Resolved Bugs
1169700 – CVE-2014-9028 CVE-2014-8962 xmms-flac: various flaws [fedora-all]
1167236 – CVE-2014-8962 flac: Buffer read overflow when processing ID3V2 metadata
1167741 – CVE-2014-9028 flac: Heap buffer write overflow in read_residual_partitioned_rice_<br
Update flac to fix security issue in xmms-flac plugin (previously an independent subpackage that was out of date).
Monthly Archives: August 2015
Fedora 21 Security Update: gnutls-3.3.17-1.fc21
Fedora 22 Security Update: gnutls-3.3.17-1.fc22
Fedora 22 Security Update: flac-1.3.1-5.fc22
Resolved Bugs
1169700 – CVE-2014-9028 CVE-2014-8962 xmms-flac: various flaws [fedora-all]
1167236 – CVE-2014-8962 flac: Buffer read overflow when processing ID3V2 metadata
1167741 – CVE-2014-9028 flac: Heap buffer write overflow in read_residual_partitioned_rice_<br
Update flac to fix security issue in xmms-flac plugin (previously an independent subpackage that was out of date).
Fedora 21 Security Update: rubygems-2.2.5-100.fc21
Simple Packet Sender 4.3
Simple Packet Sender (SPS) is a Linux packet crafting tool. It supports IPv4, IPv6 (but not extension headers yet), and tunneling IPv6 over IPv4. Written in C on Linux with GUI built using GTK+. Both source and binaries are included. Features include packet crafting and sending one, multiple, or flooding packets of type TCP, ICMP, or UDP. All values within ethernet frame can be modified arbitrarily. Supports TCP, ICMP and UDP data as well, with input from either keyboard as UTF-8/ASCII, keyboard as hexadecimal, or from file. Various other features exist as well.
GNU Transport Layer Security Library 3.3.17.1
GnuTLS is a secure communications library implementing the SSL and TLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols, as well as APIs to parse and write X.509, PKCS #12, OpenPGP, and other required structures. It is intended to be portable and efficient with a focus on security and interoperability.
Maligno 2.4
Maligno is an open source penetration testing tool written in python, that serves Metasploit payloads. It generates shellcode with msfvenom and transmits it over HTTP or HTTPS. The shellcode is encrypted with AES and encoded with Base64 prior to transmission.
T Mobile Business Cross Site Scripting
T Mobile Business suffers from a client-side cross site scripting vulnerability.
Frog CMS 0.9.5 Open Redirect
Frog CMS version 0.9.5 suffers from an open redirection vulnerability.