Category Archives: Fedora

Fedora – Security Updates

Fedora 21 Security Update: kernel-3.18.2-200.fc21

Resolved Bugs
1181054 – CVE-2014-9585 kernel: ASLR bruteforce possible for vdso library
1181056 – CVE-2014-9585 kernel: ASLR bruteforce possible for vdso library [fedora-all]
1178975 – endless loop in clock_gettime() on a kvm-based VM
1124119 – usb 3.0 HDD SCSI UASP
1094948 – Backlight control doesn’t work on the Samsung N145P netbook
1115713 – backlight problem with Intel i915 integrated graphics adatper in N4xx/N5xx Atom after kernel 3.14.2
1163574 – Backlight control needs kernel param: video.use_native_backlight=0<br
The 3.18.2 kernel rebase contains several new features as well as several fixes across the tree.

Fedora 21 Security Update: python-django-1.6.10-1.fc21

Resolved Bugs
1181939 – CVE-2015-0219 python-django: Django: WSGI header spoofing via underscore/dash conflation [fedora-all]
1181946 – CVE-2015-0221 python-django: Django: denial of service attack against django.views.static.serve [fedora-all]
1179679 – CVE-2015-0221 Django: denial of service attack against django.views.static.serve
1179672 – CVE-2015-0219 Django: WSGI header spoofing via underscore/dash conflation
1179675 – CVE-2015-0220 Django: Mitigated possible XSS attack via user-supplied redirect URLs
1179685 – CVE-2015-0222 Django: database denial of service with ModelMultipleChoiceField
1181943 – CVE-2015-0220 python-django: Django: Mitigated possible XSS attack via user-supplied redirect URLs [fedora-all]
1181951 – CVE-2015-0222 python-django: Django: database denial of service with ModelMultipleChoiceField [fedora-all]<br
fix CVE-2015-0219 (rhbz#1181939)