You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa zarafa

Sigurnosni nedostatak programskog paketa zarafa

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2014-7896
2014-06-30 09:45:44
——————————————————————————–

Name : zarafa
Product : Fedora 20
Version : 7.1.10
Release : 2.fc20
URL : http://www.zarafa.com/
Summary : Open Source Edition of the Zarafa Collaboration Platform
Description :
The Zarafa Collaboration Platform is a Microsoft Exchange replacement. The
Open Source Collaboration provides an integration with your existing Linux
mail server, native mobile phone support by ActiveSync compatibility and a
webaccess with ‘Look & Feel’ similar to Outlook using Ajax. Including an
IMAP and a POP3 gateway as well as an iCal/CalDAV gateway, the Zarafa Open
Source Collaboration can combine the usability with the stability and the
flexibility of a Linux server.

The proven Zarafa groupware solution is using MAPI objects, provides a MAPI
client library as well as programming interfaces for C++, PHP and Python.
The other Zarafa related packages need to be installed to gain all features
and benefits of the Zarafa Collaboration Platform (ZCP).

——————————————————————————–
Update Information:

Zarafa Collaboration Platform 7.1.10 final [44973]
==================================================

General
——-

This release brings a few new features while maintaining stability. This release is identical to the RC since no reports have arrived upstream and additional testing has not shown up any issues.

Backend
——-

– ZCP-12380: Avoid violating RFC 3501 at partial IMAP fetch request
– ZCP-12337: Provide support for offline S/MIME public certificates
– ZCP-12226: ZWS breaks opensource build
– ZCP-12219: Enhance MariaDB support by modifying sql_mode
– ZCP-12162: Implement “Reinvite” for Zarafa ical
– ZCP-11730: zarafa-mailbox-permissions man page error
– ZCP-11835: zarafa-set-oof does not accept argument “-n”
– ZCP-12115: support ubuntu 14.04
– ZCP-12142: Patch: Option to disable all plaintext authentications unless SSL/TLS is used
– ZCP-12162: Implement “Reinvite” for Zarafa ical
– ZCP-12200: Patch: POP3 RESP-CODES and AUTH-RESP-CODE support in Zarafa-Gateway
– ZCP-12013: Log the reason why a socket error was thrown
– ZCP-12219: Enhance MariaDB support by modifying sql_mode
– ZCP-12227: Enhance DAgent log level prios
– ZCP-12232: Patch: POP3 CAPA (CAPABILITIES) support in Zarafa-Gateway
– ZCP-12234: Include email adress when forwarding mails with a rule (community contribution)
– ZCP-12270: Change maintainer line for debian packages
– ZCP-12338: Allow administrators to backup archive stores (show GUID via zarafa-admin)
– ZCP-12339: Personal archive store not opened if archive server name in ADS does not match the casing of the actual name.
– ZCP-12340: Patch: Repair broken ssl_enable_v2 setting for Zarafa 7.1.x
– ZCP-12342: Zarafa-backup creates empty folders for skipped companies
– ZCP-9899: Update GSoap to 2.8.x
——————————————————————————–
ChangeLog:

* Fri Jul 11 2014 Robert Scheck <robert@fedoraproject.org> 7.1.10-2
– Added a workaround to really support MariaDB (#995870)
– Re-added a patch to allow building without zarafa-search
* Sun Jun 29 2014 Robert Scheck <robert@fedoraproject.org> 7.1.10-1
– Upgrade to 7.1.10
* Fri Jun 20 2014 Remi Collet <rcollet@redhat.com> – 7.1.9-2.1
– rebuild for https://fedoraproject.org/wiki/Changes/Php56
– add numerical prefix to extension configuration file
* Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 7.1.9-2.1
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Thu May 22 2014 Petr Machata <pmachata@redhat.com> – 7.1.9-2
– Rebuild for boost 1.55.0
* Thu May 1 2014 Robert Scheck <robert@fedoraproject.org> 7.1.9-1
– Upgrade to 7.1.9
* Fri Feb 21 2014 Robert Scheck <robert@fedoraproject.org> 7.1.8-3
– Upgrade to 7.1.8 (re-released)
* Fri Feb 14 2014 Parag Nemade <paragn AT fedoraproject DOT org> – 7.1.8-2
– Rebuild for icu 52
* Thu Jan 30 2014 Robert Scheck <robert@fedoraproject.org> 7.1.8-1
– Upgrade to 7.1.8 (#1056767, #1059903)
* Sun Dec 8 2013 Robert Scheck <robert@fedoraproject.org> 7.1.7-1
– Upgrade to 7.1.7 (#1008068)
– Added dependency from gateway and spooler to python-MAPI
– Added requirements to virtual libvmime ABI/API provides
——————————————————————————–
References:

[ 1 ] Bug #1073618 – CVE-2014-0103 zarafa: passwords stored in cleartext on server
https://bugzilla.redhat.com/show_bug.cgi?id=1073618
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update zarafa’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-7889
2014-06-30 09:45:24
——————————————————————————–

Name : zarafa
Product : Fedora 19
Version : 7.1.10
Release : 2.fc19
URL : http://www.zarafa.com/
Summary : Open Source Edition of the Zarafa Collaboration Platform
Description :
The Zarafa Collaboration Platform is a Microsoft Exchange replacement. The
Open Source Collaboration provides an integration with your existing Linux
mail server, native mobile phone support by ActiveSync compatibility and a
webaccess with ‘Look & Feel’ similar to Outlook using Ajax. Including an
IMAP and a POP3 gateway as well as an iCal/CalDAV gateway, the Zarafa Open
Source Collaboration can combine the usability with the stability and the
flexibility of a Linux server.

The proven Zarafa groupware solution is using MAPI objects, provides a MAPI
client library as well as programming interfaces for C++, PHP and Python.
The other Zarafa related packages need to be installed to gain all features
and benefits of the Zarafa Collaboration Platform (ZCP).

——————————————————————————–
Update Information:

Zarafa Collaboration Platform 7.1.10 final [44973]
==================================================

General
——-

This release brings a few new features while maintaining stability. This release is identical to the RC since no reports have arrived upstream and additional testing has not shown up any issues.

Backend
——-

– ZCP-12380: Avoid violating RFC 3501 at partial IMAP fetch request
– ZCP-12337: Provide support for offline S/MIME public certificates
– ZCP-12226: ZWS breaks opensource build
– ZCP-12219: Enhance MariaDB support by modifying sql_mode
– ZCP-12162: Implement “Reinvite” for Zarafa ical
– ZCP-11730: zarafa-mailbox-permissions man page error
– ZCP-11835: zarafa-set-oof does not accept argument “-n”
– ZCP-12115: support ubuntu 14.04
– ZCP-12142: Patch: Option to disable all plaintext authentications unless SSL/TLS is used
– ZCP-12162: Implement “Reinvite” for Zarafa ical
– ZCP-12200: Patch: POP3 RESP-CODES and AUTH-RESP-CODE support in Zarafa-Gateway
– ZCP-12013: Log the reason why a socket error was thrown
– ZCP-12219: Enhance MariaDB support by modifying sql_mode
– ZCP-12227: Enhance DAgent log level prios
– ZCP-12232: Patch: POP3 CAPA (CAPABILITIES) support in Zarafa-Gateway
– ZCP-12234: Include email adress when forwarding mails with a rule (community contribution)
– ZCP-12270: Change maintainer line for debian packages
– ZCP-12338: Allow administrators to backup archive stores (show GUID via zarafa-admin)
– ZCP-12339: Personal archive store not opened if archive server name in ADS does not match the casing of the actual name.
– ZCP-12340: Patch: Repair broken ssl_enable_v2 setting for Zarafa 7.1.x
– ZCP-12342: Zarafa-backup creates empty folders for skipped companies
– ZCP-9899: Update GSoap to 2.8.x
——————————————————————————–
ChangeLog:

* Fri Jul 11 2014 Robert Scheck <robert@fedoraproject.org> 7.1.10-2
– Added a workaround to really support MariaDB (#995870)
– Re-added a patch to allow building without zarafa-search
* Sun Jun 29 2014 Robert Scheck <robert@fedoraproject.org> 7.1.10-1
– Upgrade to 7.1.10
* Fri Jun 20 2014 Remi Collet <rcollet@redhat.com> – 7.1.9-2.1
– rebuild for https://fedoraproject.org/wiki/Changes/Php56
– add numerical prefix to extension configuration file
* Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 7.1.9-2.1
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Thu May 22 2014 Petr Machata <pmachata@redhat.com> – 7.1.9-2
– Rebuild for boost 1.55.0
* Thu May 1 2014 Robert Scheck <robert@fedoraproject.org> 7.1.9-1
– Upgrade to 7.1.9
* Fri Feb 21 2014 Robert Scheck <robert@fedoraproject.org> 7.1.8-3
– Upgrade to 7.1.8 (re-released)
* Fri Feb 14 2014 Parag Nemade <paragn AT fedoraproject DOT org> – 7.1.8-2
– Rebuild for icu 52
* Thu Jan 30 2014 Robert Scheck <robert@fedoraproject.org> 7.1.8-1
– Upgrade to 7.1.8 (#1056767, #1059903)
* Sun Dec 8 2013 Robert Scheck <robert@fedoraproject.org> 7.1.7-1
– Upgrade to 7.1.7 (#1008068)
– Added dependency from gateway and spooler to python-MAPI
– Added requirements to virtual libvmime ABI/API provides
* Mon Aug 5 2013 Robert Scheck <robert@fedoraproject.org> 7.1.5-1
– Upgrade to 7.1.5 (#747241, #863498, #926039, #946900)
– Added configuration compatibility for Apache 2.2 and 2.4
* Sun Aug 4 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 7.1.4-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
* Sat Jul 27 2013 Petr Machata <pmachata@redhat.com> – 7.1.4-2
– Rebuild for boost 1.54.0
* Sat May 25 2013 Rex Dieter <rdieter@fedoraproject.org> 7.1.4-2
– rebuild (libical)
* Sun Mar 24 2013 Robert Scheck <robert@fedoraproject.org> 7.1.4-1
– Upgrade to 7.1.4
* Fri Mar 22 2013 Remi Collet <rcollet@redhat.com> 7.0.13-2
– rebuild for http://fedoraproject.org/wiki/Features/Php55
——————————————————————————–
References:

[ 1 ] Bug #1073618 – CVE-2014-0103 zarafa: passwords stored in cleartext on server
https://bugzilla.redhat.com/show_bug.cgi?id=1073618
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update zarafa’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorMarijo Plepelic
Cert idNCERT-REF-2014-07-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Više ranjivosti jezgre operacijskog sustava

Otkriveno je više ranjivosti u jezgri operacijskog sustava Fedora 19. Ranjivosti zahvaćaju više dijelova jezgre, a mogle su biti iskorištene...

Close