Fedora 20 Security Update: icu-50.1.2-12.fc20

Resolved Bugs
1190131 – CVE-2014-7926 CVE-2014-9654 CVE-2014-7923 icu: various flaws [fedora-all]
1185202 – CVE-2014-7923 ICU: regexp engine missing look-behind expression range check
1185205 – CVE-2014-7926 ICU: regexp engine incorrect handling of a zero length quantifier
1190129 – CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler<br
Security fix for CVE-2014-9654, CVE-2014-7923, CVE-2014-7926

Fedora 21 Security Update: icu-52.1-6.fc21

Resolved Bugs
1190131 – CVE-2014-7926 CVE-2014-9654 CVE-2014-7923 icu: various flaws [fedora-all]
1185202 – CVE-2014-7923 ICU: regexp engine missing look-behind expression range check
1185205 – CVE-2014-7926 ICU: regexp engine incorrect handling of a zero length quantifier
1190129 – CVE-2014-9654 icu: insufficient size limit checks in regular expression compiler<br
Security fix for CVE-2014-9654, CVE-2014-7923, CVE-2014-7926

CVE-2015-0675

The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) does not properly validate failover communication messages, which allows remote attackers to reconfigure an ASA device, and consequently obtain administrative control, by sending crafted UDP packets over the local network to the failover interface, aka Bug ID CSCur21069.

CVE-2015-0676

The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 before 8.4(7.28), 8.5 before 8.5(1.24), 8.6 before 8.6(1.17), 8.7 before 8.7(1.16), 9.0 before 9.0(4.33), 9.1 before 9.1(6.1), 9.2 before 9.2(3.4), and 9.3 before 9.3(3) allows man-in-the-middle attackers to cause a denial of service (memory consumption or device outage) by triggering outbound DNS queries and then sending crafted responses to these queries, aka Bug ID CSCuq77655.

CVE-2015-0677

The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 before 9.0(4.33), 9.1 before 9.1(6), 9.2 before 9.2(3.4), and 9.3 before 9.3(3), when Clientless SSL VPN, AnyConnect SSL VPN, or AnyConnect IKEv2 VPN is used, allows remote attackers to cause a denial of service (VPN outage or device reload) via a crafted XML document, aka Bug ID CSCus95290.