[Pkg-owncloud-commits] [owncloud] 02/02: Update changelog for 7.0.4+dfsg-4~deb8u4 release

David Prévot taffit at moszumanska.debian.org
Wed Jan 6 21:29:13 UTC 2016


This is an automated email from the git hooks/post-receive script.

taffit pushed a commit to branch jessie
in repository owncloud.

commit cb1a2437779a8be067bab6122c1cf82fa9fb081d
Author: David Prévot <taffit at debian.org>
Date:   Tue Jan 5 22:25:45 2016 -0400

    Update changelog for 7.0.4+dfsg-4~deb8u4 release
---
 debian/changelog | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/debian/changelog b/debian/changelog
index e2e2e21..c3b8c58 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,17 @@
+owncloud (7.0.4+dfsg-4~deb8u4) jessie; urgency=medium
+
+  * Backport security fixes from 7.0.12, 8.0.10, and 8.0.9:
+    - Reflected XSS in OCS provider discovery
+      [oc-sa-2016-001] [CVE-2016-1498]
+    - Disclosure of files that begin with \".v\" due to unchecked return
+      value [oc-sa-2016-003] [CVE-2016-1500]
+    - Information Exposure Through Directory Listing in the file scanner
+      [oc-sa-2016-002] [CVE-2016-1499]
+    - Full installation path disclosure through error message
+      [oc-sa-2016-004] [CVE-2016-1501]
+
+ -- David Prévot <taffit at debian.org>  Tue, 05 Jan 2016 22:24:31 -0400
+
 owncloud (7.0.4+dfsg-4~deb8u3) jessie-security; urgency=high
 
   * Backport security fixes from 7.0.5, 7.0.7, 8.0.6, and 7.0.9:

-- 
Alioth's /usr/local/bin/git-commit-notice on /srv/git.debian.org/git/pkg-owncloud/owncloud.git



More information about the Pkg-owncloud-commits mailing list