Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 27: Security Advisory for php-pear-CAS XSS and Session Problems

fedora
Calendar Grey November 9, 2018
Dist Fedora Esm H88
Enhancements for php-pear-CAS on Fedora 27, tackling XSS vulnerabilities and session management concerns, featuring optimizations and error rectifications.
**Version 1.3.6** **Security Fixes:** * Fix XSS in proxy mode [#271] (Joachim Fritschi) **Bug Fixes:** * Fix bad condition [#252] (Brice Vercoustre) * Hash ticket strings to g...

Summary

This package is a PEAR library for using a Central Authentication Service.

Autoloader '%{pear_phpdir}/CAS/Autoload.php';

**Version 1.3.6** **Security Fixes:** * Fix XSS in proxy mode [#271]

(Joachim Fritschi) **Bug Fixes:** * Fix bad condition [#252] (Brice

Vercoustre) * Hash ticket strings to generate valid-length session-ids [#224,

#244, #248] (Adam Franco) * Fix "phpCAS" class capitalization in code [#273,

#277] (phy25) **Improvement:** * Remove fallback for __autoload [#247]

(marinaglancy) * More robust check for Windows OS in File.php [#275]

(xamount) * Fix continue statement within switch/case for php 7.3

compatibility [#278] (stonk7)

* Fri Oct 26 2018 Remi Collet - 1.3.6-1

- update to 1.3.6

- new github and packagist owner

su -c 'dnf upgrade --advisory FEDORA-2018-95695b59c7' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 1.3.6
Release: 1.fc27
Summary: Central Authentication Service client library in php

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here