Fedora 28: nikto Security Update
Summary
Nikto is a web server scanner which performs comprehensive tests against web
servers for multiple items, including over 3300 potentially dangerous
files/CGIs, versions on over 625 servers, and version specific problems
on over 230 servers. Scan items and plugins are frequently updated and
can be automatically updated (if desired).
Security fix for CVE-2018-11652
* Fri Jun 8 2018 Michal Ambroz
- bump to upstream version
- fix weekdays in changelog
- cherry pick patch from upstream for CVE-2018-11652 - bugs 1585612,1585614
* Thu Feb 8 2018 Fedora Release Engineering
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
[ 1 ] Bug #1585612 - CVE-2018-11652 nikto: CSV injection via the Server field in an HTTP response header
https://bugzilla.redhat.com/show_bug.cgi?id=1585612
su -c 'dnf upgrade --advisory FEDORA-2018-5f30937bed' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WP2HP7GAFORSGSAPANE4VPDGGYJT5Q3B/
FEDORA-2018-5f30937bed 2018-06-20 01:47:18.141744 Product : Fedora 28 Version : 2.1.6 Release : 1.fc28 URL : https://www.cirt.net/Nikto2 Summary : Web server scanner Description : Nikto is a web server scanner which performs comprehensive tests against web servers for multiple items, including over 3300 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired). Security fix for CVE-2018-11652 * Fri Jun 8 2018 Michal Ambroz - 1:2.1.6-1 - bump to upstream version - fix weekdays in changelog - cherry pick patch from upstream for CVE-2018-11652 - bugs 1585612,1585614 * Thu Feb 8 2018 Fedora Release Engineering - 1:2.1.5-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild [ 1 ] Bug #1585612 - CVE-2018-11652 nikto: CSV injection via the Server field in an HTTP response header https://bugzilla.redhat.com/show_bug.cgi?id=1585612 su -c 'dnf upgrade --advisory FEDORA-2018-5f30937bed' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WP2HP7GAFORSGSAPANE4VPDGGYJT5Q3B/
Change Log
References