update to 2.2.13. fix CVE-2013-5855 rhbz#1087182,1065139. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-d6c87eb4af 2016-10-09 02:40:57.468639 -------------------------------------------------------------------------------- Name : mojarra Product : Fedora 25 Version : 2.2.13 Release : 1.fc25 URL : https://javaee.github.io/javaserverfaces-spec/ Summary : JSF Reference Implementation Description : JvaServer(TM) Faces technology simplifies building user interfaces for JavaServer applications. Developers of various skill levels can quickly build web applications by: assembling reusable UI components in a page; connecting these components to an application data source; and wiring client-generated events to server-side event handlers. -------------------------------------------------------------------------------- Update Information: update to 2.2.13. fix CVE-2013-5855 rhbz#1087182,1065139 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1065139 - CVE-2013-5855 Mojarra JSF: XSS due to insufficient escaping of user-supplied content in outputText tags and EL expressions https://bugzilla.redhat.com/show_bug.cgi?id=1065139 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mojarra' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
It was discovered that Mojarra, an implementation of JavaServer Faces, evaluates untrusted values as EL expressions if includeViewParameters is set to true. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2359-1
Get the latest Linux and open source security news straight to your inbox.