drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mangelnde Rechteprüfung in OwnCloud
Name: |
Mangelnde Rechteprüfung in OwnCloud |
|
ID: |
FEDORA-2014-14066 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 19 |
|
Datum: |
So, 23. November 2014, 11:13 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6403 |
|
Applikationen: |
OwnCloud |
|
Originalnachricht |
Name : owncloud Product : Fedora 19 Version : 5.0.17 Release : 2.fc19 URL : http://owncloud.org Summary : Private file sync and share server Description : ownCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. ownCloud is extendable via a simple but powerful API for applications and plugins.
------------------------------------------------------------------------------- - Update Information:
This update provides ownCloud 5.0.17, the latest release in the 5.x series, plus an extra security-related fix backported from the stable5 branch.
It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV 1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.
ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 - ownCloud 7 - would likely fail.
I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the 5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.
Initial testing on the 4.x -> 5.x upgrade has been performed, but please back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required. ------------------------------------------------------------------------------- - ChangeLog:
* Wed Oct 29 2014 Adam Williamson <awilliam@redhat.com> - 5.0.17-2 - drop db server deps, clean up docs, disable some admin checks (from master) * Tue Oct 28 2014 Adam Williamson <awilliam@redhat.com> - 5.0.17-1 - update to 5.0.17 (latest release) - backport a further security fix from upstream (HTTP redirects only) * Fri Dec 20 2013 Adam Williamson <awilliam@redhat.com> - 5.0.14a-2 * Correct location of php-symfony-routing: #1045301 * Fri Dec 20 2013 Adam Williamson <awilliam@redhat.com> - 5.0.14a-1 - 5.0.14a * Sat Nov 16 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 5.0.13-1 - 5.0.13 * Tue Oct 8 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 5.0.12-1 - 5.0.12 * Tue Sep 24 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 5.0.11-2 - keep MDB2/pgsql driver, genuine version causes upgrade problems (RBZ#962082) * Sat Sep 7 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 5.0.11-1 - 5.0.11 * Wed Sep 4 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 5.0.10-4 - unbundle sabredav again * Fri Aug 23 2013 Adam Williamson <awilliam@redhat.com> - 5.0.10-3 - patch mediaelement not to try and use its plugins * Fri Aug 23 2013 Adam Williamson <awilliam@redhat.com> - 5.0.10-2 - drop binary Flash and Silverlight blobs: #1000257 - don't ship source of jplayer in the binary package * Sun Aug 18 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 5.0.10-1 - 5.0.10 * Thu Aug 15 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 4.5.13-2 - RBZ #962082 keep 3rdparty pqsql mdb2 driver * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 5.0.9-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Tue Jul 23 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 5.0.9-2 - buildreq: php-pear (RBZ #987279) * Tue Jul 16 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 5.0.9-1 - major upgrade to 5.0.9 - symlink 3rdparty libs and drop most of the patches - new deps: php-ZendFramework symfony * Tue Jul 16 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 4.5.13-1 - 4.5.13 * Sat Jun 8 2013 Gregor Tätzner <brummbq@fedoraproject.org> - 4.5.12-1 - 4.5.12 ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #1035593 - CVE-2013-6403 owncloud: possible security bypass on admin page (5.0.13) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1035593 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update owncloud' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|