Resolved Bugs
1184491 – CVE-2014-9637 patch: various flaws [fedora-all]
1185262 – CVE-2014-9637 patch: local denial of service with a crafted patch
1184490 – patch: directory traversal via file rename<br
Security fixes for CVE-2014-9637 and CVE-2015-1196.
Category Archives: Fedora
Fedora – Security Updates
Fedora 20 Security Update: community-mysql-5.5.41-1.fc20
Update to MySQL 5.5.41, for various fixes described at http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-41.html. This update also fixes security issues CVE-2015-0411, CVE-2015-0382, CVE-2015-0381, CVE-2015-0432, CVE-2014-6568, CVE-2015-0374.
Fedora 21 Security Update: puppetlabs-stdlib-4.5.1-1.20150121git7a91f20.fc21
Fedora 20 Security Update: jasper-1.900.1-28.fc20
Resolved Bugs
1184750 – CVE-2014-8157 CVE-2014-8158 jasper: various flaws [fedora-all]
1179282 – CVE-2014-8157 jasper: dec->numtiles off-by-one check in jpc_dec_process_sot() (oCERT-2015-001)
1179298 – CVE-2014-8158 jasper: unrestricted stack memory use in jpc_qmfb.c (oCERT-2015-001)<br
This update fixes two security flaws in jasper.
Fedora 20 Security Update: seamonkey-2.32-1.fc20
Resolved Bugs
1182009 – seamonkey-2.32 is available<br
Update to 2.32
Fixes various security issues, see http://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for more info.
Fedora 20 Security Update: rubygem-passenger-4.0.53-3.fc20
Resolved Bugs
1058993 – rubygem-passenger: insecure use of temporary files [fedora-20]<br
build for f20 (#1058993)
Fedora 20 Security Update: java-1.8.0-openjdk-1.8.0.31-1.b13.fc20
Update to January, 2015 Critical Patch Update (CPU). See:
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html#AppendixJAVA
Fedora 21 Security Update: patch-2.7.3-1.fc21
Fedora 21 Security Update: qpid-cpp-0.30-7.fc21
Fedora 20 Security Update: docker-io-1.4.1-6.fc20
Resolved Bugs
1180059 – SELinux is preventing /usr/bin/docker from ‘getattr’ accesses on the file /.docker/key.json.
1173324 – CVE-2014-9357 CVE-2014-9356 CVE-2014-9358 docker-io: various flaws [fedora-all]
1172761 – CVE-2014-9356 docker: Path traversal during processing of absolute symlinks
1172782 – CVE-2014-9357 docker: Escalation of privileges during decompression of LZMA archives
1172787 – CVE-2014-9358 docker: Path traversal and spoofing opportunities presented through image identifiers<br
run tests inside a docker repo
allow unitfile to use /etc/sysconfig/docker-network
Security fix for CVE-2014-9357, CVE-2014-9358, CVE-2014-9356