[SECURITY] Fedora 12 Update: sahana-0.6.3-1.fc12

updates at fedoraproject.org updates at fedoraproject.org
Fri May 7 03:54:55 UTC 2010


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-6379
2010-04-13 00:33:50
--------------------------------------------------------------------------------

Name        : sahana
Product     : Fedora 12
Version     : 0.6.3
Release     : 1.fc12
URL         : http://www.sahana.lk/
Summary     : Sahana is a free open source disaster management application
Description :
Sahana is a free and open source Disaster Management
System.It mainly facilitates management of Missing people,
disaster victims, Managing and administrating various
organisations, managing camps and managing requests and
assistance in the proper distribution of resources.

--------------------------------------------------------------------------------
Update Information:

This fixes an authentication/authorization bypass security problem.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Apr 11 2010 David Nalley <david at gnsa.us> 0.6.3-1
- fixed security issue notied in bz 575069 575065
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #575065 - CVE-2010-1191 Sahana: Authentication bypass via "acl_enable_acl" URLs
        https://bugzilla.redhat.com/show_bug.cgi?id=575065
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update sahana' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list