Multiple cross-site scripting (XSS) vulnerabilities in Ultimate PHP Board (aka myUPB) 2.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or (2) avatar parameter to profile.php.
Monthly Archives: March 2015
Fedora EPEL 7 Security Update: 389-admin-1.1.38-1.el7
Resolved Bugs
1183154 – CVE-2015-0233 389-admin: multiple /tmp/ file vulnerabilities [epel-all]<br
releasing 1.1.38
MDVSA-2015:057: kernel
Multiple vulnerabilities has been found and corrected in the Linux
kernel:
The Crypto API in the Linux kernel before 3.18.5 allows local users
to load arbitrary kernel modules via a bind system call for an
AF_ALG socket with a parenthesized module template expression in
the salg_name field, as demonstrated by the vfat(aes) expression,
a different vulnerability than CVE-2013-7421 (CVE-2014-9644).
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before
3.18 generates incorrect conntrack entries during handling of certain
iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols,
which allows remote attackers to bypass intended access restrictions
via packets with disallowed port numbers (CVE-2014-8160).
The Crypto API in the Linux kernel before 3.18.5 allows local users
to load arbitrary kernel modules via a bind system call for an
AF_ALG socket with a module name in the salg_name field, a different
vulnerability than CVE-2014-9644 (CVE-2013-7421).
The updated packages provides a solution for these security issues.
RHBA-2015:0669-1: crash bug fix update
Red Hat Enterprise Linux: Updated crash packages that fix one bug are now available for Red Hat Enterprise
Linux 5.
RHBA-2015:0668-1: enchant bug fix update
Red Hat Enterprise Linux: Updated enchant packages that fix one bug are now available for Red Hat
Enterprise Linux 6.
RHBA-2015:0667-1: man-pages-fr bug fix update
Red Hat Enterprise Linux: An updated man-pages-fr package that fixes one bug is now available for Red Hat
Enterprise Linux 6.
RHBA-2015:0666-1: gstreamer-plugins-good bug fix update
Red Hat Enterprise Linux: Updated gstreamer-plugins-good packages that fix one bug are now available for
Red Hat Enterprise Linux 6.
RHBA-2015:0665-1: man-pages-ja bug fix update
Red Hat Enterprise Linux: An updated man-pages-ja package that fixes several bugs is now available for Red
Hat Enterprise Linux 6.
RHBA-2015:0664-1: icu bug fix update
Red Hat Enterprise Linux: Updated icu packages that fix one bug are now available for Red Hat Enterprise
Linux 6.
RHBA-2015:0663-1: fprintd bug fix update
Red Hat Enterprise Linux: Updated fprintd packages that fix one bug are now available for Red Hat
Enterprise Linux 6.