Red Hat Enterprise Linux: Updated OpenStack Block Storage packages that resolve various issues are
now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno)
for RHEL 7.
Monthly Archives: August 2015
RHBA-2015:1656-1: Satellite 5.7 bug fix update
RHN Satellite and Proxy: Updated cobbler, satellite-schema, spacewalk-java, spacewalk-reports,
spacewalk-schema and spacewalk-utils packages that fix several bugs and add
various enhancements are now available for Red Hat Satellite 5.7.
RHBA-2015:1655-1: lvm2 bug fix update
Red Hat Enterprise Linux: Updated lvm2 packages that fix two bugs are now available for Red Hat Enterprise
Linux 6.6 Extended Update Support.
RHBA-2015:1654-1: bash bug fix update
Red Hat Enterprise Linux: Updated bash packages that fix one bug are now available for Red Hat Enterprise
Linux 6.5 Extended Update Support.
RHBA-2015:1653-1: bash bug fix update
Red Hat Enterprise Linux: Updated bash packages that fix one bug are now available for Red Hat Enterprise
Linux 6.6 Extended Update Support.
RHBA-2015:1652-1: udev bug fix update
Red Hat Enterprise Linux: Updated udev packages that fix one bug are now available for Red Hat Enterprise
Linux 5.
CVE-2014-8628
Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted X.509 certificates. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2014-9744 for the ClientHello message issue.
CVE-2014-8987
Cross-site scripting (XSS) vulnerability in the “set configuration” box in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via the config_option parameter, a different vulnerability than CVE-2014-8986.
CVE-2014-9744
Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of ClientHello messages. NOTE: this identifier was SPLIT from CVE-2014-8628 per ADT3 due to different affected versions.
CVE-2014-3612
The LDAPLoginModule implementation the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.