Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073, CVE-2016-7074
Category Archives: Fedora
Fedora – Security Updates
groovy-2.4.5-8.fc24
Security fix for CVE-2016-6814
groovy-2.4.5-10.fc25
Security fix for CVE-2016-6814
boomaga-0.8.0-6.git97f52c1.fc24
Update to 0.8.0-6.git97f52c1
boomaga-0.8.0-6.git97f52c1.fc25
Update to 0.8.0-6.git97f52c1
xemacs-packages-extra-20170114-1.fc25
This update fixes a security problem with the EDE package.
fedmsg-0.18.2-1.fc24
Fix validation logic in the base consumer
The base consumer is intended to only derive its validation switch from the
on-disk configuration if the child class doesn’t override the
validate_signatures switch.
There was a bug here where the default value provided in the base class made it
appear as if *all* child consumers had turned *off* validation, which is
incorrect.
This fix turns on signature validation by default while preserving the ability
of child consumers to override the on-disk configuration in special cases.
– Fixes: CVE-2017-1000001
– Reviewed-by: Patrick Uiterwijk
fedmsg-0.18.2-1.fc25
Fix validation logic in the base consumer
The base consumer is intended to only derive its validation switch from the
on-disk configuration if the child class doesn’t override the
validate_signatures switch.
There was a bug here where the default value provided in the base class made it
appear as if *all* child consumers had turned *off* validation, which is
incorrect.
This fix turns on signature validation by default while preserving the ability
of child consumers to override the on-disk configuration in special cases.
– Fixes: CVE-2017-1000001
– Reviewed-by: Patrick Uiterwijk
fedmsg-0.18.2-1.el7
Fix validation logic in the base consumer
The base consumer is intended to only derive its validation switch from the
on-disk configuration if the child class doesn’t override the
validate_signatures switch.
There was a bug here where the default value provided in the base class made it
appear as if *all* child consumers had turned *off* validation, which is
incorrect.
This fix turns on signature validation by default while preserving the ability
of child consumers to override the on-disk configuration in special cases.
– Fixes: CVE-2017-1000001
– Reviewed-by: Patrick Uiterwijk
bind99-9.9.9-4.P5.fc25
Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444