ALT-BU-2014-2644-1
Branch c7 update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2013-4160
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.
- [distro-pkg-dev] 20130708 [SECURITY] IcedTea 2.4.1 for OpenJDK 7 Released!
- [distro-pkg-dev] 20130708 [SECURITY] IcedTea 2.4.1 for OpenJDK 7 Released!
- [oss-security] 20130718 CVE Request: OpenJDK and lcms2 2.5 release fixes various denial of service issues in lcms2
- [oss-security] 20130718 CVE Request: OpenJDK and lcms2 2.5 release fixes various denial of service issues in lcms2
- [oss-security] 20130722 Re: CVE Request: OpenJDK and lcms2 2.5 release fixes various denial of service issues in lcms2
- [oss-security] 20130722 Re: CVE Request: OpenJDK and lcms2 2.5 release fixes various denial of service issues in lcms2
- USN-1911-1
- USN-1911-1
- https://bugzilla.novell.com/show_bug.cgi?id=826097#c9
- https://bugzilla.novell.com/show_bug.cgi?id=826097#c9
- https://github.com/mm2/Little-CMS/commit/91c2db7f2559be504211b283bc3a2c631d6f06d9
- https://github.com/mm2/Little-CMS/commit/91c2db7f2559be504211b283bc3a2c631d6f06d9
Package LibreOffice4 updated to version 4.1-alt8.M70P.1 for branch c7 in task 116435.
Closed bugs
Не запускается, если /tmp и /var/tmp недоступны
Прошу добавить оффлайн справку в LibreOffice
Не проигрывает звук, не вставляет видео
Closed bugs
Пересобрать с новым poppler
Closed bugs
Пересобрать с новым poppler
Package php5-gmagick updated to version 5.3.28.20131212-alt0.M70P.2 for branch c7 in task 116435.
Closed bugs
Новую версию PECL GMagick
Closed vulnerabilities
BDU:2015-09729
Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2013-1439
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
- DSA-2748
- DSA-2748
- [oss-security] 20130829 [notification] libraw: multiple denial of service vulnerabilities
- [oss-security] 20130829 [notification] libraw: multiple denial of service vulnerabilities
- https://github.com/LibRaw/LibRaw/commit/11909cc59e712e09b508dda729b99aeaac2b29ad
- https://github.com/LibRaw/LibRaw/commit/11909cc59e712e09b508dda729b99aeaac2b29ad
Modified: 2024-11-21
CVE-2013-2126
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.
- openSUSE-SU-2013:1083
- openSUSE-SU-2013:1083
- openSUSE-SU-2013:1085
- openSUSE-SU-2013:1085
- 53547
- 53547
- 53883
- 53883
- 53888
- 53888
- 53938
- 53938
- http://www.libraw.org/news/libraw-0-15-2
- http://www.libraw.org/news/libraw-0-15-2
- [oss-security] 20130529 Re: CVE request: libraw: multiple issues
- [oss-security] 20130529 Re: CVE request: libraw: multiple issues
- [oss-security] 20130610 Re: CVE request: libraw: multiple issues
- [oss-security] 20130610 Re: CVE request: libraw: multiple issues
- USN-1884-1
- USN-1884-1
- USN-1885-1
- USN-1885-1
- https://github.com/LibRaw/LibRaw/commit/19ffddb0fe1a4ffdb459b797ffcf7f490d28b5a6
- https://github.com/LibRaw/LibRaw/commit/19ffddb0fe1a4ffdb459b797ffcf7f490d28b5a6
Modified: 2024-11-21
CVE-2013-2127
Buffer overflow in the exposure correction code in LibRaw before 0.15.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
- 53547
- 53547
- http://www.libraw.org/news/libraw-0-15-1
- http://www.libraw.org/news/libraw-0-15-1
- [oss-security] 20130529 Re: CVE request: libraw: multiple issues
- [oss-security] 20130529 Re: CVE request: libraw: multiple issues
- https://github.com/LibRaw/LibRaw/commit/2f912f5b33582961b1cdbd9fd828589f8b78f21d
- https://github.com/LibRaw/LibRaw/commit/2f912f5b33582961b1cdbd9fd828589f8b78f21d
Closed bugs
Обновить до >= 0.15
Package kdegraphics updated to version 3.5.13.2-alt2.M70P.1 for branch c7 in task 116435.
Closed bugs
Пересобрать с новым poppler
Closed bugs
Диалог выбора комет работает не верно
Package xfce4-terminal updated to version 0.6.3-alt0.M70P.1 for branch c7 in task 116707.
Closed bugs
Падает при выборе Терминал->Установить кодировку
Package xorg-drv-synaptics updated to version 1.7.3-alt1 for branch c7 in task 116707.
Closed bugs
Исправить дефолтный конфиг
Closed vulnerabilities
Modified: 2024-11-21
CVE-2013-4173
Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitrary files via a .. (dot dot) in the host name in a "drophost" command.
- http://sourceforge.net/projects/xymon/files/Xymon/4.3.12/
- http://sourceforge.net/projects/xymon/files/Xymon/4.3.12/
- MDVSA-2013:213
- MDVSA-2013:213
- [oss-security] 20130727 Re: CVE Request: Xymon Systems and Network Monitor - remote file deletion vulnerability
- [oss-security] 20130727 Re: CVE Request: Xymon Systems and Network Monitor - remote file deletion vulnerability