Fedora Linux Distribution - Page 437.25

Find the information you need for your favorite open source distribution .

Fedora 28: php-pear-CAS Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

**Version 1.3.6** **Security Fixes:** * Fix XSS in proxy mode [#271] (Joachim Fritschi) **Bug Fixes:** * Fix bad condition [#252] (Brice Vercoustre) * Hash ticket strings to generate valid-length session-ids [#224, #244, #248] (Adam Franco) * Fix "phpCAS" class capitalization in code [#273, #277] (phy25) **Improvement:** * Remove fallback for __autoload [#247]

Fedora 29: zchunk Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This update does sanity checking when an application passes in a checksum to verify. Before this release, applications could pass in non-hex values for the checksum, which could cause zchunk to crash. Now non-hex values will be rejected.

Fedora 28: roundcubemail Security Update 2018-928e15e1db

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

**Version 1.3.8** This is a service release to update the stable version 1.3 of Roundcube Webmail. It contains fixes to several bugs backported from the master branch including a security fix for a reported XSS vulnerability plus updates to ensure compatibility with PHP 7.3 and recent versions of Courier-IMAP, Dovecot and MySQL 8. See the complete changelog below. **Changelog** - Fix PHP

Fedora 29: webkit2gtk3 Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This update addresses the following vulnerability: * [CVE-2018-4345](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4345) This update brings the following changes: * Many improvements and fixes for video playback with media source extensions (MSE), which improve the user experience across the board, and in particular for playback of WebM videos. *

Fedora 27: roundcubemail Security Update 2018-d527206a77

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

**Version 1.3.8** This is a service release to update the stable version 1.3 of Roundcube Webmail. It contains fixes to several bugs backported from the master branch including a security fix for a reported XSS vulnerability plus updates to ensure compatibility with PHP 7.3 and recent versions of Courier-IMAP, Dovecot and MySQL 8. See the complete changelog below. **Changelog** - Fix PHP

Fedora 29: lldpad Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

- Add upstream fix for improper sanitization of shell-escape codes when lldptool parses a mngAddr TLV (CVE-2018-10932). - Add upstream patch to support DSCP selectors in APP TLVs. This allows configuration of DSCP-based packet prioritization on capable network devices.