Resolved Bugs
872390 – catdoc: buffer overflow flaw
872392 – catdoc: buffer overflow flaw [epel-all]<br
Fix buffer overflow vulnerability
Category Archives: Fedora
Fedora – Security Updates
Fedora EPEL 7 Security Update: davfs2-1.4.7-6.el7
Resolved Bugs
965511 – davfs2 package should be built with PIE flags<br
Add global harderning flags – RHBZ 965511
Fedora 21 Security Update: devscripts-2.14.8-1.fc21
Resolved Bugs
1059947 – CVE-2014-1833 devscripts: directory traversal flaw in uupdate
1059948 – devscripts: directory traversal flaw in uupdate [fedora-20]<br
Update to version 2.14.8, see http://metadata.ftp-master.debian.org/changelogs//main/d/devscripts/devscripts_2.14.8_changelog for details. Fixes CVE-2014-1833.
Fedora 20 Security Update: devscripts-2.14.8-1.fc20
Resolved Bugs
1059947 – CVE-2014-1833 devscripts: directory traversal flaw in uupdate
1059948 – devscripts: directory traversal flaw in uupdate [fedora-20]<br
Update to version 2.14.8, see http://metadata.ftp-master.debian.org/changelogs//main/d/devscripts/devscripts_2.14.8_changelog for details. Fixes CVE-2014-1833.
Fedora 20 Security Update: perl-Mojolicious-5.49-1.fc20
This version of Mojolicious fixes an assumption in CGI’s parameter handling that can result in parameter injection attacks.
Fedora 21 Security Update: perl-Mojolicious-5.49-1.fc21
This version of Mojolicious fixes an assumption in CGI’s parameter handling that can result in parameter injection attacks.
Fedora 19 Security Update: perl-Mojolicious-5.49-1.fc19
This version of Mojolicious fixes an assumption in CGI’s parameter handling that can result in parameter injection attacks.
Fedora 20 Security Update: facter-1.7.6-1.fc20
Resolved Bugs
1101346 – CVE-2014-3248 puppet: Ruby modules could be loaded from the current working directory
1114902 – CVE-2014-3248 facter: puppet: Ruby modules could be loaded from the current working directory [fedora-20]<br
Update to 1.7.6 for bz#1107891 and CVE-2014-3248
See http://puppetlabs.com/security/cve/cve-2014-3248 for more
information upstream.
Fedora 20 Security Update: gnome-shell-3.10.4-9.fc20
Fedora 19 Security Update: facter-1.6.18-5.fc19
Resolved Bugs
1101346 – CVE-2014-3248 puppet: Ruby modules could be loaded from the current working directory
1107891 – CVE-2014-3248 facter: puppet: Ruby modules could be loaded from the current working directory [fedora-19]<br
Patch facter 1.6 series for Bug 1107891 – CVE-2014-3248
See http://puppetlabs.com/security/cve/cve-2014-3248 for more
information from upstream.