Resolved Bugs
1155362 – CVE-2014-8326 phpmyadmin: cross-site scripting (XSS) flaw fixed in versions 4.0.10.5, 4.1.14.6, and 4.2.10.1 (PMASA-2014-12)
1155364 – CVE-2014-8326 phpmyadmin: cross-site scripting (XSS) flaw fixed in versions 4.0.10.5, 4.1.14.6, and 4.2.10.1 (PMASA-2014-12) [epel-5]
1155365 – CVE-2014-8326 phpMyAdmin4: phpmyadmin: cross-site scripting (XSS) flaw fixed in versions 4.0.10.5, 4.1.14.6, and 4.2.10.1 (PMASA-2014-12) [epel-5]<br
phpMyAdmin 4.0.10.5 (2014-10-21)
================================
– [security] XSS in debug SQL output
– [security] XSS in monitor query analyzer
Category Archives: Fedora
Fedora – Security Updates
Fedora EPEL 7 Security Update: konversation-1.5-7.el7
Fedora EPEL 7 Security Update: hostapd-2.3-1.el7
Resolved Bugs
1151259 – CVE-2014-3686 wpa_supplicant and hostapd: wpa_cli and hostapd_cli remote command execution issue
1151262 – CVE-2014-3686 wpa_supplicant and hostapd: wpa_cli and hostapd_cli remote command execution issue [epel-7]<br
Security fix for CVE-2014-3686. Update to version 2.3 from upstream.
Fedora EPEL 7 Security Update: konversation-1.5-6.el7
Fedora EPEL 6 Security Update: konversation-1.3.1-2.el6
Fedora EPEL 7 Security Update: Pound-2.7-0.4.d.el7.1
Resolved Bugs
1155982 – Pound POODLE exploit<br
Rebase to 2.7d. Notably allows disabling protocols known to be bad to prevent “POODLE” attack.
Fedora EPEL 6 Security Update: seamonkey-2.28-1.ESR_31.2.0.el6
Update to the codebase of Extended Support Release (ESR) 31.2.0
Fixes various security issues, see https://www.mozilla.org/security/known-vulnerabilities/firefoxESR.html and https://www.mozilla.org/security/known-vulnerabilities/thunderbird.html for more info
Fedora EPEL 6 Security Update: Pound-2.6-2.el6.1
Resolved Bugs
1154335 – Upgrade to latest 2.6 release of Pound<br
Backport various security fixes.
Note they usually are extra options that need
to be enabled manually so that we won’t break functionality:
– CVE-2011-3389: Make it possible to deny use of “BEAST” vulnerable ciphers
– CVE-2012-4929: Disable compression to be safe from “CRIME”
– CVE-2005-2090: Chunked encofing response splitting (no awkward name here)
– CVE-2014-3566: Allow disabling SSLv3 (and others), to be safe from “POODLE”
– A redirect XSS fix