Fedora 27: nikto Security Update
Summary
Nikto is a web server scanner which performs comprehensive tests against web
servers for multiple items, including over 3300 potentially dangerous
files/CGIs, versions on over 625 servers, and version specific problems
on over 230 servers. Scan items and plugins are frequently updated and
can be automatically updated (if desired).
Security fix for CVE-2018-11652
* Fri Jun 8 2018 Michal Ambroz
- bump to upstream version
- fix weekdays in changelog
- cherry pick patch from upstream for CVE-2018-11652 - bugs 1585612,1585614
* Thu Feb 8 2018 Fedora Release Engineering
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
[ 1 ] Bug #1585612 - CVE-2018-11652 nikto: CSV injection via the Server field in an HTTP response header
https://bugzilla.redhat.com/show_bug.cgi?id=1585612
su -c 'dnf upgrade --advisory FEDORA-2018-15bf411a32' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IA37PVTU2GGRX6GRHAXZ7YVUCCY26SQH/
FEDORA-2018-15bf411a32 2018-06-19 15:08:14.792781 Product : Fedora 27 Version : 2.1.6 Release : 1.fc27 URL : https://www.cirt.net/Nikto2 Summary : Web server scanner Description : Nikto is a web server scanner which performs comprehensive tests against web servers for multiple items, including over 3300 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired). Security fix for CVE-2018-11652 * Fri Jun 8 2018 Michal Ambroz - 1:2.1.6-1 - bump to upstream version - fix weekdays in changelog - cherry pick patch from upstream for CVE-2018-11652 - bugs 1585612,1585614 * Thu Feb 8 2018 Fedora Release Engineering - 1:2.1.5-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild [ 1 ] Bug #1585612 - CVE-2018-11652 nikto: CSV injection via the Server field in an HTTP response header https://bugzilla.redhat.com/show_bug.cgi?id=1585612 su -c 'dnf upgrade --advisory FEDORA-2018-15bf411a32' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IA37PVTU2GGRX6GRHAXZ7YVUCCY26SQH/
Change Log
References