Radicale, a simple calendar and addressbook server - daemon, is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. . Package : radicale Version : 0.9-1+deb8u2 CVE ID : CVE-2017-8342 Radicale, a simple calendar and addressbook server - daemon, is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. For Debian 8 "Jessie", this problem has been fixed in version 0.9-1+deb8u2. We recommend that you upgrade your radicale packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical security patch for Radicale addresses timing attack susceptibilities discovered in Debian 8, bolstering system safeguards.. Radicale Security Update, Timing Attack, Authentication Issue, Debian 8, Brute-Force. . LinuxSecurity.com Team
Security fix for CVE-2017-8342. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2ab5baea0a 2017-05-14 20:16:02.224952 --------------------------------------------------------------------------------Name : radicale Product : Fedora 25 Version : 1.1.2 Release : 1.fc25 URL : https://radicale.org/ Summary : A simple CalDAV (calendar) and CardDAV (contact) server Description : The Radicale Project is a CalDAV (calendar) and CardDAV (contact) server. It aims to be a light solution, easy to use, easy to install, easy to configure. As a consequence, it requires few software dependencies and is pre-configured to work out-of-the-box. The Radicale Project runs on most of the UNIX-like platforms (Linux, BSD, MacOS X) and Windows. It is known to work with Evolution, Lightning, iPhone and Android clients. It is free and open-source software, released under GPL version 3. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-8342 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447247 - CVE-2017-8342 radicale: Insufficient protection against timing oracles and bruteforce attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447247 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade radicale' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-8342. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-cdc7caed36 2017-05-14 20:15:03.388678 --------------------------------------------------------------------------------Name : radicale Product : Fedora 24 Version : 1.1.2 Release : 1.fc24 URL : https://radicale.org/ Summary : A simple CalDAV (calendar) and CardDAV (contact) server Description : The Radicale Project is a CalDAV (calendar) and CardDAV (contact) server. It aims to be a light solution, easy to use, easy to install, easy to configure. As a consequence, it requires few software dependencies and is pre-configured to work out-of-the-box. The Radicale Project runs on most of the UNIX-like platforms (Linux, BSD, MacOS X) and Windows. It is known to work with Evolution, Lightning, iPhone and Android clients. It is free and open-source software, released under GPL version 3. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-8342 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447247 - CVE-2017-8342 radicale: Insufficient protection against timing oracles and bruteforce attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447247 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade radicale' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-8342. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-863f86e7a9 2017-05-12 14:09:49.178117 --------------------------------------------------------------------------------Name : radicale Product : Fedora 26 Version : 1.1.2 Release : 1.fc26 URL : https://radicale.org/ Summary : A simple CalDAV (calendar) and CardDAV (contact) server Description : The Radicale Project is a CalDAV (calendar) and CardDAV (contact) server. It aims to be a light solution, easy to use, easy to install, easy to configure. As a consequence, it requires few software dependencies and is pre-configured to work out-of-the-box. The Radicale Project runs on most of the UNIX-like platforms (Linux, BSD, MacOS X) and Windows. It is known to work with Evolution, Lightning, iPhone and Android clients. It is free and open-source software, released under GPL version 3. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-8342 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447247 - CVE-2017-8342 radicale: Insufficient protection against timing oracles and bruteforce attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447247 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade radicale' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. . Hash: SHA512 Package : radicale Version : 0.7-1.1+deb7u2 CVE ID : CVE-2017-8342 Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. For Debian 7 "Wheezy", these problems have been fixed in version 0.7-1.1+deb7u2. We recommend that you upgrade your radicale packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Radicale 0.7-1.1+deb7u3 addresses vulnerabilities in timing and brute-force exploitation through the htpasswd authentication technique.. Radicale Security, Timing Attack Fix, Debian Security Update, Brute-Force Protection. . Severity: Important. LinuxSecurity.com Team
Two vulnerabilities were fixed in radicale, a CardDAV/CalDAV server. CVE-2015-8747 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3462-1
Version 1.1.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-f048c43393 2016-01-19 19:15:35.972948 -------------------------------------------------------------------------------- Name : radicale Product : Fedora 23 Version : 1.1.1 Release : 1.fc23 URL : https://radicale.org/ Summary : A simple CalDAV (calendar) and CardDAV (contact) server Description : The Radicale Project is a CalDAV (calendar) and CardDAV (contact) server. It aims to be a light solution, easy to use, easy to install, easy to configure. As a consequence, it requires few software dependencies and is pre-configured to work out-of-the-box. The Radicale Project runs on most of the UNIX-like platforms (Linux, BSD, MacOS X) and Windows. It is known to work with Evolution, Lightning, iPhone and Android clients. It is free and open-source software, released under GPL version 3. For further information, please visit the Radicale Website -------------------------------------------------------------------------------- Update Information: Version 1.1.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1295836 - CVE-2015-8747 CVE-2015-8748 radicale: Multiple security issues fixed in 1.1 https://bugzilla.redhat.com/show_bug.cgi?id=1295836 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update radicale' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.