-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9128 2015-05-30 09:30:09 -------------------------------------------------------------------------------- Name : fusionforge Product : Fedora 21 Version : 5.3.2 Release : 4.fc21 URL : Summary : Collaborative development tool Description : FusionForge provides many tools to aid collaboration in a development project, such as bug-tracking, task management, mailing-lists, SCM repository, forums, support request helper, web/FTP hosting, release management, etc. All these services are integrated into one web site and managed through a web interface. This metapackage installs a stand-alone FusionForge site. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-0850 CVE-2015-0850: Prevent arbitrary command execution via clone URL parameter of the method to create secondary Git repositories. Found by Ansgar Burchardt. -------------------------------------------------------------------------------- ChangeLog: * Thu May 28 2015 Sylvain Beucler - 5.3.2-4 - CVE-2015-0850: Prevent arbitrary command execution via clone URL parameter of the method to create secondary Git repositories. Found by Ansgar Burchardt . -------------------------------------------------------------------------------- References: [ 1 ] Bug #1226872 - CVE-2015-0850 fusionforge: incorrect input validation in Git plug-in https://bugzilla.redhat.com/show_bug.cgi?id=1226872 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update fusionforge' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce