You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa springframework

Sigurnosni nedostatak programskog paketa springframework

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2016-f099190fee
2016-04-20 15:24:16.518262
——————————————————————————–

Name : springframework-amqp
Product : Fedora 23
Version : 1.3.9
Release : 4.fc23
URL : http://projects.spring.io/spring-amqp/
Summary : Support for Spring programming model with AMQP
Description :
The Spring AMQP project applies core Spring concepts to the
development of AMQP-based messaging solutions. It provides
a “template” as a high-level abstraction for sending and
receiving messages. It also provides support for Message
driven POJOs with a “listener container”. These libraries
facilitate management of AMQP resources while promoting the
use of dependency injection and declarative configuration.
In all of these cases, you will see similarities to the
JMS support in the Spring Framework.

——————————————————————————–
Update Information:

Security fix for CVE-2016-2173
——————————————————————————–
References:

[ 1 ] Bug #1326205 – CVE-2016-2173 springframework-amqp: remote code execution
https://bugzilla.redhat.com/show_bug.cgi?id=1326205
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update springframework-amqp’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2016-8d983eeb13
2016-04-21 21:26:59.079567
--------------------------------------------------------------------------------

Name        : drupal7-block_class
Product     : Fedora 22
Version     : 2.3
Release     : 1.fc22
URL         : http://drupal.org/project/block_class
Summary     : Allows users to add classes via block configuration interface
Description :
Block Class allows users to add classes to any block through the block's
configuration interface. By adding a very short snippet of PHP to a theme's
block.tpl.php file, classes can be added to the parent 
element of a block. This package provides the following Drupal module: * block_class -------------------------------------------------------------------------------- Update Information: ### 7.x-2.3 * The security update 2.2 broke very common class names, see [#2636548: upgrade to 2.2 converts class underscore to dash](https://www.drupal.org/node/2636548). ### 7.x-2.2 * Fixes [Block Class- Critical - Cross Site Scripting (XSS) - SA- CONTRIB-2015-175](https://www.drupal.org/node/2636502) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1327669 - CVE-2016-3144 drupal7-block_class: cross site scripting https://bugzilla.redhat.com/show_bug.cgi?id=1327669 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update drupal7-block_class' at the command line. For more information, refer to "Managing Software with yum", available at https://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
AutorMarko Stanec
Cert idNCERT-REF-2016-04-0008-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa samba

Otkriveni su sigurnosni nedostaci u programskom paketu samba za operacijski sustav Suse. Ranjivost, kojoj je dodijeljena oznaka CVE-2016-2118 te naziv...

Close