Resolved Bugs
1238619 – CVE-2015-1793 openssl: alternative chains certificate forgery
1241544 – CVE-2015-1793 openssl: alternative chains certificate forgery [fedora-all]<br
Security fix for CVE-2015-1793 high severity issue.
Monthly Archives: July 2015
Hacking Team Promises to Rebuild Controversial Surveillance Software
Hacking Team promised to rebuild its controversial surveillance software while two more Adobe Flash Player zero day vulnerabilities were uncovered.
Fedora 21 Security Update: elfutils-0.163-1.fc21
Resolved Bugs
1232206 – sizeof – kernel core/modules x 10
1231454 – Updated Polish translation
1230798 – run-elflint-self test failure with 0.162 with –enable-gcov
1170810 – Fuzzing elfutils — various badness
1139815 – Ukrainian translation update
1129756 – Unwinding core fails in vDSO frame when elf_begin is called with ELF_C_READ
1020842 – libelf: segment fault on x86-64 while file’s bss offset have a large number
1230468 – BuildRequires on glibc-devel not glibc-headers.<br
Update to 0.163. Hardening fixes. Updated eu-addr2line utility. Various bug fixes. Updated translations.
Fedora 22 Security Update: firefox-39.0-8.fc22
New upstream – Firefox 39.0
Fedora 22 Security Update: webkitgtk4-2.8.4-2.fc22
Resolved Bugs
1225733 – [abrt] [faf] webkitgtk4: bmalloc::Heap::allocateXLarge(std::lock_guard&, unsigned int, unsigned int)(): /usr/libexec/webkit2gtk-4.0/WebKitWebProcess killed by 11<br
WebKitGTK+ 2.8.4 includes fixes for 12 security issues. Additional fixes:
* Make WebSQL work by using a default quota instead of always failing in openDatabase with DOM Exception 18.
* Improve detection and usage of GL/GLES/EGL libraries.
* Fix a crash on memory allocation using bmalloc on 32bit systems.
* Fix DOCUMENT_VIEWER cache model to actually disable the memory cache.
* Fix a WebProcess crash after too many redirect error when there’s an active NPAPI plugin.
* Fix a WebProcess crash when gtk-font-name setting is empty.
* Ensure Math.abs() doesn’t return negative.
* Correctly restore accelerated compositing after a WebProcess crash.
* Respect X-Frame-Options headers when loading from application cache.
* Several crashes and rendering issues fixed.
* Fix the MIPS N64 detection.
* Fix several memory leaks.
* Translation updates: Catalan.
* Workaround a crash affecting 32-bit computers.
Fedora 21 Security Update: nx-libs-3.5.0.32-1.fc21
Update to nx-libs 3.5.0.32:
– Proper integration of all patches in the source tarballs. Bugs in the tarball generation script and patch file names prohibited inclusion of many patches previously, including security fixes.
– Better support for debug (DEBUG, TEST, TRACE and other directives) builds, in part thanks to Nito Martinez.
– Build fixes due to underlinking of libdl thanks to Bernard Cafarelli.
– Retroactively document correct GPLv2 licensing of previously potentially offending DXPC code.
– Help text fixups.
– Restart reading if interrupted, gets rid of “Negotiation in stage 10” errors thanks to Vadim Troshchinskiy.
– A dozen X.Org Server fixes backported by Ulrich Sibiller.
The X2Go Project thanks Bernard Cafarelli, Nito Martinez (Qindel Group), Vadim Troshchinskiy (Qindel Group) and Ulrich Sibiller for their contributions.
Fedora 22 Security Update: hostapd-2.4-3.fc22
CVE-2015-1438 – Arbitrary Code Execution [PSKMAD.sys] In Panda Security – Multiple Products
Posted by Portcullis Advisories on Jul 13
Vulnerability title: Arbitrary Code Execution [PSKMAD.sys] In Panda Security – Multiple Products
CVE: CVE-2015-1438
Vendor: Panda Security
Product: Multiple Products
Affected version: 1.0.0.13
Fixed version: 15.1.0
Reported by: Kyriakos Economou
Details:
Panda Kernel Memory Access Driver doesn’t validate the size of data to be copied to both an allocated kernel paged pool
buffer and to an allocated non-paged pool buffer. Furthermore, the…
CVE-2015-3449 – Weak File Permissions In SAP Afaria XeService.exe
Posted by Portcullis Advisories on Jul 13
Vulnerability title: Weak File Permissions In SAP Afaria XeService.exe
CVE: CVE-2015-3449
Vendor: SAP
Product: Afaria XeService.exe
Affected version: 7.0.6398.0
Fixed version: Latest
Reported by: Russ Spooner
Details:
It was identified that the Afaria Windows client software was installed with weak default permissions that granted read
and write permissions to the Everyone group to the install folder.
Further details at:…
CVE-2015-3621 – Privilege Escalation In SAP ECC
Posted by Portcullis Advisories on Jul 13
Vulnerability title: Privilege Escalation In SAP ECC
CVE: CVE-2015-3621
Vendor: SAP
Product: ECC
Affected version: Unknown
Fixed version: Latest
Reported by: Tim Brown
Details:
It has been identified that binaries that are executed with elevated privileges (SetGID and SetUID programs) have been
compiled in manner that means they searched for libraries in insecure locations.
Further details at:…