[Pkg-owncloud-commits] [owncloud] 02/02: Update changelog for 7.0.4+dfsg-4~deb8u4 release
David Prévot
taffit at moszumanska.debian.org
Wed Jan 6 21:29:13 UTC 2016
This is an automated email from the git hooks/post-receive script.
taffit pushed a commit to branch jessie
in repository owncloud.
commit cb1a2437779a8be067bab6122c1cf82fa9fb081d
Author: David Prévot <taffit at debian.org>
Date: Tue Jan 5 22:25:45 2016 -0400
Update changelog for 7.0.4+dfsg-4~deb8u4 release
---
debian/changelog | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/debian/changelog b/debian/changelog
index e2e2e21..c3b8c58 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,17 @@
+owncloud (7.0.4+dfsg-4~deb8u4) jessie; urgency=medium
+
+ * Backport security fixes from 7.0.12, 8.0.10, and 8.0.9:
+ - Reflected XSS in OCS provider discovery
+ [oc-sa-2016-001] [CVE-2016-1498]
+ - Disclosure of files that begin with \".v\" due to unchecked return
+ value [oc-sa-2016-003] [CVE-2016-1500]
+ - Information Exposure Through Directory Listing in the file scanner
+ [oc-sa-2016-002] [CVE-2016-1499]
+ - Full installation path disclosure through error message
+ [oc-sa-2016-004] [CVE-2016-1501]
+
+ -- David Prévot <taffit at debian.org> Tue, 05 Jan 2016 22:24:31 -0400
+
owncloud (7.0.4+dfsg-4~deb8u3) jessie-security; urgency=high
* Backport security fixes from 7.0.5, 7.0.7, 8.0.6, and 7.0.9:
--
Alioth's /usr/local/bin/git-commit-notice on /srv/git.debian.org/git/pkg-owncloud/owncloud.git
More information about the Pkg-owncloud-commits
mailing list