MGASA-2016-0057
Dashboard / Vulnerabilities / MGASA-2016-0057
Summary: Updated radicale packages fix CVE-2015-8748
Details: Updated radicale package fixes security vulnerabilities: If an attacker is able to authenticate with a user name like `.*', he can bypass read/write limitations imposed by regex-based rules, including the built-in rules `owner_write' (read for everybody, write for the calendar owner) and `owner_only' (read and write for the calendar owner) (CVE-2015-8748). The radicale package has been updated to version 1.1.1, fixing this issue and several other security issues.
References: https://advisories.mageia.org/MGASA-2016-0057.html, https://bugs.mageia.org/show_bug.cgi?id=17452, http://radicale.org/news/, https://www.debian.org/security/2016/dsa-3462
Affected packages
Package
Name: radicale
Purl: pkg:rpm/mageia/radicale?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
