Fedora alert FEDORA-2010-16905 (glpi)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 12 Update: glpi-0.72.4-3.svn11497.fc12 | |
Date: | Fri, 05 Nov 2010 22:52:25 +0000 | |
Message-ID: | <20101105225225.EA9DD1104EC@bastion02.phx2.fedoraproject.org> | |
Archive‑link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-16905 2010-10-28 21:21:02 -------------------------------------------------------------------------------- Name : glpi Product : Fedora 12 Version : 0.72.4 Release : 3.svn11497.fc12 URL : http://www.glpi-project.org/ Summary : Free IT asset management software Description : GLPI is the Information Resource-Manager with an additional Administration- Interface. You can use it to build up a database with an inventory for your company (computer, software, printers...). It has enhanced functions to make the daily life for the administrators easier, like a job-tracking-system with mail-notification and methods to build a database with basic information about your network-topology. -------------------------------------------------------------------------------- Update Information: Switch to system phpCAS. -------------------------------------------------------------------------------- ChangeLog: * Thu May 20 2010 Remi Collet <Fedora@FamilleCollet.com> - 0.72.4-3.svn11497 - use system phpCAS instead of bundled copy - minor bug fixes from SVN * Mon Mar 22 2010 Remi Collet <Fedora@FamilleCollet.com> - 0.72.4-2.svn11035 - update embedded phpCAS to 1.1.0RC7 (security fix - #575906) * Tue Mar 2 2010 Remi Collet <Fedora@FamilleCollet.com> - 0.72.4-1 - update to 0.72.4 * Tue Oct 27 2009 Remi Collet <Fedora@FamilleCollet.com> - 0.72.3-1 - update to 0.72.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #620743 - CVE-2010-2795 php-pear-CAS: authenticated session hijack by providing new well formed ticket (PHPCAS-61) https://bugzilla.redhat.com/show_bug.cgi?id=620743 [ 2 ] Bug #620751 - CVE-2010-2796 php-pear-CAS: XSS in proxy mode (PHPCAS-67) https://bugzilla.redhat.com/show_bug.cgi?id=620751 [ 3 ] Bug #646659 - CVE-2010-3690 CVE-2010-3691 CVE-2010-3692 phpCAS: multiple vulnerabilities fixes in 1.1.3 https://bugzilla.redhat.com/show_bug.cgi?id=646659 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update glpi' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...