Resolved Bugs
1181721 – CVE-2015-0203 qpid-cpp: qpidd can be crashed by authenticated user
1159008 – juno qpid: install qpid-cpp-server’ returned 1: Error: Package: qpid-cpp-client-0.30-3.fc21.x86_64<br
Resolves: BZ#1181721
Enabled building the linear store.
Monthly Archives: January 2015
Fedora 21 Security Update: arc-5.21p-5.fc21
Fedora 21 Security Update: suricata-2.0.6-1.fc21
Resolved Bugs
1173605 – libhtp: denial of service with specific packets
1173607 – suricata: libhtp: denial of service with specific packets [fedora-all]<br
This is a new upstream release fixing several serious bugs: reports of eveasion issues, sequence gaps in tcp stream reassembly under TLS detection, segfault in libhtp 0.5.15 which can lead to denial of service, and several others. See change log for details.
Fedora 21 Security Update: thunderbird-31.4.0-1.fc21
Resolved Bugs
1172386 – security update thunderbird for EPEL7<br
For list of changes see https://www.mozilla.org/en-US/thunderbird/31.4.0/releasenotes/
See https://www.mozilla.org/en-US/thunderbird/31.3.0/releasenotes/ for changes.
CVE-2014-2355
The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file.
CVE-2014-5418
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot) via crafted packets.
CVE-2014-5419
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different customers’ installations, which makes it easier for remote attackers to obtain the cleartext content of network traffic by reading this key from a firmware image and then sniffing the network.
CVE-2014-8143
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
CVE-2014-9194
Arbiter 1094B GPS Substation Clock allows remote attackers to cause a denial of service (disruption) via crafted radio transmissions that spoof GPS satellite broadcasts.
CVE-2014-9195
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.