ALT-BU-2014-2568-1
Branch sisyphus update bulletin.
Package alterator-preinstall updated to version 0.7.2-alt1 for branch sisyphus in task 113498.
Closed bugs
При автоустановке происходит ошибка подмены alteratord
Closed bugs
Ошибка отработки триггера
Closed vulnerabilities
BDU:2015-04120
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2013-6393
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
- http://advisories.mageia.org/MGASA-2014-0040.html
- http://advisories.mageia.org/MGASA-2014-0040.html
- APPLE-SA-2014-04-22-1
- APPLE-SA-2014-04-22-1
- APPLE-SA-2014-10-16-3
- APPLE-SA-2014-10-16-3
- openSUSE-SU-2014:0272
- openSUSE-SU-2014:0272
- openSUSE-SU-2014:0273
- openSUSE-SU-2014:0273
- openSUSE-SU-2015:0319
- openSUSE-SU-2015:0319
- openSUSE-SU-2016:1067
- openSUSE-SU-2016:1067
- 102716
- 102716
- RHSA-2014:0353
- RHSA-2014:0353
- RHSA-2014:0354
- RHSA-2014:0354
- RHSA-2014:0355
- RHSA-2014:0355
- DSA-2850
- DSA-2850
- DSA-2870
- DSA-2870
- MDVSA-2015:060
- MDVSA-2015:060
- 65258
- 65258
- USN-2098-1
- USN-2098-1
- https://bitbucket.org/xi/libyaml/commits/tag/0.1.5
- https://bitbucket.org/xi/libyaml/commits/tag/0.1.5
- https://bugzilla.redhat.com/attachment.cgi?id=847926&action=diff
- https://bugzilla.redhat.com/attachment.cgi?id=847926&action=diff
- https://bugzilla.redhat.com/show_bug.cgi?id=1033990
- https://bugzilla.redhat.com/show_bug.cgi?id=1033990
- https://puppet.com/security/cve/cve-2013-6393
- https://puppet.com/security/cve/cve-2013-6393
- https://support.apple.com/kb/HT6536
- https://support.apple.com/kb/HT6536
Closed bugs
CVE-2013-6393 -- libyaml: heap-based buffer overflow when parsing YAML tags
Package fontconfig updated to version 2.11.0-alt3 for branch sisyphus in task 113641.
Closed bugs
Неудачные замены для шрифтов
Closed bugs
Multiple security vulnerabilities
Closed vulnerabilities
Modified: 2013-12-16
CVE-2012-5394
Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to hijack the authentication of users for requests that login via vectors involving image loading.
Modified: 2024-11-21
CVE-2013-4567
Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a \b (backspace) character in CSS.
- FEDORA-2013-21874
- FEDORA-2013-21874
- FEDORA-2013-21856
- FEDORA-2013-21856
- [MediaWiki-announce] 20131114 MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9
- [MediaWiki-announce] 20131114 MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9
- 57472
- 57472
- DSA-2891
- DSA-2891
- 63760
- 63760
- https://bugzilla.wikimedia.org/show_bug.cgi?id=55332
- https://bugzilla.wikimedia.org/show_bug.cgi?id=55332
Modified: 2024-11-21
CVE-2013-4568
Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain non-ASCII characters in CSS, as demonstrated using variations of "expression" containing (1) full width characters or (2) IPA extensions, which are converted and rendered by Internet Explorer.
- FEDORA-2013-21874
- FEDORA-2013-21874
- FEDORA-2013-21856
- FEDORA-2013-21856
- [MediaWiki-announce] 20131114 MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9
- [MediaWiki-announce] 20131114 MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9
- 57472
- 57472
- DSA-2891
- DSA-2891
- 63761
- 63761
- https://bugzilla.wikimedia.org/attachment.cgi?id=13452&action=diff
- https://bugzilla.wikimedia.org/attachment.cgi?id=13452&action=diff
- https://bugzilla.wikimedia.org/show_bug.cgi?id=55332
- https://bugzilla.wikimedia.org/show_bug.cgi?id=55332
Modified: 2024-11-21
CVE-2013-4569
The CleanChanges extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3, when "Group changes by page in recent changes and watchlist" is enabled, allows remote attackers to obtain sensitive information (revision-deleted IPs) via the Recent Changes page.
- FEDORA-2013-21874
- FEDORA-2013-21874
- FEDORA-2013-21856
- FEDORA-2013-21856
- [MediaWiki-announce] 20131114 MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9
- [MediaWiki-announce] 20131114 MediaWiki Security Release: 1.21.3, 1.20.8 and 1.19.9
- https://bugzilla.wikimedia.org/show_bug.cgi?id=54294
- https://bugzilla.wikimedia.org/show_bug.cgi?id=54294
Modified: 2024-11-21
CVE-2013-4570
The zend_inline_hash_func function in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to converting Lua data structures to PHP, as demonstrated by passing { [{}] = 1 } to a module function.
Modified: 2024-11-21
CVE-2013-4571
Buffer overflow in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 has unspecified impact and remote vectors.
Modified: 2024-11-21
CVE-2013-4572
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/122998.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/122998.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123011.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123011.html
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-November/000135.html
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-November/000135.html
- https://bugzilla.wikimedia.org/show_bug.cgi?id=53032
- https://bugzilla.wikimedia.org/show_bug.cgi?id=53032
Modified: 2024-11-21
CVE-2013-4573
Cross-site scripting (XSS) vulnerability in the ZeroRatedMobileAccess extension for MediaWiki 1.19.x before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to inject arbitrary web script or HTML via the "to" parameter to index.php.
Modified: 2024-11-21
CVE-2013-4574
Cross-site scripting (XSS) vulnerability in the TimeMediaHandler extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to videos.
Modified: 2024-11-21
CVE-2013-6451
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.
Modified: 2024-11-21
CVE-2013-6452
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via crafted XSL in an SVG file.
Modified: 2024-11-21
CVE-2013-6453
MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.
Modified: 2024-11-21
CVE-2013-6454
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via a -o-link attribute.
Modified: 2024-11-21
CVE-2013-6455
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.
Modified: 2024-11-21
CVE-2013-6472
MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain information about deleted page via the (1) log API, (2) enhanced RecentChanges, and (3) user watchlists.
Modified: 2024-11-21
CVE-2013-7444
The Special:Contributions page in MediaWiki before 1.22.0 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.
- FEDORA-2015-13920
- FEDORA-2015-13920
- [oss-security] 20150812 CVE Request: MediaWiki 1.25.2, 1.24.3, 1.23.10
- [oss-security] 20150812 CVE Request: MediaWiki 1.25.2, 1.24.3, 1.23.10
- [oss-security] 20150827 Re: CVE Request: MediaWiki 1.25.2, 1.24.3, 1.23.10
- [oss-security] 20150827 Re: CVE Request: MediaWiki 1.25.2, 1.24.3, 1.23.10
- https://github.com/wikimedia/mediawiki/commit/dc2966bd05b69321300c63fd0bd78e7c78ecea6e
- https://github.com/wikimedia/mediawiki/commit/dc2966bd05b69321300c63fd0bd78e7c78ecea6e
- [MediaWiki-announce] 20150810 MediaWiki Security and Maintenance Releases: 1.25.2, 1.24.3, 1.23.10
- [MediaWiki-announce] 20150810 MediaWiki Security and Maintenance Releases: 1.25.2, 1.24.3, 1.23.10
- https://phabricator.wikimedia.org/T48457
- https://phabricator.wikimedia.org/T48457
Modified: 2024-11-21
CVE-2014-1610
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.
- FEDORA-2014-1802
- FEDORA-2014-1802
- FEDORA-2014-1745
- FEDORA-2014-1745
- [MediaWiki-announce] 20140128 MediaWiki Security Releases: 1.22.2, 1.21.5 and 1.19.11
- [MediaWiki-announce] 20140128 MediaWiki Security Releases: 1.22.2, 1.21.5 and 1.19.11
- 102630
- 102630
- 56695
- 56695
- 57472
- 57472
- http://www.checkpoint.com/defense/advisories/public/2014/cpai-26-jan.html
- http://www.checkpoint.com/defense/advisories/public/2014/cpai-26-jan.html
- http://www.checkpoint.com/threatcloud-central/articles/2014-01-28-tc-researchers-discover.html
- http://www.checkpoint.com/threatcloud-central/articles/2014-01-28-tc-researchers-discover.html
- DSA-2891
- DSA-2891
- 31329
- 31329
- 102631
- 102631
- 65223
- 65223
- 1029707
- 1029707
- https://bugzilla.wikimedia.org/attachment.cgi?id=14361&action=diff
- https://bugzilla.wikimedia.org/attachment.cgi?id=14361&action=diff
- https://bugzilla.wikimedia.org/attachment.cgi?id=14384&action=diff
- https://bugzilla.wikimedia.org/attachment.cgi?id=14384&action=diff
- https://bugzilla.wikimedia.org/show_bug.cgi?id=60339
- https://bugzilla.wikimedia.org/show_bug.cgi?id=60339
- https://gerrit.wikimedia.org/r/#/c/110069/
- https://gerrit.wikimedia.org/r/#/c/110069/
- https://gerrit.wikimedia.org/r/#/c/110069/2/includes/media/Bitmap.php
- https://gerrit.wikimedia.org/r/#/c/110069/2/includes/media/Bitmap.php
- https://gerrit.wikimedia.org/r/#/c/110215/
- https://gerrit.wikimedia.org/r/#/c/110215/
Modified: 2024-11-21
CVE-2014-3454
Cross-site request forgery (CSRF) vulnerability in Special:CreateCategory in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to hijack the authentication of users for requests that create categories via unspecified vectors.
Modified: 2024-11-21
CVE-2014-3455
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) CreateProperty, (2) CreateTemplate, (3) CreateForm, and (4) CreateClass special pages in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allow remote attackers to hijack the authentication of users for requests that have unspecified impact and vectors.