CouchDB 3.0.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-73bd8167a0 2020-03-16 20:26:14.978062 --------------------------------------------------------------------------------Name : couchdb Product : Fedora 32 Version : 3.0.0 Release : 1.fc32 URL : https://couchdb.apache.org/ Summary : A document database server, accessible via a RESTful JSON API Description : Apache CouchDB is a distributed, fault-tolerant and schema-free document-oriented database accessible via a RESTful HTTP/JSON API. Among other features, it provides robust, incremental replication with bi-directional conflict detection and resolution, and is queryable and indexable using a table-oriented view engine with JavaScript acting as the default view definition language. --------------------------------------------------------------------------------Update Information: CouchDB 3.0.0 --------------------------------------------------------------------------------ChangeLog: * Thu Mar 28 2019 Peter Lemenkov - 2.3.1-1 - Ver. 2.3.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1803197 - Install of CouchDB on Fedora 31 fails because nothing provides libmozjs185.so.1.0 https://bugzilla.redhat.com/show_bug.cgi?id=1803197 [ 2 ] Bug #1660481 - CVE-2018-17188 couchdb: Remote Privilege Escalations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1660481 [ 3 ] Bug #1660403 - CVE-2018-11769 couchdb: Possible privilege escalation by couchdb administrator to system couchdb user [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1660403 [ 4 ] Bug #1601003 - CVE-2018-8007 couchdb: Administrative Privilege Escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1601003 [ 5 ] Bug #1799258 - couchdb: FTBFS in Fedora rawhide/f32 https://bugzilla.redhat.com/show_bug.cgi?id=1799258 [ 6 ]Bug #1377306 - couchdb-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1377306 [ 7 ] Bug #1767037 - couchdb broken dependancies https://bugzilla.redhat.com/show_bug.cgi?id=1767037 [ 8 ] Bug #1735052 - couchdb: FTBFS in Fedora rawhide/f31 https://bugzilla.redhat.com/show_bug.cgi?id=1735052 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-73bd8167a0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for couchdb ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0392-1 Rating: important References: #1104204 Cross-References: CVE-2018-11769 Affected Products: SUSE OpenStack Cloud Crowbar 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for couchdb fixes the following issues: Security issue fixed: - CVE-2018-11769: Fixed a remote code execution vulnerability by removing the _config route from default.ini (bsc#1104204) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-392=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (x86_64): couchdb-1.7.2-3.6.1 couchdb-debuginfo-1.7.2-3.6.1 couchdb-debugsource-1.7.2-3.6.1 References: https://www.suse.com/security/cve/CVE-2018-11769.html https://bugzilla.suse.com/1104204 _______________________________________________ sle-security-updates mailing list
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for couchdb ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2578-1 Rating: important References: #1068386 #1100973 Cross-References: CVE-2017-12636 CVE-2018-8007 Affected Products: SUSE OpenStack Cloud 7 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for couchdb to 1.7.2 fixes the following security issues: - CVE-2018-8007: Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it was possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API (bsc#1100973). - CVE-2017-12636: CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allowed an admin user in Apache CouchDB to execute arbitrary shell commands as the CouchDB user (bsc#1068386). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2018-1807=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2018-1807=1 Package List: - SUSE OpenStack Cloud 7 (aarch64 s390x x86_64): couchdb-1.7.2-2.8.2 couchdb-debuginfo-1.7.2-2.8.2 couchdb-debugsource-1.7.2-2.8.2 - SUSE Enterprise Storage 4 (aarch64 x86_64): couchdb-1.7.2-2.8.2 couchdb-debuginfo-1.7.2-2.8.2 couchdb-debugsource-1.7.2-2.8.2 References: https://www.suse.com/security/cve/CVE-2017-12636.html https://www.suse.com/security/cve/CVE-2018-8007.html https://bugzilla.suse.com/1068386 https://bugzilla.suse.com/1100973 . A recent update for CouchDB addresses critical security vulnerabilities impacting both SUSE OpenStack Cloud and SUSE Enterprise Storage platforms.. SUSE OpenStack Cloud,CouchDB Security Update,SUSE Enterprise Storage,Configuration Issues,Apache CouchDB. . Severity: Important. LinuxSecurity.com Team
* CouchDB ver. 1.7.1 * Fixed CVE-2017-12635 * Fixed CVE-2017-12636 * Switched to eunit for testing * Erlang 20 compatible. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-d0a336a2a3 2017-12-09 21:09:01.031086 --------------------------------------------------------------------------------Name : erlang-jiffy Product : Fedora 26 Version : 0.14.13 Release : 1.fc26 URL : https://github.com/davisp/jiffy Summary : Erlang JSON parser Description : A JSON parser for Erlang implemented as a NIF. --------------------------------------------------------------------------------Update Information: * CouchDB ver. 1.7.1 * Fixed CVE-2017-12635 * Fixed CVE-2017-12636 * Switched to eunit for testing * Erlang 20 compatible --------------------------------------------------------------------------------References: [ 1 ] Bug #1516980 - CVE-2017-12636 couchdb: OS Command injection as couchdb user via remote configuration options https://bugzilla.redhat.com/show_bug.cgi?id=1516980 [ 2 ] Bug #1516979 - CVE-2017-12635 couchdb: Privilege escalation via _users documents with duplicate keys for 'roles' https://bugzilla.redhat.com/show_bug.cgi?id=1516979 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade erlang-jiffy' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.. =========================================================================Ubuntu Security Notice USN-1381-1 March 01, 2012 ubuntuone-couch vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 Summary: Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet. Software Description: - ubuntuone-couch: Ubuntu One CouchDB Details: It was discovered that Ubuntu One Couch did not perform any server certificate validation when using HTTPS connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to alter or compromise confidential information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: ubuntuone-couch 0.3.0-0ubuntu2.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1381-1 https://bugs.launchpad.net/ubuntu/+source/ubuntuone-couch/+bug/882049 Package Information: https://launchpad.net/ubuntu/+source/ubuntuone-couch/0.3.0-0ubuntu2.1 . Ubuntu Security Notice USN-1390-2 highlights a flaw in the NetworkManager, which may lead to unauthorized access to data.. ubuntu one couch, information exposure, security advisory. . Severity: Medium. LinuxSecurity.com Team
Dan Rosenberg discovered that in couchdb, a distributed, fault-tolerant and schema-free document-oriented database, an insecure library search path is used; a local attacker could execute arbitrary code by first dumping a maliciously crafted shared library in some . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ------------------------------------------------------------------------ Debian Security Advisory DSA-2107-1
Get the latest Linux and open source security news straight to your inbox.