Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 10: FEDORA-2009-9601 Critical: Javascript Sanitation Issue

fedora
Calendar Grey September 15, 2009
Dist Fedora Esm H88
Essential security update for Fedora 10 aimed at fortifying JavaScript feeds, mitigating risks of exploits.
security patch to sanitize content from rss feeds for javascript

Summary

Planet is a flexible feed aggregator, this means that it downloads feeds

and aggregates their content together into a single combined feed with

the latest news first.

It uses Mark Pilgrim's Ultra-liberal feed parser so can read from RDF, RSS

and Atom feeds and Tomas Styblo's template library to output static files

in unlimited formats based on a series of templates.

Update Information:

security patch to sanitize content from rss feeds for javascript

Change Log

* Fri Sep 11 2009 Seth Vidal - 2.0-10 - javascript sanitize for https://bugzilla.redhat.com/show_bug.cgi?id=522802 * Sun Jul 26 2009 Fedora Release Engineering - 2.0-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Thu Feb 26 2009 Fedora Release Engineering - 2.0-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Sat Nov 29 2008 Ignacio Vazquez-Abrams - 2.0-7 - Rebuild for Python 2.6

References


[ 1 ] Bug #522802 - CVE-2009-2937 planet: Insufficient escaping of input feeds https://bugzilla.redhat.com/show_bug.cgi?id=522802

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update planet' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: planet
Product: Fedora 10
Version: 2.0
Release: 10.fc10
URL: Summary : Flexible RDF/RSS/Atom feed aggregator

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here