Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in php-sabredav-Sabre_HTTP
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in php-sabredav-Sabre_HTTP
ID: FEDORA-2014-14066
Distribution: Fedora
Plattformen: Fedora 19
Datum: So, 23. November 2014, 11:13
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6403
Applikationen: php-sabredav-Sabre_HTTP

Originalnachricht

Name        : php-sabredav-Sabre_HTTP
Product : Fedora 19
Version : 1.7.11
Release : 1.fc19
URL : http://sabre.io
Summary : HTTP component for the SabreDAV WebDAV framework for PHP
Description :
Sabre_HTTP allows for a central interface to deal with Sabre.

-------------------------------------------------------------------------------
-
Update Information:

This update provides ownCloud 5.0.17, the latest release in the 5.x series,
plus an extra security-related fix backported from the stable5 branch.

It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV
1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.

ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to
known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 - ownCloud 7 - would likely fail.

I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the
5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.

Initial testing on the 4.x -> 5.x upgrade has been performed, but please
back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required.
-------------------------------------------------------------------------------
-
ChangeLog:

* Tue Oct 28 2014 Adam Williamson <awilliam@redhat.com> - 1.7.11-1
- new release 1.7.11 (from Sabre 1.7.13 EOL)
* Tue Sep 3 2013 Joseph Marrero <jmarrero@fedoraproject.org> - 1.7.3-1
- Update to 1.7.x Uptream version
- Add own pear configuration provided by Remi Collet from RH
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1035593 - CVE-2013-6403 owncloud: possible security bypass on
admin page (5.0.13) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1035593
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update php-sabredav-Sabre_HTTP' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Twitter
Neue Nachrichten
Werbung