Resolved Bugs
1181223 – CVE-2014-9527 apache-poi: denial of service in HSLFSlideShow via corrupted PPT file<br
fix for RHBZ#1181223 (CVE-2014-9527)
Monthly Archives: February 2015
Fedora 21 Security Update: drupal7-views-3.10-1.fc21
Resolved Bugs
1192339 – drupal7-views-3.10 is available<br
– SA-CONTRIB-2015-039 – Views – Multiple vulnerabilities: https://www.drupal.org/node/2424403
– Release notes: https://www.drupal.org/node/2424103
Fedora 20 Security Update: drupal7-views-3.10-1.fc20
Resolved Bugs
1192339 – drupal7-views-3.10 is available<br
– SA-CONTRIB-2015-039 – Views – Multiple vulnerabilities: https://www.drupal.org/node/2424403
– Release notes: https://www.drupal.org/node/2424103
Fedora 21 Security Update: tomcat-7.0.59-1.fc21
Resolved Bugs
1109196 – CVE-2014-0227 Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter
1102210 – CVE-2014-0099 Apache Tomcat: Request smuggling via malicious content length header [fedora-all]
1088342 – CVE-2014-0096 Tomcat/JBossWeb: XXE vulnerability via user supplied XSLTs
1102152 – CVE-2014-0096 Apache Tomcat: XXE vulnerability via user supplied XSLTs [fedora-all]
1102678 – CVE-2014-0075 tomcat: Limited DoS in chunked transfer encoding input filter [fedora-all]
1027716 – Problem with log4j link creation on /usr/share/java/log4j
1190821 – CVE-2014-0227 tomcat: Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter [fedora-all]
1051743 – tomcat-jsvc service fails to start server
1076949 – tomcat: don’t provide javax.jsp-api and javax.servlet.jsp-api
1102030 – CVE-2014-0099 Tomcat/JBossWeb: Request smuggling via malicious content length header
1072776 – CVE-2014-0075 Tomcat/JBossWeb: Limited DoS in chunked transfer encoding input filter<br
Updated to 7.0.59
Fedora 21 Security Update: apache-poi-3.10.1-2.fc21
Resolved Bugs
1138135 – CVE-2014-3529 apache-poi: XML eXternal Entity (XXE) flaw<br
fix for RHBZ#1138135 (CVE-2014-3574)
WordPress Image Metadata Cruncher Cross Site Scripting
WordPress Image Metadata Cruncher plugin suffers from multiple cross site scripting vulnerabilities.
CVE-2015-0875
The Ogaki Kyoritsu Bank Smartphone Passbook application 1.0.0 for Android creates a log file containing input data from the user, which allows attackers to obtain sensitive information by reading a file.