Fedora Linux Distribution - Page 556.25

Find the information you need for your favorite open source distribution .

Fedora 26: php-pear-CAS Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

**Changes in version 1.3.5** * Security Fixes: * Fix possible authentication bypass in validateCAS20 [#228] (Gregory Boddin) * Bug Fixes: * Fix file permissions (non-executable) [#177] (Remi Collet) * Fixed translations Greek and Japanese [#192] (ikari7789) * Fix errors under phpdbg [#204] (MasonM) * Fix logout replication error [#213] (Gregory Boddin) *

Fedora 25: proftpd Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Current upstream maintenance release for the 1.3.5 series. Includes fix for CVE-2017-7418, where not all path elements were checked for symlinks when using a chroot, so attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link.

Fedora 25: qemu Security Update 2017-01925dba3c

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

* chardev data is dropped when host side closed (bz #1352977) * CVE-2016-8667: dma: divide by zero error in set_next_tick (bz #1384876) * IPv6 DNS problems in qemu user networking (bz #1401165) * Fix crash in qxl memslot_get_virt (bz #1405847) * CVE-2017-5579: serial: fix memory leak in serial exit (bz #1416161) * spec: Pull in ipxe/vgabios links via -common package (bz #1431403) * Clean up

Fedora 25: ming Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Release 0.4.8 (no ABI or API changes) * Add PHP7 compatibility * Fix C++ output of disassembler * Fix heap overflows in parser.c (CVE-2017-7578) * Avoid division by zero in listmp3 when no valid frame was found (CVE-2016-9265) * Don't try printing unknown block (CVE-2016-9828) * Parse Protect tag's Password as string (CVE-2016-9827) * Check values before deriving malloc