Resolved Bugs
1101056 – CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114
1101057 – CVE-2014-3152 v8: integer underflow fixed in Google Chrome 35.0.1916.114 [fedora-all]<br
Fix for ARM-only CVE-2014-3152
Monthly Archives: April 2015
jessie released – backports related changes
Dear users of the backports service! With the release of Jessie (coming up) we are pleased to open the doors for jessie-backports and wheezy-backports-sloppy (mostly all architectures are already buildable there, too). Whee! But, PLEASE DO READ ON, there are some changes in the process that we would like to do for the new upload pockets. == What to upload where == As a reminder, uploads to a release-backports pocket are to be taken from release + 1, uploads to a release-backports-sloppy pocket are to be taken from release + 2. Which means: Source Distribution | Backports Distribution | Sloppy Distribution ---------------------|------------------------|-------------------------- stretch | jessie-backports | wheezy-backports-sloppy jessie | wheezy-backports | squeeze-backports-sloppy == We drop -v switch hard requirement == We required uploads to contain the changelog entries since the former version in stable in the changes file. This was quite con
APPLE-SA-2015-04-24-1 OS X Server v4.1
From: Apple Product Security
Reply to list
APPLE-SA-2015-04-24-1 OS X Server v4.1 OS X Server v4.1 is now available and addresses the following: Dovecot Available for: OS X Yosemite v10.10 or later Impact: An attacker may be able to decrypt data protected by SSL Description: There are known attacks on the confidentiality of SSL 3. [...]
DSA-3237 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
DSA-3238 chromium-browser – security update
Several vulnerabilities were discovered in the chromium web browser.
Fedora EPEL 6 Security Update: python-crypto2.1-2.1.0-4.el6
Resolved Bugs
1206739 – Review Request: python-crypto2.1 – Cryptography library for Python<br
Add a patch to fix CVE-2012-2417
First EPEL6 release
Fedora EPEL 7 Security Update: mingw-openssl-1.0.2a-1.el7
Resolved Bugs
1203856 – CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [epel-7]<br
Update to OpenSSL 1.0.2a which fixes various CVE’s
Fedora EPEL 7 Security Update: mingw-libgcrypt-1.6.3-1.el7
Resolved Bugs
1198156 – CVE-2015-0837 CVE-2014-3591 mingw-libgcrypt: various flaws [epel-all]<br
Update to 1.6.3 which fixes CVE-2014-3591 and CVE-2015-0837
Fedora EPEL 7 Security Update: mingw-qt5-qtbase-5.4.1-2.el7
Fix CVE-2015-0295, CVE-2015-1858, CVE-2015-1859 and CVE-2015-1860
Fedora EPEL 7 Security Update: mingw-qt-4.8.6-8.el7
Fix CVE-2015-0295, CVE-2015-1858, CVE-2015-1859 and CVE-2015-1860