drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in tpp
Name: |
Ausführen beliebiger Kommandos in tpp |
|
ID: |
FEDORA-2014-1955 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 19 |
|
Datum: |
Mi, 12. Februar 2014, 07:48 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2208 |
|
Applikationen: |
tpp |
|
Originalnachricht |
Name : tpp Product : Fedora 19 Version : 1.3.1 Release : 17.fc19 URL : http://www.ngolde.de/tpp.html Summary : A ncurses-based presentation tool Description : tpp stands for text presentation program and is a ncurses-based presentation tool. The presentation can be written with your favorite editor in a simple description format and then shown on any text terminal that is supported by ncurses - ranging from an old VT100 to the Linux framebuffer to an xterm.
------------------------------------------------------------------------------- - Update Information:
977368: apply Adam Miller's patch correctly. (jesusr@redhat.com) 976686, 976687: Don't execute commands with --exec by default (abe@debian.org) ------------------------------------------------------------------------------- - ChangeLog:
* Fri Jan 31 2014 jesus m. rodriguez <jesusr@redhat.com> 1.3.1-17 - 977368: apply Adam Miller's patch correctly. (jesusr@redhat.com) - Remove dep on vim-filesystem for EPEL6, subpackage doesn't exist for EL6 (maxamillion@fedoraproject.org) - Fix ruby macros for EPEL6 (maxamillion@fedoraproject.org) * Sat Jan 18 2014 jesus m. rodriguez <jmrodri@gmail.com> 1.3.1-16 - 976686, 976687: add exec patch to spec file (jmrodri@gmail.com) - 976686, 976687: Don't execute commands with --exec by default (abe@debian.org) * Wed Jan 15 2014 jesus m. rodriguez <jmrodri@gmail.com> 1.3.1-15 - patch to make it work (jmrodri@gmail.com) * Wed Jan 15 2014 jesus m. rodriguez <jesusr@redhat.com> 1.3.1-14 - 977368: remove invalid vim-filesystem dependency (maxamillion@fedoraproject.org) * Sun Aug 4 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.1-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #977368 - tpp has invalid dependency on epel6 https://bugzilla.redhat.com/show_bug.cgi?id=977368 [ 2 ] Bug #976686 - CVE-2013-2208 tpp: Possibility of arbitrary code execution when processing untrusted TPP template [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=976686 [ 3 ] Bug #976687 - CVE-2013-2208 tpp: Possibility of arbitrary code execution when processing untrusted TPP template [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=976687 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update tpp' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|