LWN.net Logo

ReviewBoard, python-djblets: multiple vulnerabilities

Package(s):ReviewBoard, python-djblets CVE #(s):
Created:August 8, 2013 Updated:October 2, 2013
Description:

From the Fedora advisory:

* Function names in diff headers are no longer rendered as HTML.

* If a user’s full name contained HTML, the Submitters list would render it as HTML, without escaping it. This was an XSS vulnerability.

* The default Apache configuration is now more strict with how it serves up file attachments. This does not apply to existing installations. See http://support.beanbaginc.com/support/solutions/articles/... for details.

* Uploaded files are now renamed to include a hash, preventing users from uploading malicious filenames, and making filenames unguessable.

* Recaptcha support has been updated to use the new URLs provided by Google.

Alerts:
Fedora FEDORA-2013-13911 2013-08-07
Fedora FEDORA-2013-13850 2013-08-07
Fedora FEDORA-2013-13911 2013-08-07
Fedora FEDORA-2013-13850 2013-08-07
Fedora FEDORA-2013-17449 2013-09-30
Fedora FEDORA-2013-17449 2013-09-30
Fedora FEDORA-2013-17443 2013-10-02
Fedora FEDORA-2013-17443 2013-10-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds