Resolved Bugs
1178824 – CVE-2015-0556 CVE-2015-0557 arj: two directory traversal flaws
1207180 – CVE-2015-2782 arj: free on invalid pointer due to to buffer overflow
1196751 – arj: buffer overflow write access initiated by a size read from a crafted archive
1178827 – arj: two directory traversal flaws [epel-all]
1207182 – CVE-2015-2782 arj: free on invalid pointer due to to buffer overflow [epel-all]
1196752 – arj: buffer overflow write access initiated by a size read from a crafted archive [epel-all]<br
– Added patch from Debian to avoid free on invalid pointer due to a buffer overflow (#1196751, #1207180)
– Added patch from Debian for symlink directory traversal (#1178824)
– Added patch from Debian to fix the directory traversal via //multiple/leading/slash (#1178824)
Monthly Archives: April 2015
Fedora EPEL 7 Security Update: php-symfony-2.5.11-1.el7
Release notes:
* http://symfony.com/blog/symfony-2-5-9-released
* http://symfony.com/blog/symfony-2-5-10-released
* http://symfony.com/blog/symfony-2-5-11-released
Security fix in 2.5.11
* security #14167 CVE-2015-2308 (nicolas-grekas)
* security #14166 CVE-2015-2309 (neclimdul)
Fedora EPEL 5 Security Update: arj-3.10.22-22.el5
Resolved Bugs
1178827 – arj: two directory traversal flaws [epel-all]
1207182 – CVE-2015-2782 arj: free on invalid pointer due to to buffer overflow [epel-all]
1196752 – arj: buffer overflow write access initiated by a size read from a crafted archive [epel-all]
1178824 – CVE-2015-0556 CVE-2015-0557 arj: two directory traversal flaws
1207180 – CVE-2015-2782 arj: free on invalid pointer due to to buffer overflow
1196751 – arj: buffer overflow write access initiated by a size read from a crafted archive<br
– Added patch from Debian to avoid free on invalid pointer due to a buffer overflow (#1196751, #1207180)
– Added patch from Debian for symlink directory traversal (#1178824)
– Added patch from Debian to fix the directory traversal via //multiple/leading/slash (#1178824)
Fedora EPEL 6 Security Update: arj-3.10.22-22.el6
Resolved Bugs
1178827 – arj: two directory traversal flaws [epel-all]
1207182 – CVE-2015-2782 arj: free on invalid pointer due to to buffer overflow [epel-all]
1196752 – arj: buffer overflow write access initiated by a size read from a crafted archive [epel-all]
1178824 – CVE-2015-0556 CVE-2015-0557 arj: two directory traversal flaws
1207180 – CVE-2015-2782 arj: free on invalid pointer due to to buffer overflow
1196751 – arj: buffer overflow write access initiated by a size read from a crafted archive<br
– Added patch from Debian to avoid free on invalid pointer due to a buffer overflow (#1196751, #1207180)
– Added patch from Debian for symlink directory traversal (#1178824)
– Added patch from Debian to fix the directory traversal via //multiple/leading/slash (#1178824)
Fedora EPEL 7 Security Update: postgis-2.0.7-1.el7
Update to latest release, which includes security fixes.
Update to 2.1.6, per changes described at:
http://postgis.net/2015/03/20/postgis-2.1.6
enable json-c for postigs, but disable it for upgrade part
Rebuild for Proj 4.9.1
Fedora EPEL 6 Security Update: perl-DBD-Firebird-1.19-1.el6
Resolved Bugs
1207216 – perl-DBD-Firebird: buffer overflow in error messages handling in IB_SQLtimeformat()
1207218 – perl-DBD-Firebird: buffer overflow in error messages handling in IB_SQLtimeformat() [epel-all]<br
DBD::Firebird 1.19 [2015-03-22]
===============================
* Fix $VERSION in Firebird.pm
* Fix typo in ISC_PASSWORD spelling
* Positive logic and early return
* Allow re-executing/fetch on prepared sth [RT#92810, Tux]
* Add rests for $dbh->{Name} and others
* Implement $dbh->{Name}
* Fix attributions to Mike Pomraning
* use strict and warnings in all modules
* add a test for inserting/fetching float and double numbers as an attempt to reproduce RT#101650
* fix File::Which configure prerequisite declaration [RT#101672, dmn]
* 03-dbh-attr.t: plan tests after creating the TestFirebird object
* Buffer Overflow in dbdimp.c
* use snprintf instead of sprintf everywhere
CVE-2014-6221
The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 does not properly generate random numbers, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
CVE-2015-0117
The LDAP Server in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, aka SPR KLYH9SLRGM.
CVE-2015-0119
FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mount port.
CVE-2015-0134
Buffer overflow in the SSLv2 implementation in IBM Domino 8.5.x before 8.5.1 FP5 IF3, 8.5.2 before FP4 IF3, 8.5.3 before FP6 IF6, 9.0 before IF7, and 9.0.1 before FP2 IF3 allows remote attackers to execute arbitrary code via unspecified vectors.