Otklonjeni su brojni propusti programskog paketa python-djblets koje udaljeni napadači mogu iskoristiti, između ostalog, za umetanje proizvoljnog HTML i skriptnog koda te izvođenje DoS napada.
Paket: | python-djblets 0.X |
Operacijski sustavi: | Fedora 16, Fedora 17 |
Problem: | pogreška u programskoj komponenti, XSS |
Iskorištavanje: | udaljeno |
Posljedica: | umetanje HTML i skriptnog koda, uskraćivanje usluga (DoS) |
Rješenje: | programska zakrpa proizvođača |
CVE: | CVE-2009-5065, CVE-2011-1156, CVE-2011-1157, CVE-2011-1158 |
Izvorni ID preporuke: | FEDORA-2012-11668 |
Izvor: | Fedora |
Problem: | |
Propusti nastaju zbog korištenja vlastite inačice python-feedparser koda koja sadržava brojne ranjivosti. |
|
Posljedica: | |
Propuste je moguće iskoristiti za izvođenje DoS napada te umetanje HTML i skriptnog koda. |
|
Rješenje: | |
Svim korisnicima se savjetuje korištenje službene nadogradnje. |
Izvorni tekst preporuke
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-11668
2012-08-09 22:17:53
--------------------------------------------------------------------------------
Name : python-djblets
Product : Fedora 17
Version : 0.7.1
Release : 3.fc17
URL : http://www.review-board.org
Summary : A collection of useful classes and functions for Django
Description :
A collection of useful classes and functions for Django
--------------------------------------------------------------------------------
Update Information:
Previous version of python-djblets contained embedded / own copy of
python-feedparser (BUILD/Djblets-0.6.22/djblets/feedview feedparser.py) code,
which is vulnerable to numerous security flaws (CVE-2009-5065, CVE-2011-1156,
CVE-2011-1157, and CVE-2011-1158 to mention some of them).
This package modifies Djblets to use the system copy of feedparser.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 8 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.1-3
- Use the system feedparser.py
- Resolves: rhbz#846759 - Current version of python-djblets in Fedora 17
contains embeded copy of python-feedparser, vulnerable to CVE-2009-5065,
CVE-2011-1156, CVE-2011-1157, and CVE-2011-1158
* Fri Aug 3 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.7.1-1
- New upstream release 0.7.1
- Support for ReviewBoard 1.7beta1
- General:
- Djblets now requires Django 1.4.1+
- Added localized timezone awareness
- Djblets now uses Django's standard static media support
- djblets.datagrid:
- DateTimeColumn and DateTimeSinceColumn are now timezone-aware
- djblets.extensions:
- Added a framework for supporting loadable, configurable extensions in
Django-based sites
- djblets.util:
- ModificationTimestampField, http_date, and the the ageid filter have
been made timezone-aware
* Tue Jul 31 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.22-1
- New upstream releae 0.6.22
- Fixes to support Review Board 1.6.11
- djblets.datagrid:
- Improved performance of the datagrids
- djblets.util:
- The ifuserorperm template tag now accepts both IDs and User
objects, allowing comparisons to be made without fetching the
User
- Fixed a bug with ifuserorperm and non-int IDs
- User and AnonymousUser are no longer imported globally in
the djblets_utils templatetags. This fixes some breakages in
apps that imported this file to get access to filters, but weren't
running in a Django settings environment
* Sat Jul 21 2012 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> -
0.6.19-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
* Tue Jun 12 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.19-1
- New upstream release 0.6.19
- JavaScript:
- inlineEditor no longer bubbles keypress events up
* Tue Jun 5 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.18-1
- New upstream release 0.6.18
- djblets.siteconfig:
- Settings form rows in the template now have IDs indicating the row and
CSS class names
- Help text for fields are now marked as safe, so that the contents
aren't escaped
- The form's disabled_reasons is no longer assumed to be populated
- The initial field values are now always set
- djblets.util:
- Added a json_dumps filter, which serialized a value to JSON
* Wed Apr 25 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.17-2
- Fix Django requirement for F18+
- Guarantee rebuild of egg-info
* Wed Apr 25 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.17-1
- New upstream release 0.6.17
- djblets.gravatars:
- Gravatars are no longer hard-coded to be jpegs. This was breaking some
gravatars.
- JavaScript:
- inlineEditor now has a showRequiredFlag option for indicating if a field
is required.
- inlineEditor now indicates when its dirty state changes
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #846759 - Current version of python-djblets in Fedora-17 contains
embeded copy of python-feedparser, vulnerable to CVE-2009-5065, CVE-2011-1156,
CVE-2011-1157, and CVE-2011-1158
https://bugzilla.redhat.com/show_bug.cgi?id=846759
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update python-djblets' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-11576
2012-08-09 22:03:40
--------------------------------------------------------------------------------
Name : python-djblets
Product : Fedora 16
Version : 0.6.22
Release : 2.fc16
URL : http://www.review-board.org
Summary : A collection of useful classes and functions for Django
Description :
A collection of useful classes and functions for Django
--------------------------------------------------------------------------------
Update Information:
Previous version of python-djblets contained embedded / own copy of
python-feedparser (BUILD/Djblets-0.6.22/djblets/feedview feedparser.py) code,
which is vulnerable to numerous security flaws (CVE-2009-5065, CVE-2011-1156,
CVE-2011-1157, and CVE-2011-1158 to mention some of them).
This package modifies Djblets to use the system copy of feedparser.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 8 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.22-2
- Use the system feedparser.py
* Tue Jul 31 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.22-1
- New upstream releae 0.6.22
- Fixes to support Review Board 1.6.11
- djblets.datagrid:
- Improved performance of the datagrids
- djblets.util:
- The ifuserorperm template tag now accepts both IDs and User
objects, allowing comparisons to be made without fetching the
User
- Fixed a bug with ifuserorperm and non-int IDs
- User and AnonymousUser are no longer imported globally in
the djblets_utils templatetags. This fixes some breakages in
apps that imported this file to get access to filters, but weren't
running in a Django settings environment
* Sat Jul 21 2012 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> -
0.6.19-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
* Tue Jun 12 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.19-1
- New upstream release 0.6.19
- JavaScript:
- inlineEditor no longer bubbles keypress events up
* Tue Jun 5 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.18-1
- New upstream release 0.6.18
- djblets.siteconfig:
- Settings form rows in the template now have IDs indicating the row and
CSS class names
- Help text for fields are now marked as safe, so that the contents
aren't escaped
- The form's disabled_reasons is no longer assumed to be populated
- The initial field values are now always set
- djblets.util:
- Added a json_dumps filter, which serialized a value to JSON
* Wed Apr 25 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.17-2
- Fix Django requirement for F18+
- Guarantee rebuild of egg-info
* Wed Apr 25 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.17-1
- New upstream release 0.6.17
- djblets.gravatars:
- Gravatars are no longer hard-coded to be jpegs. This was breaking some
gravatars.
- JavaScript:
- inlineEditor now has a showRequiredFlag option for indicating if a field
is required.
- inlineEditor now indicates when its dirty state changes
* Mon Feb 27 2012 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.16-1
- New upstream release 0.6.16
- djblets.pipeline:
- Replaced the djblets.compress module with djblets.pipeline.
- djblets.util:
- Fixed Django 1.4 compatibility.
- Fix parsing of tokens in a blocktag in Django 1.4
- djblets.datagrid:
- Removed an extraneous </span> in the paginator
- Fixed a compatibility issue with Django 1.4 in the queries
- djblets.webapi:
- Add support for resource-specific mimetypes
- Accept "true" as a valid boolean value in the web API
* Sat Jan 14 2012 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> -
0.6.14-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Thu Nov 10 2011 Stephen Gallagher <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.6.14-1
- New upstream release
- djblets.testing:
- Added a new TestCase class and @add_fixtures decorator for having
fixtures specific to text functions.
- djblets.util:
- Fixed defaults on counter fields on new model instances.
- Added a controlled_subprocess context manager for Python 2.5+.
- Moved controlled_subprocess into djblets.util.contextmanagers.
- Fixed a syntax error in controlled_subprocess on Python 2.4 and 2.5.
- The jQuery and jQuery-UI versions are now referenced in only one place,
in js/jquery.html and js/jquery-ui.html. Other templates can include
these and keep up-to-date with the versions Djblets provides.
- djblets.log:
- Allow logging page access times.
- Include the HTTP method in the new page request logs.
- djblets.webapi:
- API authorization failures, misparsed headers, and authorization attempts
are now logged.
- Fixed authentication failures when ":" was in the password.
- djblets.compress:
- Added a new filters for django-compress that handles lesscss
(http://lesscss.org) files and automatically converts/deploys as CSS.
- Added new templates for django-compress that handles the MEDIA_SERIAL
suffix.
- djblets.siteconfig:
- The settings template now allows fields to not have a label by setting
"fields_no_label" to True in the form class.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #846757 - Current version of python-djblets in Fedora-16 contains
embeded copy of python-feedparser, vulnerable to CVE-2009-5065, CVE-2011-1156,
CVE-2011-1157, and CVE-2011-1158
https://bugzilla.redhat.com/show_bug.cgi?id=846757
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update python-djblets' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke