RHSA-2015:1695-1: Important: jakarta-taglibs-standard security update

Red Hat Enterprise Linux: Updated jakarta-taglibs-standard packages that fix one security issue are
now available for Red Hat Enterprise Linux 6 and 7.

Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-0254

RHSA-2015:1694-1: Moderate: gdk-pixbuf2 security update

Red Hat Enterprise Linux: Updated gdk-pixbuf2 packages that fix one security issue are now available
for Red Hat Enterprise Linux 6 and 7.

Red Hat Product Security has rated this update as having Moderate security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-4491

CESA-2015:1694 Moderate CentOS 6 gdk-pixbuf2Security Update

CentOS Errata and Security Advisory 2015:1694 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1694.html

The following updated files have been uploaded and are currently 
syncing to the mirrors: ( sha256sum Filename ) 

i386:
07b16ceca0ae64ba2f21b9fb2e87ecd4aeecec4fc603ef8294f89afc66480bcd  gdk-pixbuf2-2.24.1-6.el6_7.i686.rpm
4c6e2434f5f74a7e3ea88790d33caa61dbbd2e3cfbf54936ed18d221c0e2876e  gdk-pixbuf2-devel-2.24.1-6.el6_7.i686.rpm

x86_64:
07b16ceca0ae64ba2f21b9fb2e87ecd4aeecec4fc603ef8294f89afc66480bcd  gdk-pixbuf2-2.24.1-6.el6_7.i686.rpm
248633f4471b62666822d4c5da72f8995d36e6cf2e9e61b6eff73993709b793f  gdk-pixbuf2-2.24.1-6.el6_7.x86_64.rpm
4c6e2434f5f74a7e3ea88790d33caa61dbbd2e3cfbf54936ed18d221c0e2876e  gdk-pixbuf2-devel-2.24.1-6.el6_7.i686.rpm
f6dcd9fee4829caf414074fd45e577a9f4334747b6b429462ab4d64e7ab51b5c  gdk-pixbuf2-devel-2.24.1-6.el6_7.x86_64.rpm

Source:
56cb617816f942b83c1693e0dce4572fb432b9f8d1433fda187e39e7b764bce9  gdk-pixbuf2-2.24.1-6.el6_7.src.rpm



CVE-2015-0943 (banking)

Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream.

CVE-2015-6742 (banking)

Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability types and different affected versions.