[SECURITY] Fedora 20 Update: couchdb-1.6.1-4.fc20

updates at fedoraproject.org updates at fedoraproject.org
Fri Dec 12 04:03:17 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-16048
2014-12-01 18:08:27
--------------------------------------------------------------------------------

Name        : couchdb
Product     : Fedora 20
Version     : 1.6.1
Release     : 4.fc20
URL         : http://couchdb.apache.org/
Summary     : A document database server, accessible via a RESTful JSON API
Description :
Apache CouchDB is a distributed, fault-tolerant and schema-free
document-oriented database accessible via a RESTful HTTP/JSON API.
Among other features, it provides robust, incremental replication
with bi-directional conflict detection and resolution, and is
queryable and indexable using a table-oriented view engine with
JavaScript acting as the default view definition language.

--------------------------------------------------------------------------------
Update Information:

* Fix CVE-2010-5312 couchdb: jquery-ui: XSS vulnerability in jQuery.ui.dialog title option (rhbz #1166767)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Nov 27 2014 Peter Lemenkov <lemenkov at gmail.com> - 1.6.1-4
- Fix CVE-2010-5312 couchdb: jquery-ui: XSS vulnerability in jQuery.ui.dialog
  title option (rhbz #1166767)
* Fri Nov 14 2014 Peter Lemenkov <lemenkov at gmail.com> - 1.6.1-3
- Fix systemd unit file permissions (755 -> 644)
- Remove EL5,EL6 support
* Tue Nov  4 2014 Peter Lemenkov <lemenkov at gmail.com> - 1.6.1-2
- Rebuild for Erlang 17.3.3
* Sun Sep  7 2014 Peter Lemenkov <lemenkov at gmail.com> - 1.6.1-1
- Ver. 1.6.1
* Fri Aug 29 2014 Peter Lemenkov <lemenkov at gmail.com> - 1.6.0-13
- Kill fragile etap tests in favor of eunit-based test-suite
* Thu Aug 28 2014 Peter Lemenkov <lemenkov at gmail.com> - 1.6.0-12
- Rebuild with Erlang 17.2.1
* Tue Aug 26 2014 David Tardon <dtardon at redhat.com> - 1.6.0-11
- rebuild for ICU 53.1
* Sat Aug 16 2014 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.6.0-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Wed Jul  9 2014 Warren Togami <warren at slickage.com> - 1.6.0-9
- Add systemd notify support
* Sun Jul  6 2014 Warren Togami <warren at slickage.com> - 1.6.0-8
- SELinux: Use /usr/libexec/couchdb wrapper for systemd ExecStart, executes as couchdb_t
  Additional fixes to selinux-policy are required,
  see latest status http://wtogami.fedorapeople.org/a/2014/couchdb.txt
- Remove -heart from ExecStart, systemd handles service runtime
- default.ini contains default configuration from upstream.
  It has previously warned users to not modify it as it will be overwritten on package upgrade.
  Now package upgrades really will overwrite default.ini.
- Configuration is read during CouchDB startup in this order:
  default.ini -> default.d/*.ini -> local.d/*.ini -> local.ini
  Other packages are meant to drop configuration into default.d/
  Users can modify local.ini or add new files in local.d/
- CouchDB runtime config changes are written to local.ini
* Thu Jul  3 2014 Warren Togami <warren at slickage.com> - 1.6.0-6
- silence stdout/stderr to prevent redundant flooding of /var/log/messages
  CouchDB already logs these messages to /var/log/couchdb/couch.log
  Instead print the log filename to stdout, in case a user who ran it
  from the CLI is confused about where the messages went.
- -couch_ini accepts .ini or a .d/ directory.  For directories it reads
  any *.ini file.  Fixes #1002277.
* Mon Jun 23 2014 Peter Lemenkov <lemenkov at gmail.com> - 1.6.0-2
- Fix building with sligntly older gcc/glibc
* Sun Jun 22 2014 Peter Lemenkov <lemenkov at gmail.com> - 1.6.0-1
- Ver. 1.6.0
* Sat Jun  7 2014 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.5.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Fri Feb 14 2014 David Tardon <dtardon at redhat.com> - 1.5.0-2
- rebuild for new ICU
* Fri Jan 10 2014 Peter Lemenkov <lemenkov at gmail.com> - 1.5.0-1
- Ver. 1.5.0
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1166041 - CVE-2010-5312 jquery-ui: XSS vulnerability in jQuery.ui.dialog title option
        https://bugzilla.redhat.com/show_bug.cgi?id=1166041
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update couchdb' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list