LWN.net Logo

Fedora alert FEDORA-2012-18462 (cgit)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 16 Update: cgit-0.9.1-2.fc16
Date:  Wed, 28 Nov 2012 11:46:45 +0000
Message-ID:  <20121128114645.608E220F0E@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-18462 2012-11-19 01:51:18 -------------------------------------------------------------------------------- Name : cgit Product : Fedora 16 Version : 0.9.1 Release : 2.fc16 URL : http://git.zx2c4.com/cgit/ Summary : A fast web interface for git Description : Cgit is a fast web interface for git. It uses caching to increase performance. -------------------------------------------------------------------------------- Update Information: Fix syntax highlight to use the correct version of highlight. Update to new upsteam version with 2 security fixes, enhancements and misc other bug fixes. See http://git.zx2c4.com/cgit/commit/?id=a6a932e198e8b6b564d7... for details. -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 17 2012 Kevin Fenzi <kevin@scrye.com> 0.9.1-2 - Add patch to use correct version of highlight for all branches except epel5 * Thu Nov 15 2012 Kevin Fenzi <kevin@scrye.com> 0.9.1-1 - Update to 0.9.1 - Fixes bug #870714 - CVE-2012-4548 - Fixes bug #820733 - CVE-2012-4465 * Wed Jul 18 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.9.0.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild * Thu Jan 12 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.9.0.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #877647 - Wrong setting of exec highlight https://bugzilla.redhat.com/show_bug.cgi?id=877647 [ 2 ] Bug #870714 - CVE-2012-4548 cgit: syntax-highlighting.sh command injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=870714 [ 3 ] Bug #820733 - avoid stack-smash when processing unusual commit [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=820733 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update cgit' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds