You are here
Home > Preporuke > Višestruke ranjivosti programskog paketa php-horde

Višestruke ranjivosti programskog paketa php-horde

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-37090f89d8
2015-11-04 18:18:57.364539
——————————————————————————–

Name : php-horde-passwd
Product : Fedora 22
Version : 5.0.4
Release : 1.fc22
URL : http://www.horde.org/apps/passwd
Summary : Horde password changing application
Description :
An application to change any user passwords stored in various backends like
SQL, LDAP, Kolab, passwd files etc.

——————————————————————————–
Update Information:

**horde 5.2.8** * [mjr] SECURITY: Protect against CSRF attacks on various admin
pages. * [jan] Don’t apply access keys to checkbox and radiobox rows in the
sidebar (Bug #14103). * [jan] Send correct MIME type for non-statically cached
javascript files. * [mjr] Added configuration support for version 2 of
WorldWeatherOnline’s API. **ingo 3.2.7** * [jan] Update Italian
translation. * [mjr] Add database migration for fixing corrupt rule ordering. *
[mjr] Fix corruption of rule order when reordering rules in certain cases.
**imp 6.2.11** * [mjr] Request that the contacts API only consider email fields
when detecting duplicates during automatic saving of attendees to the address
book (Bug #14119). * [jan] Don’t show ‘Create Keys’ button if creating PGP keys
is disabled (steffen.hau@rz.uni-mannheim.de, Request #14096). * [mjr] Fix
displaying iTips with certain locale/date_format preference combinations (Bug
#14076). **passwd 5.0.4** * [mjr] Fix changing password using Kolab driver
(Mike Gabriel).
——————————————————————————–
References:

[ 1 ] Bug #1277410 – php-horde-horde: Multiple CSRF vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=1277410
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-horde-passwd’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-37090f89d8
2015-11-04 18:18:57.364539
——————————————————————————–

Name : php-horde-ingo
Product : Fedora 22
Version : 3.2.7
Release : 1.fc22
URL : http://www.horde.org/apps/ingo
Summary : An email filter rules manager
Description :
Ingo is an email-filter management application. It is fully
internationalized, integrated with Horde and the IMP Webmail client, and
supports both server-side (Sieve, Procmail, Maildrop) and client-side
(IMAP) message filtering.

——————————————————————————–
Update Information:

**horde 5.2.8** * [mjr] SECURITY: Protect against CSRF attacks on various admin
pages. * [jan] Don’t apply access keys to checkbox and radiobox rows in the
sidebar (Bug #14103). * [jan] Send correct MIME type for non-statically cached
javascript files. * [mjr] Added configuration support for version 2 of
WorldWeatherOnline’s API. **ingo 3.2.7** * [jan] Update Italian
translation. * [mjr] Add database migration for fixing corrupt rule ordering. *
[mjr] Fix corruption of rule order when reordering rules in certain cases.
**imp 6.2.11** * [mjr] Request that the contacts API only consider email fields
when detecting duplicates during automatic saving of attendees to the address
book (Bug #14119). * [jan] Don’t show ‘Create Keys’ button if creating PGP keys
is disabled (steffen.hau@rz.uni-mannheim.de, Request #14096). * [mjr] Fix
displaying iTips with certain locale/date_format preference combinations (Bug
#14076). **passwd 5.0.4** * [mjr] Fix changing password using Kolab driver
(Mike Gabriel).
——————————————————————————–
References:

[ 1 ] Bug #1277410 – php-horde-horde: Multiple CSRF vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=1277410
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-horde-ingo’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-37090f89d8
2015-11-04 18:18:57.364539
——————————————————————————–

Name : php-horde-horde
Product : Fedora 22
Version : 5.2.8
Release : 1.fc22
URL : http://www.horde.org/apps/horde
Summary : Horde Application Framework
Description :
The Horde Application Framework is a flexible, modular, general-purpose web
application framework written in PHP. It provides an extensive array of
components that are targeted at the common problems and tasks involved in
developing modern web applications. It is the basis for a large number of
production-level web applications, notably the Horde Groupware suites. For
more information on Horde or the Horde Groupware suites, visit
http://www.horde.org.

——————————————————————————–
Update Information:

**horde 5.2.8** * [mjr] SECURITY: Protect against CSRF attacks on various admin
pages. * [jan] Don’t apply access keys to checkbox and radiobox rows in the
sidebar (Bug #14103). * [jan] Send correct MIME type for non-statically cached
javascript files. * [mjr] Added configuration support for version 2 of
WorldWeatherOnline’s API. **ingo 3.2.7** * [jan] Update Italian
translation. * [mjr] Add database migration for fixing corrupt rule ordering. *
[mjr] Fix corruption of rule order when reordering rules in certain cases.
**imp 6.2.11** * [mjr] Request that the contacts API only consider email fields
when detecting duplicates during automatic saving of attendees to the address
book (Bug #14119). * [jan] Don’t show ‘Create Keys’ button if creating PGP keys
is disabled (steffen.hau@rz.uni-mannheim.de, Request #14096). * [mjr] Fix
displaying iTips with certain locale/date_format preference combinations (Bug
#14076). **passwd 5.0.4** * [mjr] Fix changing password using Kolab driver
(Mike Gabriel).
——————————————————————————–
References:

[ 1 ] Bug #1277410 – php-horde-horde: Multiple CSRF vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=1277410
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-horde-horde’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-37090f89d8
2015-11-04 18:18:57.364539
——————————————————————————–

Name : php-horde-imp
Product : Fedora 22
Version : 6.2.11
Release : 1.fc22
URL : http://www.horde.org/apps/imp
Summary : A web based webmail system
Description :
IMP, the Internet Mail Program, is one of the most popular and widely
deployed open source webmail applications in the world. It allows
universal, web-based access to IMAP and POP3 mail servers and provides
Ajax, mobile and traditional interfaces with a rich range of features
normally found only in desktop email clients.

——————————————————————————–
Update Information:

**horde 5.2.8** * [mjr] SECURITY: Protect against CSRF attacks on various admin
pages. * [jan] Don’t apply access keys to checkbox and radiobox rows in the
sidebar (Bug #14103). * [jan] Send correct MIME type for non-statically cached
javascript files. * [mjr] Added configuration support for version 2 of
WorldWeatherOnline’s API. **ingo 3.2.7** * [jan] Update Italian
translation. * [mjr] Add database migration for fixing corrupt rule ordering. *
[mjr] Fix corruption of rule order when reordering rules in certain cases.
**imp 6.2.11** * [mjr] Request that the contacts API only consider email fields
when detecting duplicates during automatic saving of attendees to the address
book (Bug #14119). * [jan] Don’t show ‘Create Keys’ button if creating PGP keys
is disabled (steffen.hau@rz.uni-mannheim.de, Request #14096). * [mjr] Fix
displaying iTips with certain locale/date_format preference combinations (Bug
#14076). **passwd 5.0.4** * [mjr] Fix changing password using Kolab driver
(Mike Gabriel).
——————————————————————————–
References:

[ 1 ] Bug #1277410 – php-horde-horde: Multiple CSRF vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=1277410
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-horde-imp’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-a381facfd9
2015-11-04 18:17:28.547625
——————————————————————————–

Name : php-horde-imp
Product : Fedora 21
Version : 6.2.11
Release : 1.fc21
URL : http://www.horde.org/apps/imp
Summary : A web based webmail system
Description :
IMP, the Internet Mail Program, is one of the most popular and widely
deployed open source webmail applications in the world. It allows
universal, web-based access to IMAP and POP3 mail servers and provides
Ajax, mobile and traditional interfaces with a rich range of features
normally found only in desktop email clients.

——————————————————————————–
Update Information:

**horde 5.2.8** * [mjr] SECURITY: Protect against CSRF attacks on various admin
pages. * [jan] Don’t apply access keys to checkbox and radiobox rows in the
sidebar (Bug #14103). * [jan] Send correct MIME type for non-statically cached
javascript files. * [mjr] Added configuration support for version 2 of
WorldWeatherOnline’s API. **ingo 3.2.7** * [jan] Update Italian
translation. * [mjr] Add database migration for fixing corrupt rule ordering. *
[mjr] Fix corruption of rule order when reordering rules in certain cases.
**imp 6.2.11** * [mjr] Request that the contacts API only consider email fields
when detecting duplicates during automatic saving of attendees to the address
book (Bug #14119). * [jan] Don’t show ‘Create Keys’ button if creating PGP keys
is disabled (steffen.hau@rz.uni-mannheim.de, Request #14096). * [mjr] Fix
displaying iTips with certain locale/date_format preference combinations (Bug
#14076). **passwd 5.0.4** * [mjr] Fix changing password using Kolab driver
(Mike Gabriel).
——————————————————————————–
References:

[ 1 ] Bug #1277410 – php-horde-horde: Multiple CSRF vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=1277410
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-horde-imp’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-a381facfd9
2015-11-04 18:17:28.547625
——————————————————————————–

Name : php-horde-passwd
Product : Fedora 21
Version : 5.0.4
Release : 1.fc21
URL : http://www.horde.org/apps/passwd
Summary : Horde password changing application
Description :
An application to change any user passwords stored in various backends like
SQL, LDAP, Kolab, passwd files etc.

——————————————————————————–
Update Information:

**horde 5.2.8** * [mjr] SECURITY: Protect against CSRF attacks on various admin
pages. * [jan] Don’t apply access keys to checkbox and radiobox rows in the
sidebar (Bug #14103). * [jan] Send correct MIME type for non-statically cached
javascript files. * [mjr] Added configuration support for version 2 of
WorldWeatherOnline’s API. **ingo 3.2.7** * [jan] Update Italian
translation. * [mjr] Add database migration for fixing corrupt rule ordering. *
[mjr] Fix corruption of rule order when reordering rules in certain cases.
**imp 6.2.11** * [mjr] Request that the contacts API only consider email fields
when detecting duplicates during automatic saving of attendees to the address
book (Bug #14119). * [jan] Don’t show ‘Create Keys’ button if creating PGP keys
is disabled (steffen.hau@rz.uni-mannheim.de, Request #14096). * [mjr] Fix
displaying iTips with certain locale/date_format preference combinations (Bug
#14076). **passwd 5.0.4** * [mjr] Fix changing password using Kolab driver
(Mike Gabriel).
——————————————————————————–
References:

[ 1 ] Bug #1277410 – php-horde-horde: Multiple CSRF vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=1277410
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-horde-passwd’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-a381facfd9
2015-11-04 18:17:28.547625
——————————————————————————–

Name : php-horde-ingo
Product : Fedora 21
Version : 3.2.7
Release : 1.fc21
URL : http://www.horde.org/apps/ingo
Summary : An email filter rules manager
Description :
Ingo is an email-filter management application. It is fully
internationalized, integrated with Horde and the IMP Webmail client, and
supports both server-side (Sieve, Procmail, Maildrop) and client-side
(IMAP) message filtering.

——————————————————————————–
Update Information:

**horde 5.2.8** * [mjr] SECURITY: Protect against CSRF attacks on various admin
pages. * [jan] Don’t apply access keys to checkbox and radiobox rows in the
sidebar (Bug #14103). * [jan] Send correct MIME type for non-statically cached
javascript files. * [mjr] Added configuration support for version 2 of
WorldWeatherOnline’s API. **ingo 3.2.7** * [jan] Update Italian
translation. * [mjr] Add database migration for fixing corrupt rule ordering. *
[mjr] Fix corruption of rule order when reordering rules in certain cases.
**imp 6.2.11** * [mjr] Request that the contacts API only consider email fields
when detecting duplicates during automatic saving of attendees to the address
book (Bug #14119). * [jan] Don’t show ‘Create Keys’ button if creating PGP keys
is disabled (steffen.hau@rz.uni-mannheim.de, Request #14096). * [mjr] Fix
displaying iTips with certain locale/date_format preference combinations (Bug
#14076). **passwd 5.0.4** * [mjr] Fix changing password using Kolab driver
(Mike Gabriel).
——————————————————————————–
References:

[ 1 ] Bug #1277410 – php-horde-horde: Multiple CSRF vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=1277410
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-horde-ingo’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2015-a381facfd9
2015-11-04 18:17:28.547625
——————————————————————————–

Name : php-horde-horde
Product : Fedora 21
Version : 5.2.8
Release : 1.fc21
URL : http://www.horde.org/apps/horde
Summary : Horde Application Framework
Description :
The Horde Application Framework is a flexible, modular, general-purpose web
application framework written in PHP. It provides an extensive array of
components that are targeted at the common problems and tasks involved in
developing modern web applications. It is the basis for a large number of
production-level web applications, notably the Horde Groupware suites. For
more information on Horde or the Horde Groupware suites, visit
http://www.horde.org.

——————————————————————————–
Update Information:

**horde 5.2.8** * [mjr] SECURITY: Protect against CSRF attacks on various admin
pages. * [jan] Don’t apply access keys to checkbox and radiobox rows in the
sidebar (Bug #14103). * [jan] Send correct MIME type for non-statically cached
javascript files. * [mjr] Added configuration support for version 2 of
WorldWeatherOnline’s API. **ingo 3.2.7** * [jan] Update Italian
translation. * [mjr] Add database migration for fixing corrupt rule ordering. *
[mjr] Fix corruption of rule order when reordering rules in certain cases.
**imp 6.2.11** * [mjr] Request that the contacts API only consider email fields
when detecting duplicates during automatic saving of attendees to the address
book (Bug #14119). * [jan] Don’t show ‘Create Keys’ button if creating PGP keys
is disabled (steffen.hau@rz.uni-mannheim.de, Request #14096). * [mjr] Fix
displaying iTips with certain locale/date_format preference combinations (Bug
#14076). **passwd 5.0.4** * [mjr] Fix changing password using Kolab driver
(Mike Gabriel).
——————————————————————————–
References:

[ 1 ] Bug #1277410 – php-horde-horde: Multiple CSRF vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=1277410
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update php-horde-horde’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
7e

AutorTomislav Protega
Cert idNCERT-REF-2015-11-0011-ADV
ID izvornikaFEDORA-2015-37090
Proizvodphp
Izvorhttp://www.redhat.com
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa php-horde

Otkriven je sigurnosni nedostatak u programskom paketu php-horde. Otkriveni nedostatak potencijalnim napadačima omogućuje izvođenje Cross-Site Request Forgery (CSRF) napada. Svim...

Close