[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[DONE] wml://{security/2018/dsa-4136.wml}



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- --- english/security/2018/dsa-4136.wml	2018-03-15 16:20:33.896549917 +0500
+++ russian/security/2018/dsa-4136.wml	2018-03-15 16:28:05.211963333 +0500
@@ -1,43 +1,45 @@
- -<define-tag description>security update</define-tag>
+#use wml::debian::translation-check translation="1.2" maintainer="Lev Lamberov"
+<define-tag description>обновление безопаÑ?ноÑ?Ñ?и</define-tag>
 <define-tag moreinfo>
- -<p>Multiple vulnerabilities were discovered in cURL, an URL transfer library.</p>
+<p>Ð? cURL, библиоÑ?еке пеÑ?едаÑ?и URL, бÑ?ли обнаÑ?Ñ?женÑ? многоÑ?иÑ?леннÑ?е Ñ?Ñ?звимоÑ?Ñ?и.</p>
 
 <ul>
 
 <li><a href="https://security-tracker.debian.org/tracker/CVE-2018-1000120";>CVE-2018-1000120</a>
 
- -    <p>Duy Phan Thanh discovered that curl could be fooled into writing a
- -    zero byte out of bounds when curl is told to work on an FTP URL with
- -    the setting to only issue a single CWD command, if the directory part
- -    of the URL contains a &ldquo;&#37;00&rdquo; sequence.</p></li>
+    <p>Ð?ай Фан Тан обнаÑ?Ñ?жил, Ñ?Ñ?о curl можеÑ? по оÑ?ибке запиÑ?аÑ?Ñ? нÑ?левой байÑ? за
+    пÑ?еделÑ? вÑ?деленного бÑ?Ñ?еÑ?а памÑ?Ñ?и, когда curl Ñ?абоÑ?аеÑ? по FTP URL пÑ?и
+    вÑ?боÑ?е наÑ?Ñ?Ñ?ойки по оÑ?пÑ?авке Ñ?олÑ?ко одной командÑ? CWD в Ñ?лÑ?Ñ?ае, еÑ?ли Ñ?аÑ?Ñ?Ñ? каÑ?алога
+    URL Ñ?одеÑ?жиÑ? поÑ?ледоваÑ?елÑ?ноÑ?Ñ?Ñ? &ldquo;&#37;00&rdquo;.</p></li>
 
 <li><a href="https://security-tracker.debian.org/tracker/CVE-2018-1000121";>CVE-2018-1000121</a>
 
- -    <p>Dario Weisser discovered that curl might dereference a near-NULL
- -    address when getting an LDAP URL due to the ldap_get_attribute_ber()
- -    function returning LDAP_SUCCESS and a NULL pointer. A malicious server
- -    might cause libcurl-using applications that allow LDAP URLs, or that
- -    allow redirects to LDAP URLs to crash.</p></li>
+    <p>Ð?аÑ?ио Ð?айзеÑ? обнаÑ?Ñ?жил, Ñ?Ñ?о curl можеÑ? вÑ?полнÑ?Ñ?Ñ? Ñ?азÑ?менование близкого к NULL
+    адÑ?еÑ?а пÑ?и полÑ?Ñ?ении LDAP URL из-за Ñ?ого, Ñ?Ñ?о Ñ?Ñ?нкÑ?иÑ? ldap_get_attribute_ber()
+    возвÑ?аÑ?аеÑ? LDAP_SUCCESS и NULL-Ñ?казаÑ?елÑ?. Ð?Ñ?едоноÑ?нÑ?й Ñ?еÑ?веÑ? можеÑ?
+    вÑ?зваÑ?Ñ? аваÑ?ийнÑ?Ñ? оÑ?Ñ?ановкÑ? иÑ?полÑ?зÑ?Ñ?Ñ?его libcurl пÑ?иложениÑ?, Ñ?азÑ?еÑ?аÑ?Ñ?его LDAP URL,
+    или Ñ?азÑ?еÑ?аÑ?Ñ?его пеÑ?енапÑ?авлениÑ? на LDAP URL.</p></li>
 
 <li><a href="https://security-tracker.debian.org/tracker/CVE-2018-1000122";>CVE-2018-1000122</a>
 
- -    <p>OSS-fuzz, assisted by Max Dymond, discovered that curl could be
- -    tricked into copying data beyond the end of its heap based buffer
- -    when asked to transfer an RTSP URL.</p></li>
+    <p>СоÑ?Ñ?Ñ?дники OSS-fuzz пÑ?и помоÑ?и Ð?акÑ?а Ð?аймонда обнаÑ?Ñ?жили, Ñ?Ñ?о
+    curl можеÑ? Ñ?копиÑ?оваÑ?Ñ? даннÑ?е за пÑ?еделами вÑ?деленного бÑ?Ñ?еÑ?а
+    динамиÑ?еÑ?кой памÑ?Ñ?и пÑ?и запÑ?оÑ?е пеÑ?едаÑ?и RTSP URL.</p></li>
 
 </ul>
 
- -<p>For the oldstable distribution (jessie), these problems have been fixed
- -in version 7.38.0-4+deb8u10.</p>
+<p>Ð? пÑ?едÑ?дÑ?Ñ?ем Ñ?Ñ?абилÑ?ном вÑ?пÑ?Ñ?ке (jessie) Ñ?Ñ?и пÑ?облемÑ? бÑ?ли иÑ?пÑ?авленÑ?
+в веÑ?Ñ?ии 7.38.0-4+deb8u10.</p>
 
- -<p>For the stable distribution (stretch), these problems have been fixed in
- -version 7.52.1-5+deb9u5.</p>
+<p>Ð? Ñ?Ñ?абилÑ?ном вÑ?пÑ?Ñ?ке (stretch) Ñ?Ñ?и пÑ?облемÑ? бÑ?ли иÑ?пÑ?авленÑ? в
+веÑ?Ñ?ии 7.52.1-5+deb9u5.</p>
 
- -<p>We recommend that you upgrade your curl packages.</p>
+<p>РекомендÑ?еÑ?Ñ?Ñ? обновиÑ?Ñ? пакеÑ?Ñ? curl.</p>
 
- -<p>For the detailed security status of curl please refer to
- -its security tracker page at:
- -<a href="https://security-tracker.debian.org/tracker/curl";>https://security-tracker.debian.org/tracker/curl</a></p>
+<p>С подÑ?обнÑ?м Ñ?Ñ?аÑ?Ñ?Ñ?ом поддеÑ?жки безопаÑ?ноÑ?Ñ?и curl можно ознакомиÑ?Ñ?Ñ?Ñ? на
+Ñ?ооÑ?веÑ?Ñ?Ñ?вÑ?Ñ?Ñ?ей Ñ?Ñ?Ñ?аниÑ?е оÑ?Ñ?леживаниÑ? безопаÑ?ноÑ?Ñ?и по адÑ?еÑ?Ñ?
+<a href="https://security-tracker.debian.org/tracker/curl";>\
+https://security-tracker.debian.org/tracker/curl</a></p>
 </define-tag>
 
 # do not modify the following line
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE3mumcdV9mwCc9oZQXudu4gIW0qUFAlqqWNIACgkQXudu4gIW
0qXC/w//U5u2gEsXK+TS891u766UzauIWKLDZqb8BbpllwkK6lzzwQfX79dGbZCH
5/w8Yrwm976vVNf202bUqjSjozWhU2mZRcZT2IitBA59xzUQSyhx5mKaZJw+9xDY
M4zRVGIpQxbrv68QNEIUCseqmzEgwdZBqaO9Vnq83MZHesVT1PgUbnQI7jznaCcM
KQp6eTRCw/QeyT86NxH9/m2rzURLHeuIiaOLMmydOfG/WuUvO9576IIr+8/xhj0S
K3GIgx3OstFJ4lBVh/U3Jj8ND3588DB33/ocXSFKKMFKzgq2DRgzPp1sEAyFL1ga
dliLEgM0KeKaeLrxRhz83IpuEkUlrbuu99EOdmHQFH9/J7bKBks0CzxLJuWJh9Qu
MyqIu8JPLt1523cs0Fw5f+l/mGb4Bpy1Qgpt9+mg3FvfHkp/k7stZx8UPlBYsqEf
gZAzOkH7LKL//AaCBMbHNlGIf6e/Q1n2va+JohlKeg7zSrD58jMLWeQ9NPGp5EID
eudv9ZLxXB9guUqWeJ+0AJm9ngELCv4gjFQyXLNNx9Ub2QQDePFgnOlwR3mlCQRG
kK3BffHuI9Ieucmnqifdp2k6i9BV237cxab7Qi4mM82z4e0GlRzyz0IpoP6vDagH
5fiiFFSO/LFvm87smm/wyBp3H7rbzaQ3+CTI8GfyLd55WvE8Ub0=
=p+x+
-----END PGP SIGNATURE-----


Reply to: