Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 27: 2018-15bf411a32 Moderate: Nikto CSV Injection

fedora
Calendar Grey June 19, 2018
Dist Fedora Esm H88
Update release for Fedora 27 mitigating CVE-2018-11652 vulnerability in nikto diagnostic tool to avert CSV injection risks.
Security fix for CVE-2018-11652

Summary

Nikto is a web server scanner which performs comprehensive tests against web

servers for multiple items, including over 3300 potentially dangerous

files/CGIs, versions on over 625 servers, and version specific problems

on over 230 servers. Scan items and plugins are frequently updated and

can be automatically updated (if desired).

Security fix for CVE-2018-11652

* Fri Jun 8 2018 Michal Ambroz - 1:2.1.6-1

- bump to upstream version

- fix weekdays in changelog

- cherry pick patch from upstream for CVE-2018-11652 - bugs 1585612,1585614

* Thu Feb 8 2018 Fedora Release Engineering - 1:2.1.5-15

- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[ 1 ] Bug #1585612 - CVE-2018-11652 nikto: CSV injection via the Server field in an HTTP response header

https://bugzilla.redhat.com/show_bug.cgi?id=1585612

su -c 'dnf upgrade --advisory FEDORA-2018-15bf411a32' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IA37PVTU2GGRX6GRHAXZ7YVUCCY26SQH/

Change Log

References

Update Instructions

Product: Fedora 27
Version: 2.1.6
Release: 1.fc27
URL:
Summary: Web server scanner

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here