You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa ipython

Sigurnosni nedostatak programskog paketa ipython

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-11767
2015-07-17 23:29:35
——————————————————————————–

Name : ipython
Product : Fedora 21
Version : 2.4.1
Release : 7.fc21
URL : http://ipython.org/
Summary : An enhanced interactive Python shell
Description :

IPython provides a replacement for the interactive Python interpreter with
extra functionality.

Main features:
* Comprehensive object introspection.
* Input history, persistent across sessions.
* Caching of output results during a session with automatically generated
references.
* Readline based name completion.
* Extensible system of ‘magic’ commands for controlling the environment and
performing many tasks related either to IPython or the operating system.
* Configuration system with easy switching between different setups (simpler
than changing $PYTHONSTARTUP environment variables every time).
* Session logging and reloading.
* Extensible syntax processing for special purpose situations.
* Access to the system shell with user-extensible alias system.
* Easily embeddable in other Python programs.
* Integrated access to the pdb debugger and the Python profiler.

——————————————————————————–
Update Information:

Fix CSRF issue.
– Fix font-awesome paths (bug #1219956)
– Add upstream patch to fix PyQt4 import (bug #1219997)
– Use python2 macros, fix python3 shebang fix
Fix fontawesome path
——————————————————————————–
ChangeLog:

* Thu Jul 16 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.1-7
– Update to 2.x to fix CSRF issue (bug #1243842)
* Mon Jul 13 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.1-6
– Fix fontawesome path
* Sat May 9 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.1-5
– Sync more font-awesome changes from 3.1.0
* Sat May 9 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.1-4
– More font-awesome fixes (bug #1170270)
* Fri May 8 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.1-3
– Add upstream patch to fix PyQt4 import (bug #1219997)
– Use python2 macros, fix python3 shebang fix
* Fri May 8 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.1-2
– Fix font-awesome paths (bug #1219956)
* Thu Feb 26 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.1-1
– update to 2.4.1
* Wed Feb 25 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.0-1
– update to 2.4.0
* Fri Nov 14 2014 Orion Poplawski <orion@cora.nwra.com> – 2.3.0-1
– update to 2.3.0
——————————————————————————–
References:

[ 1 ] Bug #1243842 – CVE-2015-5607 iptyhon: cross-site request forgery in get_origin()
https://bugzilla.redhat.com/show_bug.cgi?id=1243842
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update ipython’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-11677
2015-07-17 23:25:23
——————————————————————————–

Name : ipython
Product : Fedora 22
Version : 2.4.1
Release : 7.fc22
URL : http://ipython.org/
Summary : An enhanced interactive Python shell
Description :

IPython provides a replacement for the interactive Python interpreter with
extra functionality.

Main features:
* Comprehensive object introspection.
* Input history, persistent across sessions.
* Caching of output results during a session with automatically generated
references.
* Readline based name completion.
* Extensible system of ‘magic’ commands for controlling the environment and
performing many tasks related either to IPython or the operating system.
* Configuration system with easy switching between different setups (simpler
than changing $PYTHONSTARTUP environment variables every time).
* Session logging and reloading.
* Extensible syntax processing for special purpose situations.
* Access to the system shell with user-extensible alias system.
* Easily embeddable in other Python programs.
* Integrated access to the pdb debugger and the Python profiler.

——————————————————————————–
Update Information:

Fix CSRF issue.
– Fix font-awesome paths (bug #1219956)
– Add upstream patch to fix PyQt4 import (bug #1219997)
– Use python2 macros, fix python3 shebang fix
Fix fontawesome path
——————————————————————————–
ChangeLog:

* Thu Jul 16 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.1-7
– Update to 2.x to fix CSRF issue (bug #1243842)
* Mon Jul 13 2015 Orion Poplawski <orion@cora.nwra.com> – 2.4.1-6
– Fix fontawesome path
——————————————————————————–
References:

[ 1 ] Bug #1243842 – CVE-2015-5607 iptyhon: cross-site request forgery in get_origin()
https://bugzilla.redhat.com/show_bug.cgi?id=1243842
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update ipython’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorMarko Stanec
Cert idNCERT-REF-2015-07-0023-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni propust programskog paketa ecryptfs-utils

Otkriven je sigurnosni propust u programskom paketu ecryptfs-utils za Fedoru. Propust je posljedica nekorištenja "SALT" vrijednosti. Potencijalnim napadačima omogućuje otkrivanje...

Close