You are here
Home > Preporuke > Sigurnosni propust programskog paketa owncloud

Sigurnosni propust programskog paketa owncloud

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2014-14066
2014-11-01 00:32:41
——————————————————————————–

Name : php-sabredav-Sabre_VObject
Product : Fedora 19
Version : 2.1.4
Release : 1.fc19
URL : http://sabre.io/
Summary : An intuitive reader for iCalendar and vCard objects
Description :
SabreDAV VObject plugin.

——————————————————————————–
Update Information:

This update provides ownCloud 5.0.17, the latest release in the 5.x series, plus an extra security-related fix backported from the stable5 branch.

It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV 1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.

ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 – ownCloud 7 – would likely fail.

I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the 5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.

Initial testing on the 4.x -> 5.x upgrade has been performed, but please back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required.
——————————————————————————–
ChangeLog:

* Thu May 22 2014 Remi Collet <remi@fedoraproject.org> 2.1.4-1
– update to 2.1.4
– sources from github
– fix upstream URL
* Wed Feb 12 2014 Joseph Marrero <jmarrero@fedoraproject.org> 2.1.3-1
– update to 2.1.3
* Tue Sep 3 2013 Joseph Marrero <jmarrero@fedoraproject.org> 2.1.0-1
– update to 2.1.0
– use our own package.xml created by Remi Collet as upstream doesn’t use pear anymore
——————————————————————————–
References:

[ 1 ] Bug #1035593 – CVE-2013-6403 owncloud: possible security bypass on admin page (5.0.13) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1035593
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-sabredav-Sabre_VObject’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-14066
2014-11-01 00:32:41
——————————————————————————–

Name : php-sabredav-Sabre_DAV
Product : Fedora 19
Version : 1.7.13
Release : 1.fc19
URL : http://sabre.io
Summary : Sabre_DAV is a WebDAV framework for PHP
Description :
SabreDAV allows you to easily add WebDAV support to a PHP application. SabreDAV
is meant to cover the entire standard.

——————————————————————————–
Update Information:

This update provides ownCloud 5.0.17, the latest release in the 5.x series, plus an extra security-related fix backported from the stable5 branch.

It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV 1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.

ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 – ownCloud 7 – would likely fail.

I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the 5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.

Initial testing on the 4.x -> 5.x upgrade has been performed, but please back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required.
——————————————————————————–
ChangeLog:

* Tue Oct 28 2014 Adam Williamson <awilliam@redhat.com> – 1.7.13-1
– new release 1.7.13 (EOL)
* Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 1.7.8-3
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Thu Sep 5 2013 Joseph Marrero <jmarrero@fedoraproject.org> – 1.7.8-2
– fix package xml files incorrectly tagged by myself doc instead of php
* Tue Sep 3 2013 Joseph Marrero <jmarrero@fedoraproject.org> – 1.7.8-1
– Update to 1.7.8 Uptream version
– Add own pear configuration provided by Remi Collet from RH
——————————————————————————–
References:

[ 1 ] Bug #1035593 – CVE-2013-6403 owncloud: possible security bypass on admin page (5.0.13) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1035593
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-sabredav-Sabre_DAV’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-14066
2014-11-01 00:32:41
——————————————————————————–

Name : php-sabredav-Sabre_CalDAV
Product : Fedora 19
Version : 1.7.9
Release : 1.fc19
URL : http://sabre.io
Summary : Provides RFC4791 (CalDAV) support to Sabre_DAV
Description :
CalDAV plugin for Sabre, adds support for CalDAV in Sabre_DAV.

——————————————————————————–
Update Information:

This update provides ownCloud 5.0.17, the latest release in the 5.x series, plus an extra security-related fix backported from the stable5 branch.

It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV 1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.

ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 – ownCloud 7 – would likely fail.

I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the 5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.

Initial testing on the 4.x -> 5.x upgrade has been performed, but please back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required.
——————————————————————————–
ChangeLog:

* Tue Oct 28 2014 Adam Williamson <awilliam@redhat.com> – 1.7.9-1
– new release 1.7.9 (from SabreDAV 1.7.13, EOL)
* Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 1.7.8-3
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Thu Sep 5 2013 Joseph Marrero <jmarrero@fedoraproject.org> – 1.7.8-2
– fix package xml files incorrectly tagged by myself doc instead of php
* Tue Sep 3 2013 Joseph Marrero <jmarrero@fedoraproject.org> 1.7.8-1
– update to 1.7.8
– use our own package.xml provided by Remi Collet as upstream doesn’t use pear anymore
——————————————————————————–
References:

[ 1 ] Bug #1035593 – CVE-2013-6403 owncloud: possible security bypass on admin page (5.0.13) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1035593
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-sabredav-Sabre_CalDAV’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-14066
2014-11-01 00:32:41
——————————————————————————–

Name : owncloud
Product : Fedora 19
Version : 5.0.17
Release : 2.fc19
URL : http://owncloud.org
Summary : Private file sync and share server
Description :
ownCloud gives you universal access to your files through a web interface or
WebDAV. It also provides a platform to easily view & sync your contacts,
calendars and bookmarks across all your devices and enables basic editing right
on the web. ownCloud is extendable via a simple but powerful API for
applications and plugins.

——————————————————————————–
Update Information:

This update provides ownCloud 5.0.17, the latest release in the 5.x series, plus an extra security-related fix backported from the stable5 branch.

It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV 1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.

ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 – ownCloud 7 – would likely fail.

I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the 5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.

Initial testing on the 4.x -> 5.x upgrade has been performed, but please back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required.
——————————————————————————–
ChangeLog:

* Wed Oct 29 2014 Adam Williamson <awilliam@redhat.com> – 5.0.17-2
– drop db server deps, clean up docs, disable some admin checks (from master)
* Tue Oct 28 2014 Adam Williamson <awilliam@redhat.com> – 5.0.17-1
– update to 5.0.17 (latest release)
– backport a further security fix from upstream (HTTP redirects only)
* Fri Dec 20 2013 Adam Williamson <awilliam@redhat.com> – 5.0.14a-2
* Correct location of php-symfony-routing: #1045301
* Fri Dec 20 2013 Adam Williamson <awilliam@redhat.com> – 5.0.14a-1
– 5.0.14a
* Sat Nov 16 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 5.0.13-1
– 5.0.13
* Tue Oct 8 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 5.0.12-1
– 5.0.12
* Tue Sep 24 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 5.0.11-2
– keep MDB2/pgsql driver, genuine version causes upgrade problems (RBZ#962082)
* Sat Sep 7 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 5.0.11-1
– 5.0.11
* Wed Sep 4 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 5.0.10-4
– unbundle sabredav again
* Fri Aug 23 2013 Adam Williamson <awilliam@redhat.com> – 5.0.10-3
– patch mediaelement not to try and use its plugins
* Fri Aug 23 2013 Adam Williamson <awilliam@redhat.com> – 5.0.10-2
– drop binary Flash and Silverlight blobs: #1000257
– don’t ship source of jplayer in the binary package
* Sun Aug 18 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 5.0.10-1
– 5.0.10
* Thu Aug 15 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 4.5.13-2
– RBZ #962082 keep 3rdparty pqsql mdb2 driver
* Sat Aug 3 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 5.0.9-3
– Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
* Tue Jul 23 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 5.0.9-2
– buildreq: php-pear (RBZ #987279)
* Tue Jul 16 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 5.0.9-1
– major upgrade to 5.0.9
– symlink 3rdparty libs and drop most of the patches
– new deps: php-ZendFramework symfony
* Tue Jul 16 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 4.5.13-1
– 4.5.13
* Sat Jun 8 2013 Gregor Tätzner <brummbq@fedoraproject.org> – 4.5.12-1
– 4.5.12
——————————————————————————–
References:

[ 1 ] Bug #1035593 – CVE-2013-6403 owncloud: possible security bypass on admin page (5.0.13) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1035593
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update owncloud’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-14066
2014-11-01 00:32:41
——————————————————————————–

Name : php-sabredav-Sabre_CardDAV
Product : Fedora 19
Version : 1.7.9
Release : 2.fc19
URL : http://sabre.io
Summary : Provides CardDAV support to Sabre_DAV
Description :
CardDAV plugin for Sabre, Adds support for CardDAV in Sabre_DAV.

——————————————————————————–
Update Information:

This update provides ownCloud 5.0.17, the latest release in the 5.x series, plus an extra security-related fix backported from the stable5 branch.

It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV 1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.

ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 – ownCloud 7 – would likely fail.

I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the 5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.

Initial testing on the 4.x -> 5.x upgrade has been performed, but please back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required.
——————————————————————————–
ChangeLog:

* Tue Oct 28 2014 Adam Williamson <awilliam@redhat.com> – 1.7.9-1
– new release 1.7.9 (from SabreDAV 1.7.13, EOL)
* Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 1.7.8-3
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Thu Sep 5 2013 Joseph Marrero <jmarrero@fedoraproject.org> – 1.7.8-2
– fix package xml files incorrectly tagged by myself doc instead of php
* Tue Sep 3 2013 Joseph Marrero <jmarrero@fedoraproject.org> 1.7.8-1
– update to 1.7.8
– use our own package.xml created by Remi Collet as upstream doesn’t use pear anymore
——————————————————————————–
References:

[ 1 ] Bug #1035593 – CVE-2013-6403 owncloud: possible security bypass on admin page (5.0.13) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1035593
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-sabredav-Sabre_CardDAV’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-14066
2014-11-01 00:32:41
——————————————————————————–

Name : php-sabredav-Sabre_DAVACL
Product : Fedora 19
Version : 1.7.9
Release : 1.fc19
URL : http://sabre.io
Summary : RFC3744 implementation for SabreDAV
Description :
DAVACL plugin for SabreDAV.

——————————————————————————–
Update Information:

This update provides ownCloud 5.0.17, the latest release in the 5.x series, plus an extra security-related fix backported from the stable5 branch.

It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV 1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.

ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 – ownCloud 7 – would likely fail.

I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the 5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.

Initial testing on the 4.x -> 5.x upgrade has been performed, but please back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required.
——————————————————————————–
ChangeLog:

* Tue Oct 28 2014 Adam Williamson <awilliam@redhat.com> – 1.7.9-1
– new release 1.7.9 (from SabreDAV 1.7.13, EOL)
* Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 1.7.8-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Tue Sep 3 2013 Joseph Marrero <jmarrero@fedoraproject.org> – 1.7.8-1
– Update to 1.7.8 Upstream version
– Add own pear configuration provided by Remi Collet from RH
——————————————————————————–
References:

[ 1 ] Bug #1035593 – CVE-2013-6403 owncloud: possible security bypass on admin page (5.0.13) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1035593
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-sabredav-Sabre_DAVACL’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-14066
2014-11-01 00:32:41
——————————————————————————–

Name : php-sabredav-Sabre_HTTP
Product : Fedora 19
Version : 1.7.11
Release : 1.fc19
URL : http://sabre.io
Summary : HTTP component for the SabreDAV WebDAV framework for PHP
Description :
Sabre_HTTP allows for a central interface to deal with Sabre.

——————————————————————————–
Update Information:

This update provides ownCloud 5.0.17, the latest release in the 5.x series, plus an extra security-related fix backported from the stable5 branch.

It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV 1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.

ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 – ownCloud 7 – would likely fail.

I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the 5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.

Initial testing on the 4.x -> 5.x upgrade has been performed, but please back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required.
——————————————————————————–
ChangeLog:

* Tue Oct 28 2014 Adam Williamson – 1.7.11-1
– new release 1.7.11 (from Sabre 1.7.13 EOL)
* Tue Sep 3 2013 Joseph Marrero – 1.7.3-1
– Update to 1.7.x Uptream version
– Add own pear configuration provided by Remi Collet from RH
——————————————————————————–
References:

[ 1 ] Bug #1035593 – CVE-2013-6403 owncloud: possible security bypass on admin page (5.0.13) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1035593
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-sabredav-Sabre_HTTP’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorTomislav Protega
Cert idNCERT-REF-2014-11-0013-ADV
CveCVE-2013-6403
ID izvornikaFEDORA-2014-14066
Proizvodphp owncloud
Izvorhttp://www.redhat.com
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa polarssl

Otkriveni su sigurnosni nedostaci u programskom paketu polarssl za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvoljnog programskog...

Close