Update to ganglia-web 3.7.2, fixing a XSS issue.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-8749c58855 2016-09-04 00:22:36.131025 -------------------------------------------------------------------------------- Name : ganglia Product : Fedora 24 Version : 3.7.2 Release : 10.fc24 URL : https://sourceforge.net/projects/ganglia/ Summary : Distributed Monitoring System Description : Ganglia is a scalable, real-time monitoring and execution environment with all execution requests and statistics expressed in an open well-defined XML format. -------------------------------------------------------------------------------- Update Information: Update to ganglia-web 3.7.2, fixing a XSS issue. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1369843 - ganglia: ganglia-web: Reflected XSS in the metrics API [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1369843 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ganglia' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Update to ganglia-web 3.7.1, including security fix for CVE-2015-6816.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-de8ba28354 2015-11-01 01:51:21.178724 -------------------------------------------------------------------------------- Name : ganglia Product : Fedora 23 Version : 3.7.2 Release : 6.fc23 URL : https://sourceforge.net/projects/ganglia/ Summary : Distributed Monitoring System Description : Ganglia is a scalable, real-time monitoring and execution environment with all execution requests and statistics expressed in an open well-defined XML format. -------------------------------------------------------------------------------- Update Information: Update to ganglia-web 3.7.1, including security fix for CVE-2015-6816. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1260563 - CVE-2015-6816 ganglia: Bypassing Ganglia-web auth using boolean serialization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1260563 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ganglia' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Update to ganglia-web 3.7.1, including security fix for CVE-2015-6816.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-ee7a2b5844 2015-10-23 11:59:44.995208 -------------------------------------------------------------------------------- Name : ganglia Product : Fedora 22 Version : 3.7.2 Release : 6.fc22 URL : https://sourceforge.net/projects/ganglia/ Summary : Distributed Monitoring System Description : Ganglia is a scalable, real-time monitoring and execution environment with all execution requests and statistics expressed in an open well-defined XML format. -------------------------------------------------------------------------------- Update Information: Update to ganglia-web 3.7.1, including security fix for CVE-2015-6816. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1260563 - CVE-2015-6816 ganglia: Bypassing Ganglia-web auth using boolean serialization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1260563 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ganglia' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Update to ganglia-web 3.7.1, including security fix for CVE-2015-6816.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-accdc7ebfc 2015-10-23 11:54:19.355938 -------------------------------------------------------------------------------- Name : ganglia Product : Fedora 21 Version : 3.7.2 Release : 6.fc21 URL : https://sourceforge.net/projects/ganglia/ Summary : Distributed Monitoring System Description : Ganglia is a scalable, real-time monitoring and execution environment with all execution requests and statistics expressed in an open well-defined XML format. -------------------------------------------------------------------------------- Update Information: Update to ganglia-web 3.7.1, including security fix for CVE-2015-6816. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1260563 - CVE-2015-6816 ganglia: Bypassing Ganglia-web auth using boolean serialization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1260563 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ganglia' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Insufficient input sanitization in Ganglia, a web based monitoring system, could lead to remote PHP script execution with permissions of the user running the web browser. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2610-1
Get the latest Linux and open source security news straight to your inbox.