Ausführen beliebiger Kommandos in devscripts
ID: | FEDORA-2014-12947 |
Distribution: | Fedora |
Plattformen: | Fedora 21 |
Datum: | So, 2. November 2014, 20:56 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1833 |
Applikationen: | devscripts |
Originalnachricht |
|
Name : devscripts Product : Fedora 21 Version : 2.14.10 Release : 1.fc21 URL : https://packages.debian.org/sid/devscripts Summary : Scripts for Debian Package maintainers Description : Scripts to make the life of a Debian Package maintainer easier. -------------------------------------------------------------------------------- Update Information: Update to version 2.14.10, see http://metadata.ftp-master.debian.org/changelogs//main/d/devscripts/devscripts_2.14.10_changelog for details. Update to version 2.14.9, see http://metadata.ftp-master.debian.org/changelogs//main/d/devscripts/devscripts_2.14.9_changelog for details. Update to version 2.14.8, see http://metadata.ftp-master.debian.org/changelogs//main/d/devscripts/devscripts_2.14.8_changelog for details. Fixes CVE-2014-1833. Update to version 2.14.9, see http://metadata.ftp-master.debian.org/changelogs//main/d/devscripts/devscripts_2.14.9_changelog for details. Update to version 2.14.8, see http://metadata.ftp-master.debian.org/changelogs//main/d/devscripts/devscripts_2.14.8_changelog for details. Fixes CVE-2014-1833. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1059947 - CVE-2014-1833 devscripts: directory traversal flaw in uupdate https://bugzilla.redhat.com/show_bug.cgi?id=1059947 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update devscripts' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce |