drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in MHonArc
Name: |
Zwei Probleme in MHonArc |
|
ID: |
FEDORA-2011-3357 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 13 |
|
Datum: |
Do, 24. März 2011, 09:06 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1677
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4524 |
|
Applikationen: |
MHonArc |
|
Originalnachricht |
Name : mhonarc Product : Fedora 13 Version : 2.6.18 Release : 3.fc13 URL : http://www.mhonarc.org/ Summary : Perl mail-to-HTML converter Description : MHonArc is a Perl mail-to-HTML converter. MHonArc provides HTML mail archiving with index, mail thread linking, etc; plus other capabilities including support for MIME and powerful user customization features.
------------------------------------------------------------------------------- - Update Information:
Update to latest stable release:
- Fixes CVE-2010-1677 mhonarc: remote DoS via certain tags - Fixes CVE-2010-4524 MHonArc: Improper escaping of certain HTML sequences (XSS) - Fixes dealing with ISO-2022-JP charset. ------------------------------------------------------------------------------- - ChangeLog:
* Tue Mar 15 2011 José Matos <jamatos@fedoraproject.org> - 2.6.18-3 - Fix requires filter. * Sat Mar 12 2011 José Matos <jamatos@fedoraproject.org> - 2.6.18-2 - Take back the unwanted dependencies filter with new clothes. * Sat Mar 12 2011 José Matos <jamatos@fedoraproject.org> - 2.6.18-1 - Thanks to Jeff Schroeder for the ideas to fix the spec file (bz 664730) - New upstream release - Fixes CVE-2010-1677 and CVE-2010-4524 (bz 664730) - Use %{version} in Source - Simplify the filter usage for perl requirements * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.6.16-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #667478 - CVE-2010-1677 mhonarc: remote DoS via certain tags https://bugzilla.redhat.com/show_bug.cgi?id=667478 [ 2 ] Bug #664718 - CVE-2010-4524 MHonArc: Improper escaping of certain HTML sequences (XSS) https://bugzilla.redhat.com/show_bug.cgi?id=664718 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update mhonarc' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|