Fehlerhafte Zugriffsrechte in pulp-ostree
ID: | FEDORA-2016-f9db2293a8 |
Distribution: | Fedora |
Plattformen: | Fedora 24 |
Datum: | Di, 24. Mai 2016, 22:44 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3111 |
Applikationen: | Pulp |
Originalnachricht |
|
Name : pulp-ostree Product : Fedora 24 Version : 1.1.1 Release : 1.fc24 URL : https://github.com/pulp/pulp_ostree Summary : Support for OSTree content in the Pulp platform Description : Provides a collection of platform plugins and client extensions support for OSTree content. -------------------------------------------------------------------------------- Update Information: Update to Pulp 2.8.3, a security and bugfix update. ---- CVE-2016-3111: Protect the RSA keys during and after install (#1325693). -------------------------------------------------------------------------------- References: [ 1 ] Bug #1337309 - pulp 2.8.3 released https://bugzilla.redhat.com/show_bug.cgi?id=1337309 [ 2 ] Bug #1337311 - pulp-puppet 2.8.3 released https://bugzilla.redhat.com/show_bug.cgi?id=1337311 [ 3 ] Bug #1337312 - pulp-rpm 2.8.3 released https://bugzilla.redhat.com/show_bug.cgi?id=1337312 [ 4 ] Bug #1337315 - pulp-ostree 1.1.1 released https://bugzilla.redhat.com/show_bug.cgi?id=1337315 [ 5 ] Bug #1337316 - pulp-docker 2.0.1 released https://bugzilla.redhat.com/show_bug.cgi?id=1337316 [ 6 ] Bug #1337317 - pulp-python 1.1.1 released https://bugzilla.redhat.com/show_bug.cgi?id=1337317 [ 7 ] Bug #1325693 - /etc/pki/pulp/rsa.key is installed world readable https://bugzilla.redhat.com/show_bug.cgi?id=1325693 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update pulp-ostree' at the command line. For more information, refer to "Managing Software with yum", available at https://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org http://lists.fedoraproject.org/admin/lists/package-announce@lists.fedoraproject.org |