Resolved Bugs
1112497 – Please update to librest 0.7.91 in f20
1204682 – rest: memory corruption when using oauth because of implicit declaration of rest_proxy_call_get_url [fedora-all]<br
CVE-2015-2675 rest: memory corruption when using oauth because of implicit declaration of rest_proxy_call_get_url
Monthly Archives: March 2015
Fedora 20 Security Update: libzip-0.11.2-5.fc20
Fedora 22 Security Update: mingw-libzip-0.11.2-3.fc22
Fedora 21 Security Update: mingw-qt5-qtbase-5.4.1-1.fc21,mingw-qt5-qtdeclarative-5.4.1-1.fc21,mingw-qt5-qtgraphicaleffects-5.4.1-1.fc21,mingw-qt5-qtimageformats-5.4.1-1.fc21,mingw-qt5-qtlocation-5.4.1-1.fc21,mingw-qt5-qtmultimedia-5.4.1-1.fc21,mingw-qt5-qtquick1-5.4.1-1.fc21,mingw-qt5-qtscript-5.4.1-1.fc21,mingw-qt5-qtsensors-5.4.1-1.fc21,mingw-qt5-qtsvg-5.4.1-1.fc21,mingw-qt5-qttools-5.4.1-1.fc21,mingw-qt5-qttranslations-5.4.1-1.fc21,mingw-qt5-qtwebkit-5.4.1-1.fc21,mingw-qt5-qtwinextras-5.4.1-1.fc21
Resolved Bugs
1204798 – mingw-qt5-qtwebkit: qt5-qtwebkit: QtWebKit logs visited URLs to WebpageIcons.db in private browsing mode [fedora-all]<br
Update to Qt 5.4.1
Fedora 22 Security Update: drupal7-webform-4.6-1.fc22
Resolved Bugs
1205125 – drupal7-webform: drupal webform: multiple XSS flaws [fedora-all]
1205122 – drupal webform: multiple XSS flaws
1199067 – drupal7-webform-4.5 is available<br
– Security fix for drupal7-webform module
– Upstream release notes: https://www.drupal.org/node/2457219
– Release notes can be found at https://www.drupal.org/node/2454063
Fedora 20 Security Update: moodle-2.6.10-1.fc20
Resolved Bugs
1203205 – CVE-2015-2269 CVE-2015-2268 CVE-2015-2267 CVE-2015-2266 CVE-2015-2272 CVE-2015-2273 CVE-2015-2270 CVE-2015-2271 moodle: multiple flaws in moodle [epel-6]
1190119 – CVE-2015-1493 moodle: Directory Traversal Attack possible through some files serving JS (MSA-15-0009) [fedora-all]
1203203 – CVE-2015-2269 CVE-2015-2268 CVE-2015-2267 CVE-2015-2266 CVE-2015-2272 CVE-2015-2273 CVE-2015-2270 CVE-2015-2271 moodle: multiple flaws in moodle [fedora-all]<br
Update to latest versions of the respective branches. f20 has been updated from 2.5.x to 2.6.x because 2.5.x is EOL.
Fedora 22 Security Update: quassel-0.11.0-2.fc22
Fedora 20 Security Update: python-dulwich-0.10.0-1.fc20
Resolved Bugs
1204889 – CVE-2014-9706 python-dulwich: arbitrary files allowed to be commited, leading to code execution
1204890 – CVE-2014-9706 python-dulwich: arbitrary files allowed to be commited, leading to code execution [fedora-all]
1204891 – CVE-2014-9706 python-dulwich: arbitrary files allowed to be commited, leading to code execution [epel-all]<br
Fix for CVE-2014-9706 (rhbz#1204889, rhbz#1204890, and rhbz#1204891)
Fedora 22 Security Update: python-django-1.8-0.7.c1.fc22
Fedora 20 Security Update: drupal7-webform-4.6-1.fc20
Resolved Bugs
1205125 – drupal7-webform: drupal webform: multiple XSS flaws [fedora-all]
1193356 – drupal7-webform-4.3 is available
1205122 – drupal webform: multiple XSS flaws
1199067 – drupal7-webform-4.5 is available
1150458 – drupal7-webform-4.2 is available<br
– Security fix for drupal7-webform module
– Upstream release notes: https://www.drupal.org/node/2457219
– Release notes can be found at https://www.drupal.org/node/2454063
– Update to 4.3
– Release notes can be found at https://www.drupal.org/node/2427257
– Update to 4.2
– Release notes can be found at https://www.drupal.org/node/2381793