You are here
Home > Preporuke > Sigurnosni nedostatak programskih paketa evolution, evolution-ews i evolution-data-server

Sigurnosni nedostatak programskih paketa evolution, evolution-ews i evolution-data-server

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2018-1434efb8f3
2018-07-22 03:02:16.238486
——————————————————————————–

Name : evolution
Product : Fedora 28
Version : 3.28.4
Release : 1.fc28
URL : https://wiki.gnome.org/Apps/Evolution
Summary : Mail and calendar client for GNOME
Description :
Evolution is the GNOME mailer, calendar, contact manager and
communications tool. The components which make up Evolution
are tightly integrated with one another and act as a seamless
personal information-management tool.

——————————————————————————–
Update Information:

Update to 3.28.4 upstream release
——————————————————————————–
ChangeLog:

* Mon Jul 16 2018 Milan Crha <mcrha@redhat.com> – 3.28.4-1
– Update to 3.28.4
* Mon Jun 18 2018 Milan Crha <mcrha@redhat.com> – 3.28.3-1
– Update to 3.28.3
* Mon May 7 2018 Milan Crha <mcrha@redhat.com> – 3.28.2-1
– Update to 3.28.2
——————————————————————————–
References:

[ 1 ] Bug #1592626 – CVE-2018-12422 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1592626
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2018-1434efb8f3’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XY2MV3R5ZZHRQ3BSJC536HYXVNBC5KAW/

——————————————————————————–
Fedora Update Notification
FEDORA-2018-1434efb8f3
2018-07-22 03:02:16.238486
——————————————————————————–

Name : evolution-ews
Product : Fedora 28
Version : 3.28.4
Release : 1.fc28
URL : https://wiki.gnome.org/Apps/Evolution
Summary : Evolution extension for Exchange Web Services
Description :
This package allows Evolution to interact with Microsoft Exchange servers,
versions 2007 and later, through its Exchange Web Services (EWS) interface.

——————————————————————————–
Update Information:

Update to 3.28.4 upstream release
——————————————————————————–
ChangeLog:

* Mon Jul 16 2018 Milan Crha <mcrha@redhat.com> – 3.28.4-1
– Update to 3.28.4
– Remove patch for GNOME bug #796297 (Fixed upstream)
* Mon Jun 25 2018 Milan Crha <mcrha@redhat.com> – 3.28.3-2
– Add patch for GNOME bug #796297 (Cannot modify existing meeting after fix for this bug)
* Mon Jun 18 2018 Milan Crha <mcrha@redhat.com> – 3.28.3-1
– Update to 3.28.3
* Mon May 7 2018 Milan Crha <mcrha@redhat.com> – 3.28.2-1
– Update to 3.28.2
——————————————————————————–
References:

[ 1 ] Bug #1592626 – CVE-2018-12422 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1592626
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2018-1434efb8f3’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3ISJYGSEJP7CYKMC43IT2JEPZLQO3FZY/

——————————————————————————–
Fedora Update Notification
FEDORA-2018-1434efb8f3
2018-07-22 03:02:16.238486
——————————————————————————–

Name : evolution-data-server
Product : Fedora 28
Version : 3.28.4
Release : 1.fc28
URL : https://wiki.gnome.org/Apps/Evolution
Summary : Backend data server for Evolution
Description :
The evolution-data-server package provides a unified backend for programs that work
with contacts, tasks, and calendar information.

It was originally developed for Evolution (hence the name), but is now used
by other packages.

——————————————————————————–
Update Information:

Update to 3.28.4 upstream release
——————————————————————————–
ChangeLog:

* Mon Jul 16 2018 Milan Crha <mcrha@redhat.com> – 3.28.4-1
– Update to 3.28.4
* Mon Jun 18 2018 Milan Crha <mcrha@redhat.com> – 3.28.3-1
– Update to 3.28.3
– Remove patch for GNOME bug #795997 (Fixed upstream)
* Mon May 14 2018 Milan Crha <mcrha@redhat.com> – 3.28.2-2
– Add patch for GNOME bug #795997 (Fails to parse Google OAuth2 authorization code)
* Mon May 7 2018 Milan Crha <mcrha@redhat.com> – 3.28.2-1
– Update to 3.28.2
——————————————————————————–
References:

[ 1 ] Bug #1592626 – CVE-2018-12422 evolution-data-server: Unsafe use of strcat allows buffer overflow in addressbook/backends/ldap/e-book-backend-ldap.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1592626
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2018-1434efb8f3’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKR3HNP6BFAXQSOH7D37DWHE5B7URZSS/

AutorZvonimir Bosnjak
Cert idNCERT-REF-2018-07-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa rust

Otkriven je sigurnosni nedostatak u programskom paketu rust za operacijski sustav Fedora. Otkriveni nedostatak potencijalnim napadačima omogućuje izvršavanje proizvoljnog programskog...

Close