Fedora Essential and Critical Security Patch Updates - Page 722
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Privilege escalation via emulated floppy disk drive [XSA-133, CVE-2015-3456] (#1221153)
Latest upstream bugfix. Fixed dcraw vulnerability in ljpeg_start()
This update fixes a bug in the DER parser which is used to decode SSL/TLS certificates could crash Suricata. Also, those processing large numbers of (untrusted) pcap files need to update as a malformed pcap could crash Suricata.
Privilege escalation via emulated floppy disk drive [XSA-133, CVE-2015-3456] (#1221153)
Update to version 0.16.1, see https://www.libraw.org/download for details. Security fix for CVE-2015-3885.
Security update for integer underflow in AP mode WMM Action frame processing.
Update to version 0.16.2, see https://www.libraw.org/download for details. Update to version 0.16.1, see https://www.libraw.org/download for details. Security fix for CVE-2015-3885.
* CVE-2015-3456: (VENOM) fdc: out-of-bounds fifo buffer memory access (bz #1221152)
**WordPress 4.2 “Powell†** * Upstream announcement https://wordpress.org/news/2015/04/powell/ **WordPress 4.2.1 Security Release** * Upstream announcement https://wordpress.org/news/2015/04/wordpress-4-2-1/ **WordPress 4.2.2 Security and Maintenance Release**
**WordPress 4.2 “Powell†** * Upstream announcement https://wordpress.org/news/2015/04/powell/ **WordPress 4.2.1 Security Release** * Upstream announcement https://wordpress.org/news/2015/04/wordpress-4-2-1/ **WordPress 4.2.2 Security and Maintenance Release**
* **ZF2015-04**: Zend\Mail and Zend\Http were both susceptible to CRLF Injection Attack vectors (for HTTP, this is often referred to as HTTP Response Splitting). Both components were updated to perform header value validations to ensure no values contain characters not detailed in their corresponding specifications, and will raise exceptions on detection. Each also provides new facilities for both [More...]
fixes CVE-2015-3420: SSL/TLS handshake failures leading to a crash of the login process - dovecot updated to 2.2.16 - auth: Don't crash if master user login is attempted without any configured master=yes passdbs - Parsing UTF-8 text for mails could have caused broken results
* **ZF2015-04**: Zend\Mail and Zend\Http were both susceptible to CRLF Injection Attack vectors (for HTTP, this is often referred to as HTTP Response Splitting). Both components were updated to perform header value validations to ensure no values contain characters not detailed in their corresponding specifications, and will raise exceptions on detection. Each also provides new facilities for both [More...]
fixes CVE-2015-3420: SSL/TLS handshake failures leading to a crash of the login process - dovecot updated to 2.2.16 - auth: Don't crash if master user login is attempted without any configured master=yes passdbs - Parsing UTF-8 text for mails could have caused broken results
phpMyAdmin 4.4.6.1 (2015-05-13) - [security] CSRF vulnerability in setup - [security] Vulnerability allowing man-in-the-middle attack