You are here
Home > Preporuke > Sigurnosni nedostatak php programskih biblioteka

Sigurnosni nedostatak php programskih biblioteka

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-15201
2015-09-14 18:15:25.985512
——————————————————————————–

Name : php-doctrine-annotations
Product : Fedora 21
Version : 1.2.7
Release : 1.fc21
URL : https://github.com/doctrine/annotations
Summary : PHP docblock annotations parser library
Description :
PHP docblock annotations parser library (extracted from Doctrine Common).

——————————————————————————–
Update Information:

CVE-2015-5723 http://www.doctrine-project.org/2015/08/31/security_misconfigurat
ion_vulnerability_in_various_doctrine_projects.html
——————————————————————————–
References:

[ 1 ] Bug #1258669 – php-doctrine-annotations-v1.2.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1258669
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-doctrine-annotations’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-15198
2015-09-14 18:15:25.985607
——————————————————————————–

Name : php-doctrine-cache
Product : Fedora 21
Version : 1.4.2
Release : 1.fc21
URL : https://github.com/doctrine/cache
Summary : Doctrine Cache
Description :
Cache component extracted from the Doctrine Common project.

Optional:
* APC (php-pecl-apc)
* Couchbase (http://pecl.php.net/package/couchbase)
* Memcache (php-pecl-memcache)
* Memcached (php-pecl-memcached)
* MongoDB (php-pecl-mongo)
* Redis (php-pecl-redis)
* Riak (http://pecl.php.net/package/riak)
* XCache (php-xcache)

——————————————————————————–
Update Information:

CVE-2015-5723 http://www.doctrine-project.org/2015/08/31/security_misconfigurat
ion_vulnerability_in_various_doctrine_projects.html
——————————————————————————–
References:

[ 1 ] Bug #1258670 – php-doctrine-cache-v1.4.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1258670
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-doctrine-cache’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-15204
2015-09-14 18:15:25.985405
——————————————————————————–

Name : php-doctrine-doctrine-bundle
Product : Fedora 21
Version : 1.5.2
Release : 1.fc21
URL : https://github.com/doctrine/DoctrineBundle
Summary : Symfony Bundle for Doctrine
Description :
Doctrine DBAL & ORM Bundle for the Symfony Framework.

Optional:
* Doctrine ORM (2.3 <= php-doctrine-orm < 3.0)
* Symfony Web Profile Bundle (2.3 <= php-symfony-web-profiler-bundle < 4.0)
* Twig (1.10 <= php-twig < 2.0)

——————————————————————————–
Update Information:

## 1.5.2 (2015-08-31) ### Security: * Fix Security Misconfiguration
Vulnerability, allowing potential local arbitrary code execution *
CVE-2015-5723 * http://www.doctrine-project.org/2015/08/31/security_misconfi
guration_vulnerability_in_various_doctrine_projects.html ## 1.5.1 (2015-08-12)
### Bugfix: * Fixed the JS expanding all queries in the profiler in case of
multiple connections * Fixed the retrieval of the namespace in
DisconnectedMetadataFactory * Changed the composer constraint to allow Symfony
3.0 for people wanting to do early testing
——————————————————————————–
References:

[ 1 ] Bug #1253092 – php-doctrine-doctrine-bundle-v1.5.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1253092
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-doctrine-doctrine-bundle’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-15203
2015-09-14 18:16:15.199548
——————————————————————————–

Name : php-doctrine-annotations
Product : Fedora 22
Version : 1.2.7
Release : 1.fc22
URL : https://github.com/doctrine/annotations
Summary : PHP docblock annotations parser library
Description :
PHP docblock annotations parser library (extracted from Doctrine Common).

——————————————————————————–
Update Information:

CVE-2015-5723 http://www.doctrine-project.org/2015/08/31/security_misconfigurat
ion_vulnerability_in_various_doctrine_projects.html
——————————————————————————–
References:

[ 1 ] Bug #1258669 – php-doctrine-annotations-v1.2.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1258669
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-doctrine-annotations’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-15199
2015-09-14 18:16:15.199619
——————————————————————————–

Name : php-doctrine-cache
Product : Fedora 22
Version : 1.4.2
Release : 1.fc22
URL : https://github.com/doctrine/cache
Summary : Doctrine Cache
Description :
Cache component extracted from the Doctrine Common project.

Optional:
* APC (php-pecl-apc)
* Couchbase (http://pecl.php.net/package/couchbase)
* Memcache (php-pecl-memcache)
* Memcached (php-pecl-memcached)
* MongoDB (php-pecl-mongo)
* Redis (php-pecl-redis)
* Riak (http://pecl.php.net/package/riak)
* XCache (php-xcache)

——————————————————————————–
Update Information:

CVE-2015-5723 http://www.doctrine-project.org/2015/08/31/security_misconfigurat
ion_vulnerability_in_various_doctrine_projects.html
——————————————————————————–
References:

[ 1 ] Bug #1258670 – php-doctrine-cache-v1.4.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1258670
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-doctrine-cache’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-15206
2015-09-14 18:16:15.194940
——————————————————————————–

Name : php-doctrine-doctrine-bundle
Product : Fedora 22
Version : 1.5.2
Release : 1.fc22
URL : https://github.com/doctrine/DoctrineBundle
Summary : Symfony Bundle for Doctrine
Description :
Doctrine DBAL & ORM Bundle for the Symfony Framework.

Optional:
* Doctrine ORM (2.3 <= php-doctrine-orm < 3.0)
* Symfony Web Profile Bundle (2.3 <= php-symfony-web-profiler-bundle < 4.0)
* Twig (1.10 <= php-twig < 2.0)

——————————————————————————–
Update Information:

## 1.5.2 (2015-08-31) ### Security: * Fix Security Misconfiguration
Vulnerability, allowing potential local arbitrary code execution *
CVE-2015-5723 * http://www.doctrine-project.org/2015/08/31/security_misconfi
guration_vulnerability_in_various_doctrine_projects.html ## 1.5.1 (2015-08-12)
### Bugfix: * Fixed the JS expanding all queries in the profiler in case of
multiple connections * Fixed the retrieval of the namespace in
DisconnectedMetadataFactory * Changed the composer constraint to allow Symfony
3.0 for people wanting to do early testing
——————————————————————————–
References:

[ 1 ] Bug #1253092 – php-doctrine-doctrine-bundle-v1.5.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1253092
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-doctrine-doctrine-bundle’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorMarijo Plepelic
Cert idNCERT-REF-2015-09-0009-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa php5

Otkriveni su sigurnosni nedostaci u programskom paketu php5. Otkriveni nedostaci potencijalnim napadačima omogućuju korištenje već oslobođene memorije i pokretanje proizvoljnog...

Close