Newman, David R (2021) EPrints 3.3.16 February 2021 security patch.
Patch file for security vulnerabilities - Other
Available under License Creative Commons GNU LGPL (Software). 3kB |
Official URL: http://wiki.eprits.org/
Abstract
A number of security vulnerabilities have been identified with EPrints 3.3.16 codebase and will have been present in earlier versions of EPrints 3.3. These vulnerabilities have been patched in EPrints 3.3 GitHub (https://github.com/eprints/eprints) but this provides a patch file to fix these vulnerabilities in 3.3.16. The scripts affected are: - /cgi/ajax/phrase : CVE-2021-26703 - /cgi/latex2png : CVE-2021-3342 - /cgi/toolbox/toolbox : CVE-2021-26704
Requirements
EPrints 3.3.16 already installed. May work on earlier versions of EPrints 3.3.
Installation
Run the following command as the eprints user. Assuming this patch file is in eprints' home directory and replacing EPRINTS_PATH for EPrints' root directory: patch -p1 -ruN -d EPRINTS_PATH < ~/eprints-3_3_16-vulns.patch
Copyright
University of Southampton
Repository Staff Only: edit this item