John Heasman discovered that the site plugin handling of the
Elasticsearch search engine was susceptible to directory traversal.
Monthly Archives: April 2015
DSA-3239 icecast2 – security update
Juliane Holzt discovered that Icecast2, a streaming media server, could
dereference a NULL pointer when URL authentication is configured and the
stream_auth URL is trigged by a client without setting any credentials.
This could allow remote attackers to cause a denial of service (crash).
DSA-3240 curl – security update
It was discovered that cURL, an URL transfer library, if configured to
use a proxy server with the HTTPS protocol, by default could send to the
proxy the same HTTP headers it sends to the destination server, possibly
leaking sensitive information.
NIELD (Network Interface Events Logging Daemon) 0.6.1
Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the netlink socket and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules, and traffic control.
CVE-2015-1150
The Firewall component in Apple OS X Server before 4.1 uses an incorrect pathname in configuration files, which allows remote attackers to bypass network-access restrictions by sending packets for which custom-rule blocking was intended.
CVE-2015-1151
Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from an iPad client.
RHBA-2015:0905-1: rhevm-reports 3.5.1 bug fix update
Red Hat Enterprise Linux: An updated rhevm-reports package that fixes several bugs is now available.
RHBA-2015:0904-1: vdsm 3.5.1 – bug fix and enhancement update
Red Hat Enterprise Linux: Updated vdsm packages that fix several bugs and add various enhancements are now
available.
RHBA-2015:0903-1: ovirt-node bug fix and enhancement update for RHEV 3.5.1 with RHEL 7.1 support
Red Hat Enterprise Linux: An updated ovirt-node package that fixes various bugs and contains a number of
enhancements is now available.
RHBA-2015:0902-1: rhev-hypervisor bug fix and enhancement update for RHEV 3.5.1
Red Hat Enterprise Linux: Updated rhev-hypervisor packages that fix several bugs and add various
enhancements are now available.