Описание
ELSA-2013-0128: conga security, bug fix, and enhancement update (LOW)
[0.12.2-64.0.2.el5]
- Remove conga-enterprise.patch
[0.12.2-64.0.1.el5]
- Added conga-enterprise.patch
- Added conga-enterprise-Carthage.patch to support OEL5
- Replaced redhat logo image in conga-0.12.2.tar.gz and Data.fs
[0.12.2-64]
- Improvements for bz786372 (Better protect luci's authentication cookie)
- Improvements for bz607179 (Improper handling of session timeouts)
[0.12.2-60]
- Improvements for bz832185 (Luci cannot configure the 'identity_file' attribute for fence_ilo_mp)
- Improvements for bz822633 (Add luci support for nfsrestart)
[0.12.2-59]
- Fix bz835649 (luci uninstall will leave /var/lib/luci/var/pts and /usr/lib*/luci/zope/var/pts behind)
[0.12.2-58]
- Fix bz832183 (Luci is missing configuration of ssl for fence_ilo)
[0.12.2-57]
- Fix bz835649 (luci uninstall will leave /var/lib/luci/var/pts and /usr/lib*/luci/zope/var/pts behind)
[0.12.2-56]
- Fix bz842865 (Conga unable to find/install packages due to line breaks in yum output)
[0.12.2-55]
- Add support for IBM iPDU fencing configuration (Resolves bz741986)
[0.12.2-54]
- Fix bz839732 (Conga Add a Service Screen is Missing Option for Restart-Disable Recovery Policy)
[0.12.2-53]
- Fix bz786372 (Better protect luci's authentication cookie)
- Fix bz607179 (Improper handling of session timeouts)
[0.12.2-52]
- Fix bz822633 (Add luci support for nfsrestart)
- Fix bz832181 (fence_apc_snmp is missing from luci)
- Fix bz832183 (Luci is missing configuration of ssl for fence_ilo)
- Fix bz832185 (Luci cannot configure the 'identity_file' attribute for fence_ilo_mp)
Обновленные пакеты
Oracle Linux 5
Oracle Linux ia64
luci
0.12.2-64.0.2.el5
ricci
0.12.2-64.0.2.el5
Oracle Linux x86_64
luci
0.12.2-64.0.2.el5
ricci
0.12.2-64.0.2.el5
Oracle Linux i386
luci
0.12.2-64.0.2.el5
ricci
0.12.2-64.0.2.el5
Связанные CVE
Связанные уязвимости
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.