Category Archives: Fedora

Fedora – Security Updates

Fedora EPEL 7 Security Update: thunderbird-31.2.0-1.el7

Resolved Bugs
1124601 – update thunderbird for EPEL7<br
Update to Thunderbird to latest upstream release, includes a number of bugfixes. Release Notes can be found here: https://www.mozilla.org/en-US/thunderbird/31.2.0/releasenotes/
Latest security update of Mozilla products. See list of changes here:
https://www.mozilla.org/en-US/firefox/32.0/releasenotes/
https://www.mozilla.org/en-US/thunderbird/31.1.0/releasenotes/

Fedora 19 Security Update: subscription-manager-1.13.6-1.fc19,python-rhsm-1.13.6-1.fc19

New features:
– Send list of compliance reasons on dbus
– Added client-side support for –matches on the list command.
Security:
– 1153375: Support TLSv1.2 and v1.1 by default. (CVE-2014-3566)
Bug fixes:
– 1120772: Don’t traceback on missing /ostree/repo
– 1094747: add appdata metdata file
– 1122107: Clarify registration –consumerid option in manpage.
– 1151925: Improved filtered listing output when results are empty.
– 990183: Add a manpage for rhsm.conf

Fedora 20 Security Update: subscription-manager-1.13.6-1.fc20,python-rhsm-1.13.6-1.fc20

New features:
– Send list of compliance reasons on dbus
– Added client-side support for –matches on the list command.
Security:
– 1153375: Support TLSv1.2 and v1.1 by default. (CVE-2014-3566)
Bug fixes:
– 1120772: Don’t traceback on missing /ostree/repo
– 1094747: add appdata metdata file
– 1122107: Clarify registration –consumerid option in manpage.
– 1151925: Improved filtered listing output when results are empty.
– 990183: Add a manpage for rhsm.conf

Fedora 20 Security Update: Pound-2.6-8.fc20

Backport various security fixes.
Note they usually are extra options that need
to be enabled manually so that we won’t break functionality:
– CVE-2011-3389: Make it possible to deny use of “BEAST” vulnerable ciphers
– CVE-2012-4929: Disable compression to be safe from “CRIME”
– CVE-2005-2090: Chunked encofing response splitting (no awkward name here)
– CVE-2014-3566: Allow disabling SSLv3 (and others), to be safe from “POODLE”
– A redirect XSS fix