Fedora alert FEDORA-2014-13574 (php-Smarty)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 20 Update: php-Smarty-3.1.21-1.fc20 | |
Date: | Wed, 05 Nov 2014 03:57:11 +0000 | |
Message-ID: | <20141105035716.EAD8260C8144@bastion01.phx2.fedoraproject.org> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2014-13574 2014-10-27 02:21:42 -------------------------------------------------------------------------------- Name : php-Smarty Product : Fedora 20 Version : 3.1.21 Release : 1.fc20 URL : http://www.smarty.net Summary : Template/Presentation Framework for PHP Description : Although Smarty is known as a "Template Engine", it would be more accurately described as a "Template/Presentation Framework." That is, it provides the programmer and template designer with a wealth of tools to automate tasks commonly dealt with at the presentation layer of an application. I stress the word Framework because Smarty is not a simple tag-replacing template engine. Although it can be used for such a simple purpose, its focus is on quick and painless development and deployment of your application, while maintaining high-performance, scalability, security and future growth. -------------------------------------------------------------------------------- Update Information: New upstream release, fix CVE-2014-8350 New upstream release New upstream release New upstream release -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 23 2014 Johan Cwiklinski <johan AT x-tnd DOT be> - 3.1.21-1 - New upstream release - Fix version constant - Fix requires * Wed Oct 15 2014 Johan Cwiklinski <johan AT x-tnd DOT be> - 3.1.20-1 - New upstream release * Thu Jul 31 2014 Johan Cwiklinski <johan AT x-tnd DOT be> - 3.1.19-1 - Last upstream release - Add composer provides * Sat May 10 2014 Johan Cwiklinski <johan AT x-tnd DOT be> - 3.1.18-1 - Last upstream release * Sun Dec 22 2013 Johan Cwiklinski <johan AT x-tnd DOT be> - 3.1.16-1 - Last upstream release * Sun Dec 8 2013 Johan Cwiklinski <johan AT x-tnd DOT be> - 3.1.15-1 - Last upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1155846 - CVE-2014-8350 php-Smarty: secure mode bypass https://bugzilla.redhat.com/show_bug.cgi?id=1155846 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update php-Smarty' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...