redcarpet CVE-2015-5147 Stack Buffer Overflow Vulnerability
Monthly Archives: July 2015
Red Hat Security Advisory 2015-1513-01
Red Hat Security Advisory 2015-1513-01 – The Berkeley Internet Name Domain is an implementation of the Domain Name System protocols. BIND includes a DNS server ; a resolver library ; and tools for verifying that the DNS server is operating correctly. A flaw was found in the way BIND handled requests for TKEY DNS resource records. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS request packet.
Fedora 22 Security Update: libuser-0.62-1.fc22
Fedora 22 Security Update: bind99-9.9.7-6.P2.fc22
Fedora 22 Security Update: wordpress-4.2.3-1.fc22
Resolved Bugs
1246396 – CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in
1246398 – CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in [fedora-all]<br
**WordPress 4.2.3 Security and Maintenance Release**
WordPress 4.2.3 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately.
WordPress versions 4.2.2 and earlier are affected by a cross-site scripting vulnerability, which could allow users with the Contributor or Author role to compromise a site. This was initially reported by Jon Cave and fixed by Robert Chapin, both of the WordPress security team, and later reported by Jouko Pynnönen.
We also fixed an issue where it was possible for a user with Subscriber permissions to create a draft through Quick Draft. Reported by Netanel Rubin from Check Point Software Technologies.
Our thanks to those who have practiced responsible disclosure of security issues.
WordPress 4.2.3 also contains fixes for 20 bugs from 4.2. For more information, see:
* the release notes: https://codex.wordpress.org/Version_4.2.3
* the list of changes: https://core.trac.wordpress.org/log/branches/4.2?rev=33382&stop_rev=32430
Fedora 22 Security Update: openstack-swift-2.2.0-5.fc22
Resolved Bugs
1246358 – CVE-2015-1856 openstack-swift: OpenStack Swift: unauthorized deletion of versioned Swift object [fedora-all]<br
This update fixes CVE-2015-1856, unauthorized deletion of versioned Swift object.
Fedora 21 Security Update: lighttpd-1.4.36-1.fc21
Resolved Bugs
1224911 – CVE-2015-3200 lighttpd: log injection via malformed base64 string in Authentication header [epel-all]
1224910 – CVE-2015-3200 lighttpd: log injection via malformed base64 string in Authentication header [fedora-all]
1246857 – lighttpd-1.4.36 is available<br
Latest upstream security release:
http://www.lighttpd.net/2015/7/26/1.4.36/
Fedora 22 Security Update: lighttpd-1.4.36-1.fc22
Resolved Bugs
1224911 – CVE-2015-3200 lighttpd: log injection via malformed base64 string in Authentication header [epel-all]
1224910 – CVE-2015-3200 lighttpd: log injection via malformed base64 string in Authentication header [fedora-all]
1246857 – lighttpd-1.4.36 is available<br
Latest upstream security release:
http://www.lighttpd.net/2015/7/26/1.4.36/
Fedora 22 Security Update: openssh-6.9p1-4.fc22
Resolved Bugs
1247203 – openssh: scp can send arbitrary control characters / escape sequences to the terminal
1247204 – openssh: scp can send arbitrary control characters / escape sequences to the terminal [fedora-all]<br
Handle terminal control characters in scp progressmeter (#1247204) — Security fix
Fedora 21 Security Update: wordpress-4.2.3-1.fc21
Resolved Bugs
1246396 – CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in
1246398 – CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in [fedora-all]<br
**WordPress 4.2.3 Security and Maintenance Release**
WordPress 4.2.3 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately.
WordPress versions 4.2.2 and earlier are affected by a cross-site scripting vulnerability, which could allow users with the Contributor or Author role to compromise a site. This was initially reported by Jon Cave and fixed by Robert Chapin, both of the WordPress security team, and later reported by Jouko Pynnönen.
We also fixed an issue where it was possible for a user with Subscriber permissions to create a draft through Quick Draft. Reported by Netanel Rubin from Check Point Software Technologies.
Our thanks to those who have practiced responsible disclosure of security issues.
WordPress 4.2.3 also contains fixes for 20 bugs from 4.2. For more information, see:
* the release notes: https://codex.wordpress.org/Version_4.2.3
* the list of changes: https://core.trac.wordpress.org/log/branches/4.2?rev=33382&stop_rev=32430