Monthly Archives: March 2015
GLSA 201503-08: file: Denial of Service
Fedora 20 Security Update: nx-libs-3.5.0.29-1.fc20
Update to 3.5.0.29:
– further reduction of code size by Mike Gabriel
– ~/.x2go/config/keystrokes.cfg, /etc/x2go/keystrokes.cfg and
/etc/nxagent/keystrokes.cfg are now respected thanks to Horst Schirmeier
– security fixes for CVE-2011-2895, CVE-2011-4028, CVE-2013-4396,
CVE-2013-6462, CVE-2014-0209, CVE-2014-0210, CVE-2014-0211,
CVE-2014-8092, CVE-2014-8097, CVE-2014-8095, CVE-2014-8096,
CVE-2014-8099, CVE-2014-8100, CVE-2014-8102, CVE-2014-8101,
CVE-2014-8093, CVE-2014-8098, CVE-2015-0255 by Michael DePaulo
– other (build) bug fixes
Update to 3.5.0.28:
o Fix non-working Copy+Paste into some rootless Qt applications when Xfixes extension is enabled in NX. Thanks to Ulrich Sibiller!
o Adapt X11 launchd socket path for recent Mac OS X versions.
o Fix Xinerama on Debian/Ubuntu installation (only worked on systems that had dpkg-dev installed) and all RPM based distros.
o Partly make nxcomp aware of nx-libs’s four-digit version string. Thanks to Nito Martinez from TheQVD project!
– Fix unowned directories
– Minor cleanup
Fedora 21 Security Update: nx-libs-3.5.0.29-1.fc21
Update to 3.5.0.29:
– further reduction of code size by Mike Gabriel
– ~/.x2go/config/keystrokes.cfg, /etc/x2go/keystrokes.cfg and
/etc/nxagent/keystrokes.cfg are now respected thanks to Horst Schirmeier
– security fixes for CVE-2011-2895, CVE-2011-4028, CVE-2013-4396,
CVE-2013-6462, CVE-2014-0209, CVE-2014-0210, CVE-2014-0211,
CVE-2014-8092, CVE-2014-8097, CVE-2014-8095, CVE-2014-8096,
CVE-2014-8099, CVE-2014-8100, CVE-2014-8102, CVE-2014-8101,
CVE-2014-8093, CVE-2014-8098, CVE-2015-0255 by Michael DePaulo
– other (build) bug fixes
Update to 3.5.0.28:
o Fix non-working Copy+Paste into some rootless Qt applications when Xfixes extension is enabled in NX. Thanks to Ulrich Sibiller!
o Adapt X11 launchd socket path for recent Mac OS X versions.
o Fix Xinerama on Debian/Ubuntu installation (only worked on systems that had dpkg-dev installed) and all RPM based distros.
o Partly make nxcomp aware of nx-libs’s four-digit version string. Thanks to Nito Martinez from TheQVD project!
– Fix unowned directories
– Minor cleanup
Fedora 22 Security Update: nx-libs-3.5.0.29-1.fc22
Update to 3.5.0.29:
– further reduction of code size by Mike Gabriel
– ~/.x2go/config/keystrokes.cfg, /etc/x2go/keystrokes.cfg and
/etc/nxagent/keystrokes.cfg are now respected thanks to Horst Schirmeier
– security fixes for CVE-2011-2895, CVE-2011-4028, CVE-2013-4396,
CVE-2013-6462, CVE-2014-0209, CVE-2014-0210, CVE-2014-0211,
CVE-2014-8092, CVE-2014-8097, CVE-2014-8095, CVE-2014-8096,
CVE-2014-8099, CVE-2014-8100, CVE-2014-8102, CVE-2014-8101,
CVE-2014-8093, CVE-2014-8098, CVE-2015-0255 by Michael DePaulo
– other (build) bug fixes
Update to 3.5.0.28:
o Fix non-working Copy+Paste into some rootless Qt applications when Xfixes extension is enabled in NX. Thanks to Ulrich Sibiller!
o Adapt X11 launchd socket path for recent Mac OS X versions.
o Fix Xinerama on Debian/Ubuntu installation (only worked on systems that had dpkg-dev installed) and all RPM based distros.
o Partly make nxcomp aware of nx-libs’s four-digit version string. Thanks to Nito Martinez from TheQVD project!
– Fix unowned directories
– Minor cleanup
CVE-2015-2304
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
Comsenz SupeSite CMS 7.0 SQL Injection
Comsenz SupeSite CMS version 7.0 suffers from a remote SQL injection vulnerability.
Serendipity CMS 2.0 Cross Site Scripting
Serendipity CMS version 2.0 suffers from a cross site scripting vulnerability.
Innovative WebPAC Pro 2.0 Open Redirect
Innovative WebPAC Pro version 2.0 suffers from non-validated redirects and forwards.
Fedora 22 Security Update: xen-4.5.0-6.fc22
Resolved Bugs
1201365 – CVE-2015-2152 xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119) [fedora-all]
1200398 – CVE-2015-2151 xen: hypervisor memory corruption due to x86 emulator flaw (xsa123) [fedora-all]
1200724 – CVE-2015-2152 xen: HVM qemu unexpectedly enabling emulated VGA graphics backends (XSA 119)
1196274 – CVE-2015-2151 xen: hypervisor memory corruption due to x86 emulator flaw (xsa123)<br
Additional patch for XSA-98 on arm64
HVM qemu unexpectedly enabling emulated VGA graphics backends [XSA-119, CVE-2015-2152]
Hypervisor memory corruption due to x86 emulator flaw [XSA-123, CVE-2015-2151]
Information leak via internal x86 system device emulation, Information leak through version information hypercall, fix a typo in xen.fedora.systemd.patch