag> <define-tag moreinfo> - -<p>Several vulnerabilities were discovered in qemu, a full virtualization - -solution on x86 hardware.</p> +<p>Ð qemu, полном ÑеÑении Ð´Ð»Ñ Ð²Ð¸ÑÑÑализаÑии на обоÑÑдовании Ñ Ð°ÑÑ Ð¸ÑекÑÑÑой +x86, бÑло обнаÑÑжено неÑколÑко ÑÑзвимоÑÑей.</p> <ul> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7295">CVE-2015-7295</a> - - <p>Jason Wang of Red Hat Inc. discovered that the Virtual Network - - Device support is vulnerable to denial-of-service, that could - - occur when receiving large packets.</p></li> + <p>ÐжейÑон Ðанг из Red Hat Inc. обнаÑÑжил, ÑÑо поддеÑжка Virtual Network + Device ÑÑзвима к оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за ÑÑезмеÑного поÑÑÐµÐ±Ð»ÐµÐ½Ð¸Ñ + ÑеÑÑÑÑов), коÑоÑое Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑоизойÑи пÑи полÑÑении болÑÑÐ¸Ñ Ð¿Ð°ÐºÐµÑов.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7504">CVE-2015-7504</a> - - <p>Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. - - discovered that the PC-Net II ethernet controller is vulnerable to - - a heap-based buffer overflow that could result in - - denial-of-service (via application crash) or arbitrary code - - execution.</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. и Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. + обнаÑÑжили, ÑÑо конÑÑÐ¾Ð»Ð»ÐµÑ PC-Net II ÑÑзвим к + пеÑÐµÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð´Ð¸Ð½Ð°Ð¼Ð¸ÑеÑкой памÑÑи, коÑоÑое пÑÐ¸Ð²Ð¾Ð´Ð¸Ñ Ðº + оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿Ñиложений) или вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ + пÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7512">CVE-2015-7512</a> - - <p>Ling Liu of Qihoo 360 Inc. and Jason Wang of Red Hat Inc. - - discovered that the PC-Net II ethernet controller is vulnerable to - - a buffer overflow that could result in denial-of-service (via - - application crash) or arbitrary code execution.</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. и ÐжейÑон Ðанг из Red Hat Inc. + обнаÑÑжили, ÑÑо конÑÑÐ¾Ð»Ð»ÐµÑ PC-Net II ÑÑзвим к + пеÑÐµÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð±ÑÑеÑа, коÑоÑое Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за + аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ) или вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-7549">CVE-2015-7549</a> - - <p>Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 - - Inc. discovered that the PCI MSI-X emulator is vulnerable to a - - null pointer dereference issue, that could lead to - - denial-of-service (via application crash).</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. и Ðин ÐÑ Ð¸Ð· Qihoo 360 + Inc. обнаÑÑжили, ÑÑо ÑмÑлÑÑÐ¾Ñ PCI MSI-X ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² + ÑазÑменовании null-ÑказаÑелÑ, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº + оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8345">CVE-2015-8345</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the eepro100 - - emulator contains a flaw that could lead to an infinite loop when - - processing Command Blocks, eventually resulting in - - denial-of-service (via application crash).</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо ÑмÑлÑÑÐ¾Ñ eepro100 + ÑодеÑÐ¶Ð¸Ñ Ð¾ÑибкÑ, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº Ð²Ð¾Ð·Ð½Ð¸ÐºÐ½Ð¾Ð²ÐµÐ½Ð¸Ñ Ð±ÐµÑконеÑного Ñикла пÑи + обÑабоÑке команднÑÑ Ð±Ð»Ð¾ÐºÐ¾Ð² и вÑзÑваÑÑ + оÑказ в обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8504">CVE-2015-8504</a> - - <p>Lian Yihan of Qihoo 360 Inc. discovered that the VNC display - - driver support is vulnerable to an arithmetic exception flaw that - - could lead to denial-of-service (via application crash).</p></li> + <p>ÐÑÐ½Ñ ÐÑ Ð°Ð½Ñ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка диÑплейного дÑайвеÑа + VNC ÑÑзвима к аÑиÑмеÑиÑеÑÐºÐ¾Ð¼Ñ Ð¸ÑклÑÑениÑ, коÑоÑое Ð¼Ð¾Ð¶ÐµÑ + пÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8550">CVE-2015-8550</a> - - <p>Felix Wilhelm of ERNW Research discovered that the PV backend drivers are - - vulnerable to double fetch vulnerabilities, possibly resulting in - - arbitrary code execution.</p></li> + <p>Ð¤ÐµÐ»Ð¸ÐºÑ ÐилÑгелÑм из ERNW Research обнаÑÑжил, ÑÑо двайвеÑÑ Ð´Ð²Ð¸Ð¶ÐºÐ° PV ÑодеÑÐ¶Ð°Ñ + пÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² двойном извлеÑении, коÑоÑÐ°Ñ Ð²Ð¾Ð·Ð¼Ð¾Ð¶Ð½Ð¾ пÑÐ¸Ð²Ð¾Ð´Ð¸Ñ Ðº + вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8558">CVE-2015-8558</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the USB EHCI - - emulation support contains a flaw that could lead to an infinite - - loop during communication between the host controller and a device - - driver. This could lead to denial-of-service (via resource - - exhaustion).</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + USB EHCI ÑодеÑÐ¶Ð¸Ñ Ð¾ÑибкÑ, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº Ð²Ð¾Ð·Ð½Ð¸ÐºÐ½Ð¾Ð²ÐµÐ½Ð¸Ñ Ð±ÐµÑконеÑного + Ñикла пÑи взаимодейÑÑвии Ð¼ÐµÐ¶Ð´Ñ ÐºÐ¾Ð½ÑÑоллеÑом Ñзла и дÑайвеÑом + ÑÑÑÑойÑÑва. ÐÑа ÑÑзвимоÑÑÑ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за ÑÑезмеÑного + поÑÑÐµÐ±Ð»ÐµÐ½Ð¸Ñ ÑеÑÑÑÑов).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8567">CVE-2015-8567</a> <a href="https://security-tracker.debian.org/tracker/CVE-2015-8568">CVE-2015-8568</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the vmxnet3 device - - emulator could be used to intentionally leak host memory, thus - - resulting in denial-of-service.</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо ÑмÑлÑÑÐ¾Ñ ÑÑÑÑойÑÑв + vmxnet3 Ð¼Ð¾Ð¶ÐµÑ Ð¸ÑполÑзоваÑÑÑÑ Ð´Ð»Ñ Ð½Ð°Ð¼ÐµÑенной ÑÑеÑки памÑÑи главной маÑинÑ, ÑÑо + пÑÐ¸Ð²Ð¾Ð´Ð¸Ñ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8613">CVE-2015-8613</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the SCSI MegaRAID - - SAS HBA emulation support is vulnerable to a stack-based buffer - - overflow issue, that could lead to denial-of-service (via - - application crash).</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + SCSI MegaRAID SAS HBA ÑÑзвима к пеÑÐµÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð±ÑÑеÑа, + коÑоÑое Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за + аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8619">CVE-2015-8619</a> - - <p>Ling Liu of Qihoo 360 Inc. discovered that the Human Monitor - - Interface support is vulnerable to an out-of-bound write access - - issue that could result in denial-of-service (via application - - crash).</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка Human Monitor + Interface ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² ÑÑении/запиÑи за пÑеделами вÑделенного бÑÑеÑа + памÑÑи, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ + ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8743">CVE-2015-8743</a> - - <p>Ling Liu of Qihoo 360 Inc. discovered that the NE2000 emulator is - - vulnerable to an out-of-bound read/write access issue, potentially - - resulting in information leak or memory corruption.</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо ÑмÑлÑÑÐ¾Ñ NE2000 + ÑодеÑÐ¶Ð¸Ñ Ð¿ÑÐ¾Ð±Ð»ÐµÐ¼Ñ Ñ ÑÑением/запиÑÑÑ Ð·Ð° пÑеделами вÑделенного бÑÑеÑа памÑÑи, ÑÑо поÑенÑиалÑно + пÑÐ¸Ð²Ð¾Ð´Ð¸Ñ Ðº ÑÑеÑкам инÑоÑмаÑии или повÑÐµÐ¶Ð´ÐµÐ½Ð¸Ñ ÑодеÑжимого памÑÑи.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8744">CVE-2015-8744</a> - - <p>The vmxnet3 driver incorrectly processes small packets, which could - - result in denial-of-service (via application crash).</p></li> + <p>ÐÑÐ°Ð¹Ð²ÐµÑ vmxnet3 некоÑÑекÑно обÑабаÑÑÐ²Ð°ÐµÑ Ð½ÐµÐ±Ð¾Ð»ÑÑие пакеÑÑ, ÑÑо Ð¼Ð¾Ð¶ÐµÑ + пÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2015-8745">CVE-2015-8745</a> - - <p>The vmxnet3 driver incorrectly processes Interrupt Mask Registers, - - which could result in denial-of-service (via application crash).</p></li> + <p>ÐÑÐ°Ð¹Ð²ÐµÑ vmxnet3 некоÑÑекÑно обÑабаÑÑÐ²Ð°ÐµÑ Ð¼Ð°Ñки пÑеÑÑваний ÑегиÑÑÑов, + ÑÑо Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1568">CVE-2016-1568</a> - - <p>Qinghao Tang of Qihoo 360 Inc. discovered that the IDE AHCI - - emulation support is vulnerable to a use-after-free issue, that - - could lead to denial-of-service (via application crash) or - - arbitrary code execution.</p></li> + <p>Ð¦Ð¸Ð½Ñ Ð°Ð¾ Тан из Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + IDE AHCI ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² иÑполÑзовании ÑказаÑелей поÑле оÑÐ²Ð¾Ð±Ð¾Ð¶Ð´ÐµÐ½Ð¸Ñ Ð¿Ð°Ð¼ÑÑи, коÑоÑÐ°Ñ + Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ) или + вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1714">CVE-2016-1714</a> - - <p>Donghai Zhu of Alibaba discovered that the Firmware Configuration - - emulation support is vulnerable to an out-of-bound read/write - - access issue, that could lead to denial-of-service (via - - application crash) or arbitrary code execution.</p></li> + <p>ÐÑÐ½Ñ Ð°Ð¹ Ð§Ð¶Ñ Ð¸Ð· Alibaba обнаÑÑжил, ÑÑо поддеÑжка ÑмÑлÑÑии + Firmware Configuration ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² ÑÑении/запиÑи за пÑеделами вÑделенного + бÑÑеÑа памÑÑи, коÑоÑÐ°Ñ Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за + аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ) или вÑÐ¿Ð¾Ð»Ð½ÐµÐ½Ð¸Ñ Ð¿ÑоизволÑного кода.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1922">CVE-2016-1922</a> - - <p>Ling Liu of Qihoo 360 Inc. discovered that 32-bit Windows guests - - support is vulnerable to a null pointer dereference issue, that - - could lead to denial-of-service (via application crash).</p></li> + <p>Ðин ÐÑ Ð¸Ð· Qihoo 360 Inc. обнаÑÑжил, ÑÑо поддеÑжка 32-биÑнÑÑ Ð³Ð¾ÑÑевÑÑ ÑиÑÑем + Windows ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, ÑоÑÑоÑÑÑÑ Ð² ÑазÑменовании null-ÑказаÑелÑ, коÑоÑÐ°Ñ + Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-1981">CVE-2016-1981</a> - - <p>The e1000 driver is vulnerable to an infinite loop issue that - - could lead to denial-of-service (via application crash).</p></li> + <p>ÐÑÐ°Ð¹Ð²ÐµÑ e1000 ÑодеÑÐ¶Ð¸Ñ Ð¿ÑоблемÑ, пÑиводÑÑÑÑ Ðº Ð²Ð¾Ð·Ð½Ð¸ÐºÐ½Ð¾Ð²ÐµÐ½Ð¸Ñ Ð±ÐµÑконеÑного Ñикла, ÑÑо + Ð¼Ð¾Ð¶ÐµÑ Ð¿ÑиводиÑÑ Ðº оÑÐºÐ°Ð·Ñ Ð² обÑлÑживании (из-за аваÑийного завеÑÑÐµÐ½Ð¸Ñ ÑабоÑÑ Ð¿ÑиложениÑ).</p></li> </ul> - -<p>For the stable distribution (jessie), these problems have been fixed in - -version 1:2.1+dfsg-12+deb8u5a.</p> +<p>Ð ÑÑабилÑном вÑпÑÑке (jessie) ÑÑи пÑÐ¾Ð±Ð»ÐµÐ¼Ñ Ð±Ñли иÑпÑÐ°Ð²Ð»ÐµÐ½Ñ Ð² +веÑÑии 1:2.1+dfsg-12+deb8u5a.</p> - -<p>We recommend that you upgrade your qemu packages.</p> +<p>РекомендÑеÑÑÑ Ð¾Ð±Ð½Ð¾Ð²Ð¸ÑÑ Ð¿Ð°ÐºÐµÑÑ qemu.</p> </define-tag> # do not modify the following line - --- english/security/2016/dsa-3472.wml 2016-02-09 01:27:33.000000000 +0500 +++ russian/security/2016/dsa-3472.wml 2016-02-09 15:24:40.109361766 +0500 @@ -1,32 +1,33 @@ - -<define-tag description>security update</define-tag> +#use wml::debian::translation-check translation="1.1" maintainer="Lev Lamberov" +<define-tag description>обновление безопаÑноÑÑи</define-tag> <define-tag moreinfo> - -<p>Two vulnerabilities were discovered in wordpress, a web blogging tool. - -The Common Vulnerabilities and Exposures project identifies the - -following problems:</p> +<p>Ð wordpress, инÑÑÑÑменÑе Ð²ÐµÐ´ÐµÐ½Ð¸Ñ Ð±Ð»Ð¾Ð³Ð°, бÑло обнаÑÑжено две ÑÑзвимоÑÑи. +ÐÑÐ¾ÐµÐºÑ Common Vulnerabilities and Exposures опÑеделÑÐµÑ +ÑледÑÑÑие пÑоблемÑ:</p> <ul> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-2221">CVE-2016-2221</a> - - <p>Shailesh Suthar discovered an open redirection vulnerability.</p></li> + <p>Ð¨Ð°Ð»ÐµÑ Ð¡ÑÑÐ°Ñ Ð¾Ð±Ð½Ð°ÑÑжил ÑÑзвимоÑÑÑ, ÑоÑÑоÑÑÑÑ Ð² оÑкÑÑÑом пеÑенапÑавлении.</p></li> <li><a href="https://security-tracker.debian.org/tracker/CVE-2016-2222">CVE-2016-2222</a> - - <p>Ronni Skansing discovered a server-side request forgery (SSRF) - - vulnerability.</p></li> + <p>Ронни СканÑинг обнаÑÑжил Ð¿Ð¾Ð´Ð´ÐµÐ»ÐºÑ Ð·Ð°Ð¿ÑоÑа на ÑÑоÑоне + ÑеÑвеÑа (SSRF).</p></li> </ul> - -<p>For the oldstable distribution (wheezy), these problems have been fixed - -in version 3.6.1+dfsg-1~deb7u10.</p> +<p>РпÑедÑдÑÑем ÑÑабилÑном вÑпÑÑке (wheezy) ÑÑи пÑÐ¾Ð±Ð»ÐµÐ¼Ñ Ð±Ñли иÑпÑÐ°Ð²Ð»ÐµÐ½Ñ +в веÑÑии 3.6.1+dfsg-1~deb7u10.</p> - -<p>For the stable distribution (jessie), these problems have been fixed in - -version 4.1+dfsg-1+deb8u8.</p> +<p>Ð ÑÑабилÑном вÑпÑÑке (jessie) ÑÑи пÑÐ¾Ð±Ð»ÐµÐ¼Ñ Ð±Ñли иÑпÑÐ°Ð²Ð»ÐµÐ½Ñ Ð² +веÑÑии 4.1+dfsg-1+deb8u8.</p> - -<p>For the unstable distribution (sid), these problems have been fixed in - -version 4.4.2+dfsg-1.</p> +<p>РнеÑÑабилÑном вÑпÑÑке (sid) ÑÑи пÑÐ¾Ð±Ð»ÐµÐ¼Ñ Ð±Ñли иÑпÑÐ°Ð²Ð»ÐµÐ½Ñ Ð² +веÑÑии 4.4.2+dfsg-1.</p> - -<p>We recommend that you upgrade your wordpress packages.</p> +<p>РекомендÑеÑÑÑ Ð¾Ð±Ð½Ð¾Ð²Ð¸ÑÑ Ð¿Ð°ÐºÐµÑÑ wordpress.</p> </define-tag> # do not modify the following line -----BEGIN PGP SIGNATURE-----
iQIcBAEBCgAGBQJWub5tAAoJEF7nbuICFtKl8DwP/31eYStODtVU4X1mvWfTgVIx C9ffzeBTh/R3NZMi4O4DaMaQUixvjbBc74vdfG+5gRcJzvkglhbNN9ZIKYzyMuFv CI87YF4/CdiH0iyCh4qKfYbqHKuGP+8Ksl+SCUVNide8K7y6gUOQXcHsa6MuEdNo EMtNh2EHEq0UlENK2oBoGabC20cqRIcz+aR4HKHHqL3XVpKXUyNfyminIKlVKaDB 0aZAVVUtA1uzAL+HDro/AbZO/7TKvZllxRcPfwDAn36rTIJjjp9VB/dKfT7Ni1ri /nrrTs05j++1wSBTC58qRTDUnUVxid9HCeOHRxFRIlcpzs3hViK0yMg8lSIXAUri wgH1QilhVxgr80nikDvMsoIaJiz3xodMRnXV8pwDP25L3n5AggCDC/yb6duM7sX2 e/OCWvO0cpvw3YKRsrGxvORUBIYxTAA3eMNu9YgZqltJl9SKMGVcbrbnbKW+GLSq ZgubYnlKyCVCEloUz8ZjlIjuj04qUjHUmUYsbXVi164/phkOzj86tQ8C0UayoP+A rtieTxkOR6oYY2Eh/6YG2hq+FE431FiGOlMVcsndEnHim6b+n16CAHm1jQzrvI/H yH69jUel45mjJzZdZxbcPL7CIRnOhusGssv+Jt0knBkKHM6VKoFpTLRZZcfJhVmY RaDGs3ei5x9jDG2Ujlgl =u0O6 -----END PGP SIGNATURE-----

