Resolved Bugs
838162 – CVE-2012-3381 sblim-sfcb: insecure LD_LIBRARY_PATH usage [epel-5]<br
Fix insecure LD_LIBRARY_PATH usage.
Category Archives: Fedora
Fedora – Security Updates
Fedora 21 Security Update: python-requests-kerberos-0.6-1.fc21
Fedora 21 Security Update: slapi-nis-0.54.1-1.fc21,freeipa-4.1.1-1.fc21
Resolved Bugs
1157989 – ldapsearch does not find existing overrides for FreeIPA ID views when slapi-nis 0.54 is enabled<br
freeipa:
– Update to upstream 4.1.1
– see http://www.freeipa.org/page/Releases/4.1.1
– fix CVE-2014-7828
slapi-nis:
– support FreeIPA overrides in LDAP BIND callback
– ignore FreeIPA override searchs outside configured schema compat subtrees
Fedora 19 Security Update: curl-7.29.0-25.fc19
Resolved Bugs
1154941 – CVE-2014-3707 curl: incorrect handle duplication after COPYPOSTFIELDS<br
– fix handling of CURLOPT_COPYPOSTFIELDS in curl_easy_duphandle (CVE-2014-3707)
Fedora 20 Security Update: curl-7.32.0-15.fc20
Resolved Bugs
1154941 – CVE-2014-3707 curl: incorrect handle duplication after COPYPOSTFIELDS<br
– fix handling of CURLOPT_COPYPOSTFIELDS in curl_easy_duphandle (CVE-2014-3707)
Fedora 21 Security Update: fedup-0.9.0-2.fc21
Resolved Bugs
1159292 – Machine automatically shutdown during upgrade in less than 15 minutes
1038413 – fedup stage2 keymap will always be US again for F20-F21 due to anaconda not writing vconsole.keymap kernel parameter any more (#1035316)
1153816 – Fedup needs to support upgrading into a Productized Fedora 21
1066679 – CVE-2013-6494 fedup: /var/tmp/fedora-upgrade temporary directory creation vulnerability<br
This update works around a serious problem in Fedora 21 Beta which makes systems automatically shut down 15 minutes into the upgrade.
Other improvements:
* Adds `–product=PRODUCT` flag, required for upgrades to F21
* Uses host’s config files in `upgrade.img`, which should fix various upgrade problems (e.g. incorrect keyboard layout when unlocking disks due to missing `vconsole.conf`)
* Logging improvements: complete upgrade log should appear in system journal
Fedora 21 Security Update: curl-7.37.0-9.fc21
Resolved Bugs
1154941 – CVE-2014-3707 curl: incorrect handle duplication after COPYPOSTFIELDS<br
– fix handling of CURLOPT_COPYPOSTFIELDS in curl_easy_duphandle (CVE-2014-3707)
Fedora 21 Security Update: aircrack-ng-1.2-0.5rc1.fc21
Resolved Bugs
1159812 – CVE-2014-8321 CVE-2014-8322 CVE-2014-8323 CVE-2014-8324 aircrack-ng: multiple vulnerabilities
1159813 – CVE-2014-8324 CVE-2014-8321 CVE-2014-8323 CVE-2014-8322 aircrack-ng: multiple vulnerabilities [fedora-all]
984478 – aircrack-ng-1.2-rc1 is available<br
Security fix for CVE-2014-8321, CVE-2014-8322, CVE-2014-8323, CVE-2014-8324
Fedora 19 Security Update: python-2.7.5-15.fc19
Resolved Bugs
1113528 – CVE-2014-4650 python: CGIHTTPServer module does not properly handle URL-encoded path separators in URLs [fedora-all]<br
Fix for CVE-2014-4650: CGIHTTPServer module does not properly handle URL-encoded path separators in URLs.
Fedora 19 Security Update: fedup-0.9.0-2.fc19
Resolved Bugs
1159292 – Machine automatically shutdown during upgrade in less than 15 minutes
1038413 – fedup stage2 keymap will always be US again for F20-F21 due to anaconda not writing vconsole.keymap kernel parameter any more (#1035316)
1153816 – Fedup needs to support upgrading into a Productized Fedora 21
1066679 – CVE-2013-6494 fedup: /var/tmp/fedora-upgrade temporary directory creation vulnerability
1044987 – fedup-0.8.0-3.fc20.noarch exits if doulble ckicking on the window to max/min it
1045090 – [abrt] fedup: download.py:133:setup_repos:ValueError: need more than 1 value to unpack
1044083 – [abrt] fedup: commandline.py:197:device_setup:NameError: global name ‘message’ is not defined
1043981 – [abrt] fedup: fedup-cli:216:main:AttributeError: ‘ProblemSummary’ object has no attribute ‘format_details’
1047005 – [abrt] fedup: download.py:276:find_replacement:AttributeError: ‘NoneType’ object has no attribute ‘pkgtup'<br
This update works around a serious problem in Fedora 21 Beta which makes systems automatically shut down 15 minutes into the upgrade.
Other improvements:
* Adds `–product=PRODUCT` flag, required for upgrades to F21
* Uses host’s config files in `upgrade.img`, which should fix various upgrade problems (e.g. incorrect keyboard layout when unlocking disks due to missing `vconsole.conf`)
* Logging improvements: complete upgrade log should appear in system journal
* Adds a warning for upgrades without a new kernel
* Fixes a bunch of crashes