Resolved Bugs
1048169 – CVE-2013-7252 kwallet: crypto misuse [fedora-all]
1177947 – kio_sftp.so corrupts files when reading
1048168 – CVE-2013-7252 kwallet: crypto misuse<br
Pull in upstream fixes for: CVE-2013-7252 kwallet: crypto misuse, and kio_sftp corruption
Monthly Archives: January 2015
Red Hat Security Advisory 2015-0036-01
Red Hat Security Advisory 2015-0036-01 – HTCondor is a specialized workload management system for compute-intensive jobs. It provides a job queuing mechanism, scheduling policy, priority scheme, and resource monitoring and management. The HTCondor scheduler can optionally notify a user of completed jobs by sending an email. Due to the way the daemon sent the email message, authenticated users able to submit jobs could execute arbitrary code with the privileges of the condor user. This issue was discovered by Florian Weimer of Red Hat Product Security.
Red Hat Security Advisory 2015-0035-01
Red Hat Security Advisory 2015-0035-01 – HTCondor is a specialized workload management system for compute-intensive jobs. It provides a job queuing mechanism, scheduling policy, priority scheme, and resource monitoring and management. The HTCondor scheduler can optionally notify a user of completed jobs by sending an email. Due to the way the daemon sent the email message, authenticated users able to submit jobs could execute arbitrary code with the privileges of the condor user. This issue was discovered by Florian Weimer of Red Hat Product Security.
Ubuntu Security Notice USN-2459-1
Ubuntu Security Notice 2459-1 – Pieter Wuille discovered that OpenSSL incorrectly handled Bignum squaring. Markus Stenberg discovered that OpenSSL incorrectly handled certain crafted DTLS messages. A remote attacker could use this issue to cause OpenSSL to crash, resulting in a denial of service. Karthikeyan Bhargavan discovered that OpenSSL incorrectly handled certain handshakes. A remote attacker could possibly use this issue to downgrade to ECDH, removing forward secrecy from the ciphersuite. Various other issues were also addressed.
Debian Security Advisory 3126-1
Debian Linux Security Advisory 3126-1 – It was discovered that libmagic as used by PHP, would trigger an out of bounds memory access when trying to identify a crafted file.
Red Hat Security Advisory 2015-0033-01
Red Hat Security Advisory 2015-0033-01 – Red Hat Satellite provides a solution to organizations requiring absolute control over and privacy of the maintenance and package deployment of their servers. It allows organizations to utilize the benefits of Red Hat Network without having to provide public Internet access to their servers or other client systems. This update introduces Red Hat Satellite 5.7.0.
Red Hat Security Advisory 2015-0034-01
Red Hat Security Advisory 2015-0034-01 – Red Hat JBoss Data Virtualization is a lean data integration solution that provides easy, real-time, and unified data access across disparate sources to multiple applications and users. JBoss Data Virtualization makes data spread across physically distinct systems such as multiple databases, XML files, and even Hadoop systems appear as a set of tables in a local database. This roll up patch serves as a cumulative upgrade for Red Hat JBoss Data Virtualization 6.0.0. It includes various bug fixes, which are listed in the README file included with the patch files.