Fedora alert FEDORA-2014-12584 (bugzilla)
| From: | updates@fedoraproject.org | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 19 Update: bugzilla-4.2.11-1.fc19 | |
| Date: | Wed, 22 Oct 2014 08:50:36 +0000 | |
| Message-ID: | <20141022085046.E84AE60D30D4@bastion01.phx2.fedoraproject.org> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2014-12584 2014-10-10 14:47:05 -------------------------------------------------------------------------------- Name : bugzilla Product : Fedora 19 Version : 4.2.11 Release : 1.fc19 URL : http://www.bugzilla.org/ Summary : Bug tracking system Description : Bugzilla is a popular bug tracking system used by multiple open source projects It requires a database engine installed - either MySQL, PostgreSQL or Oracle. Without one of these database engines (local or remote), Bugzilla will not work - see the Release Notes for details. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2014-1571, CVE-2014-1572, CVE-2014-1573 -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 8 2014 Emmanuel Seyman <emmanuel@seyman.fr> - 4.2.11-1 - Update to 4.2.11 (CVE-2014-157, CVE-2014-1573 and CVE-2014-1571) * Fri Jul 25 2014 Emmanuel Seyman <emmanuel@seyman.fr> - 4.2.10-1 - Update to 4.2.10 which fixes a security bug (CVE-2014-1546) * Sat Apr 19 2014 Emmanuel Seyman <emmanuel@seyman.fr> - 4.2.9-1 - Update to 4.2.9 (regression fix for 4.2.8 which was a security update) - Drop backported patches * Sun Jan 19 2014 Emmanuel Seyman <emmanuel@seyman.fr> - 4.2.7-3 - Fix the comparison of module versions (#1044854) - Really honor the PROJECT environment variable (#911943) * Fri Nov 15 2013 Emmanuel Seyman <emmanuel@seyman.fr> - 4.2.7-2 - Add patch to cache bz_locations() (bmo #843457) - Fix constants patch to honor the PROJECT environment variable (#911943) * Thu Oct 17 2013 Emmanuel Seyman <emmanuel@seyman.fr> - 4.2.7-1 - Update to 4.2.7 (security updates) - Patch bugzilla to write compiled templates under /var (#949130) * Sun Aug 4 2013 Emmanuel Seyman <emmanuel@seyman.fr> - 4.2.6-2 - Change apache conf to enable access to all machines -------------------------------------------------------------------------------- References: [ 1 ] Bug #1150091 - CVE-2014-1571 CVE-2014-1572 CVE-2014-1573 bugzilla: security fixes release https://bugzilla.redhat.com/show_bug.cgi?id=1150091 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update bugzilla' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...
