[SECURITY] Fedora 19 Update: php-sabredav-Sabre_VObject-2.1.4-1.fc19

updates at fedoraproject.org updates at fedoraproject.org
Sat Nov 22 12:36:18 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-14066
2014-11-01 00:32:41
--------------------------------------------------------------------------------

Name        : php-sabredav-Sabre_VObject
Product     : Fedora 19
Version     : 2.1.4
Release     : 1.fc19
URL         : http://sabre.io/
Summary     : An intuitive reader for iCalendar and vCard objects
Description :
SabreDAV VObject plugin.

--------------------------------------------------------------------------------
Update Information:

This update provides ownCloud 5.0.17, the latest release in the 5.x series, plus an extra security-related fix backported from the stable5 branch.

It also provides SabreDAV 1.7.13. This is also a major upgrade from SabreDAV 1.6, and has API incompatibilities. ownCloud is the only Fedora 19 package that requires SabreDAV, and ownCloud 5 cannot work with SabreDAV 1.6: the API-incompatible upgrade is unfortunate but necessary to provide a secure ownCloud release.

ownCloud 4.5, the current version in Fedora 19, is un-maintained, subject to known security issues, and has no upgrade path beyond ownCloud 5. Upgrading directly from 4.5 to the current version in Fedora 20 or 21 - ownCloud 7 - would likely fail.

I plan to update the package to 6.x before Fedora 19 goes EOL and maintain the 5.x and 6.x builds in a side repository to make sure there is a viable upgrade path from Fedora 19.

Initial testing on the 4.x -> 5.x upgrade has been performed, but please back up your user data, ownCloud configuration and ownCloud database before performing the upgrade. Please file negative karma and a bug report for any issues encountered during the upgrade. Ideally, the upgrade should run smoothly on first access to the updated ownCloud instance with no manual intervention required.
--------------------------------------------------------------------------------
ChangeLog:

* Thu May 22 2014 Remi Collet <remi at fedoraproject.org> 2.1.4-1
- update to 2.1.4
- sources from github
- fix upstream URL
* Wed Feb 12 2014 Joseph Marrero <jmarrero at fedoraproject.org> 2.1.3-1
- update to 2.1.3
* Tue Sep  3 2013 Joseph Marrero <jmarrero at fedoraproject.org> 2.1.0-1
- update to 2.1.0
- use our own package.xml created by Remi Collet as upstream doesn't use pear anymore
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1035593 - CVE-2013-6403 owncloud: possible security bypass on admin page (5.0.13) [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1035593
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update php-sabredav-Sabre_VObject' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list