Red Hat Enterprise Linux: Updated shim packages that fix three security issues are now available for
Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having Moderate security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2014-3675, CVE-2014-3676, CVE-2014-3677
Red Hat Enterprise Linux: An updated mod_auth_mellon package that fixes two security issues is now
available for Red Hat Enterprise Linux 6.
Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2014-8566, CVE-2014-8567
Red Hat Enterprise Linux: Updated hwcert-client-info-1.6.5.2 package that adds one enhancement is now
available for Red Hat Enterprise Linux Hardware Certification.
Red Hat Enterprise Linux: Updated nfs-utils packages that add two enhancements are now available for Red
Hat Enterprise Linux 6 Extended Update Support.
A security issue affects these releases of Ubuntu and its
derivatives:
Ubuntu 14.10
Ubuntu 14.04 LTS
Ubuntu 12.04 LTS
Summary
Several security issues were fixed in Ruby.
Software description
ruby1.8
– Object-oriented scripting language
ruby1.9.1
– Object-oriented scripting language
ruby2.0
– Object-oriented scripting language
ruby2.1
– Object-oriented scripting language
Details
Will Wood discovered that Ruby incorrectly handled the encodes() function. An attacker could possibly use this issue to cause Ruby to crash, resulting in a denial of service, or possibly execute arbitrary code. The default compiler options for affected releases should reduce the vulnerability to a denial of service. (CVE-2014-4975)
Willis Vandevanter discovered that Ruby incorrectly handled XML entity expansion. An attacker could use this flaw to cause Ruby to consume large amounts of resources, resulting in a denial of service. (CVE-2014-8080)
Update instructions
The problem can be corrected by updating your system to the following
package version:
A security issue affects these releases of Ubuntu and its
derivatives:
Ubuntu 14.10
Ubuntu 14.04 LTS
Summary
LibreOffice could be made to crash or run programs if it received specially
crafted network traffic.
Software description
libreoffice
– Office productivity suite
Details
It was discovered that LibreOffice incorrectly handled the Impress remote control port. An attacker could possibly use this issue to cause Impress to crash, resulting in a denial of service, or possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following
package version:
This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart LibreOffice to make all the necessary changes.