ALT-BU-2014-2959-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2015-7747
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170387.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170387.html
- http://www.openwall.com/lists/oss-security/2015/10/06/2
- http://www.openwall.com/lists/oss-security/2015/10/06/2
- http://www.ubuntu.com/usn/USN-2787-1
- http://www.ubuntu.com/usn/USN-2787-1
- https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1502721
- https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1502721
- https://github.com/ccrisan/motioneyeos/blob/master/package/audiofile/0008-CVE-2015-7747.patch
- https://github.com/ccrisan/motioneyeos/blob/master/package/audiofile/0008-CVE-2015-7747.patch
- https://www.openwall.com/lists/oss-security/2015/10/08/1
- https://www.openwall.com/lists/oss-security/2015/10/08/1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2014-2553
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to dynamic fields.
Modified: 2024-11-21
CVE-2014-2554
OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2013-2292
bitcoind and Bitcoin-Qt 0.8.0 and earlier allow remote attackers to cause a denial of service (electricity consumption) by mining a block to create a nonstandard Bitcoin transaction containing multiple OP_CHECKSIG script opcodes.
Modified: 2024-11-21
CVE-2013-2293
The CTransaction::FetchInputs method in bitcoind and Bitcoin-Qt before 0.8.0rc1 copies transactions from disk to memory without incrementally checking for spent prevouts, which allows remote attackers to cause a denial of service (disk I/O consumption) via a Bitcoin transaction with many inputs corresponding to many different parts of the stored block chain.
Closed bugs
Пересобрать
Closed bugs
file /usr/share/java/junit.jar from install of junit4-4.11-alt1_1jpp7 conflicts with file from package junit-3.8.2-alt7_10jpp6