PonyOS versions 3.0 and below VFS privilege escalation exploit.
Monthly Archives: May 2015
Fedora 22 Security Update: kernel-4.0.4-303.fc22
Fedora 21 Security Update: httpd-2.4.12-1.fc21
Fedora 22 Security Update: ceph-deploy-1.5.25-1.fc22
Resolved Bugs
1224129 – CVE-2015-4053 ceph-deploy admin command copies keyring file to /etc/ceph which is world readable<br
Update to ceph-deploy 1.5.25 (CVE-2015-4053). See the [upstream changelog](http://ceph.com/ceph-deploy/docs/changelog.html) for more details.
Fedora 20 Security Update: fossil-1.33-1.fc20
Resolved Bugs
1191203 – fossil: version 1.30 is available with CVE-2014-3566 (POODLE) fixed<br
Update to latest release
Fedora 20 Security Update: nss-util-3.19.1-1.0.fc20,nss-3.19.1-1.0.fc20,nss-softokn-3.19.1-1.0.fc20
Resolved Bugs
1224448 – CVE-2015-4000 nss: LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks [fedora-all]
1214732 – nss-3.19.1 is available
1223211 – CVE-2015-4000 LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks<br
Security fix for CVE-2015-4000
Update to the upstream NSS 3.19.1 release, which includes a fix for the recently published logjam attack.
The previous 3.19 release made several notable changes related to the TLS protocol, one of them was to disable the SSL 3 protocol by default.
For the full list of changes in the 3.19 and 3.19.1 releases, please refer to the upstream release notes documents:
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.1_release_notes
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19_release_notes
Fedora 21 Security Update: kernel-4.0.4-202.fc21
Fedora 21 Security Update: fusionforge-5.3.2-4.fc21
CVE-2015-0850: Prevent arbitrary command execution via clone URL parameter of the method to create secondary Git repositories. Found by Ansgar Burchardt .
Fedora 21 Security Update: nss-3.19.1-1.0.fc21,nss-softokn-3.19.1-1.0.fc21,nss-util-3.19.1-1.0.fc21
Resolved Bugs
1224448 – CVE-2015-4000 nss: LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks [fedora-all]
1214732 – nss-3.19.1 is available
1223211 – CVE-2015-4000 LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks<br
Security fix for CVE-2015-4000
Update to the upstream NSS 3.19.1 release, which includes a fix for the recently published logjam attack.
The previous 3.19 release made several notable changes related to the TLS protocol, one of them was to disable the SSL 3 protocol by default.
For the full list of changes in the 3.19 and 3.19.1 releases, please refer to the upstream release notes documents:
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.1_release_notes
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19_release_notes
Fedora 21 Security Update: ceph-deploy-1.5.25-1.fc21
Resolved Bugs
1224129 – CVE-2015-4053 ceph-deploy admin command copies keyring file to /etc/ceph which is world readable<br
Update to ceph-deploy 1.5.25 (CVE-2015-4053). See the [upstream changelog](http://ceph.com/ceph-deploy/docs/changelog.html) for more details.