You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa WebCalendar

Sigurnosni nedostaci programskog paketa WebCalendar

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2017-26a53ccbdf
2017-10-09 13:07:48.300189
——————————————————————————–

Name : WebCalendar
Product : Fedora 25
Version : 1.2.9
Release : 1.fc25
URL : http://www.k5n.us/webcalendar.php
Summary : Single/multi-user web-based calendar application
Description :
WebCalendar is a PHP-based calendar application that can be configured as a
single-user calendar, a multi-user calendar for groups of users, or as an
event calendar viewable by visitors. MySQL, PostgreSQL, Oracle, DB2,
Interbase, MS SQL Server, or ODBC is required.
WebCalendar can be setup in a variety of ways, such as…
* A schedule management system for a single person
* A schedule management system for a group of people, allowing one or
more assistants to manage the calendar of another user
* An events schedule that anyone can view, allowing visitors to submit
new events
* A calendar server that can be viewed with iCal-compliant calendar
applications like Mozilla Sunbird, Apple iCal or GNOME Evolution or
RSS-enabled applications like Firefox, Thunderbird, RSSOwl, or
FeedDemon, or BlogExpress.

——————————————————————————–
Update Information:

New upstream release. Fixes CVE-2017-10840 and CVE-2017-10841.<br> Upstream
moved from sourceforge to github.<br> PHP >= 5.3 required.<br> Adjust httpd
configuration to support PHP FCGI.
——————————————————————————–
References:

[ 1 ] Bug #1486208 – CVE-2017-10840 CVE-2017-10841 WebCalendar: Cross-site scripting and directory traversal issues
https://bugzilla.redhat.com/show_bug.cgi?id=1486208
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade WebCalendar’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2017-c9abeb3158
2017-10-09 13:07:47.580265
——————————————————————————–

Name : WebCalendar
Product : Fedora 26
Version : 1.2.9
Release : 1.fc26
URL : http://www.k5n.us/webcalendar.php
Summary : Single/multi-user web-based calendar application
Description :
WebCalendar is a PHP-based calendar application that can be configured as a
single-user calendar, a multi-user calendar for groups of users, or as an
event calendar viewable by visitors. MySQL, PostgreSQL, Oracle, DB2,
Interbase, MS SQL Server, or ODBC is required.
WebCalendar can be setup in a variety of ways, such as…
* A schedule management system for a single person
* A schedule management system for a group of people, allowing one or
more assistants to manage the calendar of another user
* An events schedule that anyone can view, allowing visitors to submit
new events
* A calendar server that can be viewed with iCal-compliant calendar
applications like Mozilla Sunbird, Apple iCal or GNOME Evolution or
RSS-enabled applications like Firefox, Thunderbird, RSSOwl, or
FeedDemon, or BlogExpress.

——————————————————————————–
Update Information:

New upstream release. Fixes CVE-2017-10840 and CVE-2017-10841.<br> Upstream
moved from sourceforge to github.<br> PHP >= 5.3 required.<br> Adjust httpd
configuration to support PHP FCGI.
——————————————————————————–
References:

[ 1 ] Bug #1486208 – CVE-2017-10840 CVE-2017-10841 WebCalendar: Cross-site scripting and directory traversal issues
https://bugzilla.redhat.com/show_bug.cgi?id=1486208
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade WebCalendar’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

AutorDanijel Kozinovic
Cert idNCERT-REF-2017-10-0054-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa PCRE2

Otkriveni su sigurnosni nedostaci u programskom paketu PCRE2 za operacijski sustav Gentoo. Otkriveni nedostaci potencijalnim udaljenim napadačima omogućuju izvršavanje proizvoljnog...

Close