You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa PHPMailer

Sigurnosni nedostatak programskog paketa PHPMailer

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2018-18f3eff32b
2018-11-27 03:30:06.112910
——————————————————————————–

Name : php-phpmailer6
Product : Fedora 29
Version : 6.0.6
Release : 1.fc29
URL : https://github.com/PHPMailer/PHPMailer
Summary : Full-featured email creation and transfer class for PHP
Description :
PHPMailer – A full-featured email creation and transfer class for PHP

Class Features
* Probably the world’s most popular code for sending email from PHP!
* Used by many open-source projects:
WordPress, Drupal, 1CRM, SugarCRM, Yii, Joomla! and many more
* Integrated SMTP support – send without a local mail server
* Send emails with multiple To, CC, BCC and Reply-to addresses
* Multipart/alternative emails for mail clients that do not read HTML email
* Add attachments, including inline
* Support for UTF-8 content and 8bit, base64, binary, and quoted-printable
encodings
* SMTP authentication with LOGIN, PLAIN, CRAM-MD5 and XOAUTH2 mechanisms
over SSL and SMTP+STARTTLS transports
* Validates email addresses automatically
* Protect against header injection attacks
* Error messages in 47 languages!
* DKIM and S/MIME signing support
* Compatible with PHP 5.5 and later
* Namespaced to prevent name clashes
* Much more!

Autoloader: /usr/share/php/PHPMailer/PHPMailer6/autoload.php

——————————————————————————–
Update Information:

**Version 6.0.6** * **SECURITY** Fix potential object injection
vulnerability. **CVE-2018-19296**. Reported by Sehun Oh of cyberone.kr. *
Added Tagalog translation, thanks to StoneArtz * Added Malagache translation,
thanks to Hackinet * Updated Serbian translation, fixed incorrect language
code, thanks to mmilanovic4 * Updated Arabic translations (MicroDroid) *
Updated Hungarian translations * Updated Dutch translations * Updated
Slovenian translation (filips123) * Updated Slovak translation (pcmanik) *
Updated Italian translation (sabas) * Updated Norwegian translation (aleskr)
* Updated Indonesian translation (mylastof) * Add constants for common
values, such as text/html and quoted-printable, and use them * Added support
for copied headers in DKIM, helping with debugging, and an option to add extra
headers to the DKIM signature. See DKIM_sign example for how to use them. Thanks
to gwi-mmuths. * Add Campaign Monitor transaction ID pattern matcher *
Remove deprecated constant and ini values causing warnings in PHP 7.3, added PHP
7.3 build to Travis config. * Expanded test coverage
——————————————————————————–
ChangeLog:

* Fri Nov 16 2018 Remi Collet <remi@remirepo.net> – 6.0.6-1
– update to 6.0.6
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2018-18f3eff32b’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2018-a2e9bd6eae
2018-11-27 03:30:06.112900
——————————————————————————–

Name : php-PHPMailer
Product : Fedora 29
Version : 5.2.27
Release : 1.fc29
URL : https://github.com/PHPMailer/PHPMailer
Summary : PHP email transport class with a lot of features
Description :
Full Featured Email Transfer Class for PHP. PHPMailer features:

* Supports emails digitally signed with S/MIME encryption!
* Supports emails with multiple TOs, CCs, BCCs and REPLY-TOs
* Works on any platform.
* Supports Text & HTML emails.
* Embedded image support.
* Multipart/alternative emails for mail clients that do not read
HTML email.
* Flexible debugging.
* Custom mail headers.
* Redundant SMTP servers.
* Support for 8bit, base64, binary, and quoted-printable encoding.
* Word wrap.
* Multiple fs, string, and binary attachments (those from database,
string, etc).
* SMTP authentication.
* Tested on multiple SMTP servers: Sendmail, qmail, Postfix, Gmail,
Imail, Exchange, etc.
* Good documentation, many examples included in download.
* It’s swift, small, and simple.

——————————————————————————–
Update Information:

**Version 5.2.27** * SECURITY Fix potential object injection vulnerability.
**CVE-2018-19296**. Reported by Sehun Oh of cyberone.kr. Note that the 5.2
branch is deprecated and will not receive security updates after 31st December
2018.
——————————————————————————–
ChangeLog:

* Fri Nov 16 2018 Remi Collet <remi@remirepo.net> – 5.2.27-1
– update to 5.2.27
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2018-a2e9bd6eae’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2018-46b92c9064
2018-11-27 03:12:43.615105
——————————————————————————–

Name : php-phpmailer6
Product : Fedora 27
Version : 6.0.6
Release : 1.fc27
URL : https://github.com/PHPMailer/PHPMailer
Summary : Full-featured email creation and transfer class for PHP
Description :
PHPMailer – A full-featured email creation and transfer class for PHP

Class Features
* Probably the world’s most popular code for sending email from PHP!
* Used by many open-source projects:
WordPress, Drupal, 1CRM, SugarCRM, Yii, Joomla! and many more
* Integrated SMTP support – send without a local mail server
* Send emails with multiple To, CC, BCC and Reply-to addresses
* Multipart/alternative emails for mail clients that do not read HTML email
* Add attachments, including inline
* Support for UTF-8 content and 8bit, base64, binary, and quoted-printable
encodings
* SMTP authentication with LOGIN, PLAIN, CRAM-MD5 and XOAUTH2 mechanisms
over SSL and SMTP+STARTTLS transports
* Validates email addresses automatically
* Protect against header injection attacks
* Error messages in 47 languages!
* DKIM and S/MIME signing support
* Compatible with PHP 5.5 and later
* Namespaced to prevent name clashes
* Much more!

Autoloader: /usr/share/php/PHPMailer/PHPMailer6/autoload.php

——————————————————————————–
Update Information:

**Version 6.0.6** * **SECURITY** Fix potential object injection
vulnerability. **CVE-2018-19296**. Reported by Sehun Oh of cyberone.kr. *
Added Tagalog translation, thanks to StoneArtz * Added Malagache translation,
thanks to Hackinet * Updated Serbian translation, fixed incorrect language
code, thanks to mmilanovic4 * Updated Arabic translations (MicroDroid) *
Updated Hungarian translations * Updated Dutch translations * Updated
Slovenian translation (filips123) * Updated Slovak translation (pcmanik) *
Updated Italian translation (sabas) * Updated Norwegian translation (aleskr)
* Updated Indonesian translation (mylastof) * Add constants for common
values, such as text/html and quoted-printable, and use them * Added support
for copied headers in DKIM, helping with debugging, and an option to add extra
headers to the DKIM signature. See DKIM_sign example for how to use them. Thanks
to gwi-mmuths. * Add Campaign Monitor transaction ID pattern matcher *
Remove deprecated constant and ini values causing warnings in PHP 7.3, added PHP
7.3 build to Travis config. * Expanded test coverage
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2018-46b92c9064’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

——————————————————————————–
Fedora Update Notification
FEDORA-2018-daee493feb
2018-11-27 03:12:43.615094
——————————————————————————–

Name : php-PHPMailer
Product : Fedora 27
Version : 5.2.27
Release : 1.fc27
URL : https://github.com/PHPMailer/PHPMailer
Summary : PHP email transport class with a lot of features
Description :
Full Featured Email Transfer Class for PHP. PHPMailer features:

* Supports emails digitally signed with S/MIME encryption!
* Supports emails with multiple TOs, CCs, BCCs and REPLY-TOs
* Works on any platform.
* Supports Text & HTML emails.
* Embedded image support.
* Multipart/alternative emails for mail clients that do not read
HTML email.
* Flexible debugging.
* Custom mail headers.
* Redundant SMTP servers.
* Support for 8bit, base64, binary, and quoted-printable encoding.
* Word wrap.
* Multiple fs, string, and binary attachments (those from database,
string, etc).
* SMTP authentication.
* Tested on multiple SMTP servers: Sendmail, qmail, Postfix, Gmail,
Imail, Exchange, etc.
* Good documentation, many examples included in download.
* It’s swift, small, and simple.

——————————————————————————–
Update Information:

**Version 5.2.27** * SECURITY Fix potential object injection vulnerability.
**CVE-2018-19296**. Reported by Sehun Oh of cyberone.kr. Note that the 5.2
branch is deprecated and will not receive security updates after 31st December
2018.
——————————————————————————–
ChangeLog:

* Fri Nov 16 2018 Remi Collet <remi@remirepo.net> – 5.2.27-1
– update to 5.2.27
* Mon Nov 6 2017 Remi Collet <remi@remirepo.net> – 5.2.26-1
– Update to 5.2.26
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade –advisory FEDORA-2018-daee493feb’ at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

AutorToni Vugdelija
Cert idNCERT-REF-2018-11-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak jezgre operacijskog sustava

Otkriven je sigurnosni nedostatak jezgre operacijskog sustava Fedora. Otkriveni nedostatak potencijalnim napadačima omogućuje otkrivanje osjetljivih informacija. Savjetuje se ažuriranje izdanim...

Close