Category Archives: Fedora

Fedora – Security Updates

Fedora 19 Security Update: asterisk-11.14.2-1.fc19

Resolved Bugs
1173002 – asterisk: Remote Crash Vulnerability in WebSocket Server (AST-2014-019)
1173003 – asterisk: Remote Crash Vulnerability in WebSocket Server (AST-2014-019) [fedora-all]<br
The Asterisk Development Team has announced security releases for Certified
Asterisk 11.6 and Asterisk 11, 12, and 13. The available security releases are
released as versions 11.6-cert9, 11.14.2, 12.7.2, and 13.0.2.
These releases are available for immediate download at
http://downloads.asterisk.org/pub/telephony/asterisk/releases
The release of these versions resolves the following security vulnerability:
* AST-2014-019: Remote Crash Vulnerability in WebSocket Server
When handling a WebSocket frame the res_http_websocket module dynamically
changes the size of the memory used to allow the provided payload to fit. If a
payload length of zero was received the code would incorrectly attempt to
resize to zero. This operation would succeed and end up freeing the memory but
be treated as a failure. When the session was subsequently torn down this
memory would get freed yet again causing a crash.
For more information about the details of this vulnerability, please read
security advisory AST-2014-019, which was released at the same time as this
announcement.
For a full list of changes in the current releases, please see the ChangeLogs:
http://downloads.asterisk.org/pub/telephony/certified-asterisk/releases/ChangeLog-11.6-cert9
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-11.14.2
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-12.7.2
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-13.0.2
The security advisory is available at:
* http://downloads.asterisk.org/pub/security/AST-2014-019.pdf

Fedora 20 Security Update: docker-io-1.4.0-1.fc20

Resolved Bugs
1173324 – CVE-2014-9357 CVE-2014-9356 CVE-2014-9358 docker-io: various flaws [fedora-all]
1172782 – CVE-2014-9357 docker: Escalation of privileges during decompression of LZMA archives
1172761 – CVE-2014-9356 docker: Path traversal during processing of absolute symlinks
1172787 – CVE-2014-9358 docker: Path traversal and spoofing opportunities presented through image identifiers<br
Security fix for CVE-2014-9357, CVE-2014-9358, CVE-2014-9356

Fedora 19 Security Update: docker-io-1.4.0-1.fc19

Resolved Bugs
1173324 – CVE-2014-9357 CVE-2014-9356 CVE-2014-9358 docker-io: various flaws [fedora-all]
1172761 – CVE-2014-9356 docker: Path traversal during processing of absolute symlinks
1172782 – CVE-2014-9357 docker: Escalation of privileges during decompression of LZMA archives
1172787 – CVE-2014-9358 docker: Path traversal and spoofing opportunities presented through image identifiers
1167507 – CVE-2014-6408 CVE-2014-6407 docker-io: various flaws [fedora-all]
1167505 – CVE-2014-6407 docker: symbolic and hardlink issues leading to privilege escalation
1167506 – CVE-2014-6408 docker: potential container escalation<br
Security fix for CVE-2014-9357, CVE-2014-9358, CVE-2014-9356
Security fix for CVE-2014-6407, CVE-2014-6408