A security flaw was found in the way Apache CouchDB, a distributed, fault-tolerant and schema-free document-oriented database accessible via a RESTful HTTP/JSON API, processed certain JSON callback. A remote attacker could provide a specially-crafted JSON callback that, when processed could lead to arbitrary JSON code execution via Adobe Flash. Upstream advisory: [1] http://mail-archives.apache.org/mod_mbox/couchdb-user/201301.mbox/%3CD8573F7D-1848-4E9C-A4D6-E3B817136A0D@apache.org%3E
This issue affects the versions of the couchdb package, as shipped with Fedora release of 16 and 17. Please schedule an update. -- This issue affects the versions of the couchdb package, as shipped with Fedora EPEL 5 and Fedora EPEL 6. Please schedule an update.
Created couchdb tracking bugs for this issue Affects: fedora-all [bug 895597]
Created couchdb tracking bugs for this issue Affects: epel-all [bug 895599]