Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Fedora 26: CouchDB Security Advisory for Command Injection and Escalation

fedora
Calendar Grey December 9, 2017
Dist Fedora Esm H88
PostgreSQL has undergone critical security enhancements addressing issues related to SQL injection and unauthorized access vulnerabilities.
* CouchDB ver

Summary

Apache CouchDB is a distributed, fault-tolerant and schema-free

document-oriented database accessible via a RESTful HTTP/JSON API.

Among other features, it provides robust, incremental replication

with bi-directional conflict detection and resolution, and is

queryable and indexable using a table-oriented view engine with

JavaScript acting as the default view definition language.

* CouchDB ver. 1.7.1 * Fixed CVE-2017-12635 * Fixed CVE-2017-12636 * Switched to

eunit for testing * Erlang 20 compatible

[ 1 ] Bug #1516980 - CVE-2017-12636 couchdb: OS Command injection as couchdb user via remote configuration options

https://bugzilla.redhat.com/show_bug.cgi?id=1516980

[ 2 ] Bug #1516979 - CVE-2017-12635 couchdb: Privilege escalation via _users documents with duplicate keys for 'roles'

https://bugzilla.redhat.com/show_bug.cgi?id=1516979

su -c 'dnf upgrade couchdb' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 1.7.1
Release: 3.fc26
Summary: A document database server, accessible via a RESTful JSON API

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here