This is the mail archive of the gnats-announce@sources.redhat.com mailing list for the GNATS project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]

Announcing gnatsweb 2.8.2


A new release of Gnatsweb is available for download.

Version 2.8.2 fixes a serious security flaw present in versions 2.7 beta, 
2.8.0 and 2.8.1, whereby an attacker could potentially gain access to any 
file or execute any command on the Gnatsweb server machine. This is the 
only change from 2.8.1.

I strongly urge anyone running affected versions of Gnatsweb to either 
upgrade their installations immediately, or apply the fixes detailed in 
http://sources.redhat.com/gnats/gnatsweb/advisory-jun-26-2001.html

Yngve Svendsen
Gnatsweb maintainer


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]