ALT-BU-2014-2976-1
Branch t7 update bulletin.
Package alterator-fbi updated to version 5.30-alt0.M70P.1 for branch t7 in task 129339.
Closed bugs
Недостаточно правильно осуществляется подстановка %H в X-Alterator-URI
Closed vulnerabilities
Modified: 2024-11-21
CVE-2013-2292
bitcoind and Bitcoin-Qt 0.8.0 and earlier allow remote attackers to cause a denial of service (electricity consumption) by mining a block to create a nonstandard Bitcoin transaction containing multiple OP_CHECKSIG script opcodes.
Modified: 2024-11-21
CVE-2013-2293
The CTransaction::FetchInputs method in bitcoind and Bitcoin-Qt before 0.8.0rc1 copies transactions from disk to memory without incrementally checking for spent prevouts, which allows remote attackers to cause a denial of service (disk I/O consumption) via a Bitcoin transaction with many inputs corresponding to many different parts of the stored block chain.
Closed bugs
собрать свежую версию для P7
Package phpMyAdmin updated to version 4.2.8-alt1 for branch t7 in task 129339.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2014-4349
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
- openSUSE-SU-2014:1069
- openSUSE-SU-2014:1069
- http://phpmyadmin.net/home_page/security/PMASA-2014-3.php
- http://phpmyadmin.net/home_page/security/PMASA-2014-3.php
- 60397
- 60397
- 68205
- 68205
- https://github.com/phpmyadmin/phpmyadmin/commit/d4f754c937f9e2c0beadff5b2e38215dde1d6a79
- https://github.com/phpmyadmin/phpmyadmin/commit/d4f754c937f9e2c0beadff5b2e38215dde1d6a79
- https://github.com/phpmyadmin/phpmyadmin/commit/daa98d0c7ed24b529dc5df0d5905873acd0b00be
- https://github.com/phpmyadmin/phpmyadmin/commit/daa98d0c7ed24b529dc5df0d5905873acd0b00be
Modified: 2024-11-21
CVE-2014-4955
Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.
- openSUSE-SU-2014:1069
- openSUSE-SU-2014:1069
- 60397
- 60397
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-5.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-5.php
- 68799
- 68799
- https://github.com/phpmyadmin/phpmyadmin/commit/10014d4dc596b9e3a491bf04f3e708cf1887d5e1
- https://github.com/phpmyadmin/phpmyadmin/commit/10014d4dc596b9e3a491bf04f3e708cf1887d5e1
Modified: 2024-11-21
CVE-2014-4986
Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) table name or (2) column name that is improperly handled during construction of an AJAX confirmation message.
- openSUSE-SU-2014:1069
- openSUSE-SU-2014:1069
- 60397
- 60397
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-6.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-6.php
- 68803
- 68803
- https://github.com/phpmyadmin/phpmyadmin/commit/29a1f56495a7d1d98da31a614f23c0819a606a4d
- https://github.com/phpmyadmin/phpmyadmin/commit/29a1f56495a7d1d98da31a614f23c0819a606a4d
- GLSA-201505-03
- GLSA-201505-03
Modified: 2024-11-21
CVE-2014-4987
server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.
- openSUSE-SU-2014:1069
- openSUSE-SU-2014:1069
- 60397
- 60397
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-7.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-7.php
- 68804
- 68804
- https://github.com/phpmyadmin/phpmyadmin/commit/395265e9937beb21134626c01a21f44b28e712e5
- https://github.com/phpmyadmin/phpmyadmin/commit/395265e9937beb21134626c01a21f44b28e712e5
- GLSA-201505-03
- GLSA-201505-03
Modified: 2024-11-21
CVE-2014-5273
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.
- openSUSE-SU-2014:1069
- openSUSE-SU-2014:1069
- 60397
- 60397
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-8.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-8.php
- https://github.com/phpmyadmin/phpmyadmin/commit/2c45d7caa614afd71dbe3d0f7270f51ce5569614
- https://github.com/phpmyadmin/phpmyadmin/commit/2c45d7caa614afd71dbe3d0f7270f51ce5569614
- https://github.com/phpmyadmin/phpmyadmin/commit/3ffc967fb60cf2910cc2f571017e977558c67821
- https://github.com/phpmyadmin/phpmyadmin/commit/3ffc967fb60cf2910cc2f571017e977558c67821
- https://github.com/phpmyadmin/phpmyadmin/commit/647c9d12e33a6b64e1c3ff7487f72696bdf2dccb
- https://github.com/phpmyadmin/phpmyadmin/commit/647c9d12e33a6b64e1c3ff7487f72696bdf2dccb
- https://github.com/phpmyadmin/phpmyadmin/commit/90ddeecf60fc029608b972e490b735f3a65ed0cb
- https://github.com/phpmyadmin/phpmyadmin/commit/90ddeecf60fc029608b972e490b735f3a65ed0cb
- https://github.com/phpmyadmin/phpmyadmin/commit/cd9f302bf7f91a160fe7080f9a612019ef847f1c
- https://github.com/phpmyadmin/phpmyadmin/commit/cd9f302bf7f91a160fe7080f9a612019ef847f1c
Modified: 2024-11-21
CVE-2014-5274
Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.
- openSUSE-SU-2014:1069
- openSUSE-SU-2014:1069
- 60397
- 60397
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-9.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-9.php
- https://github.com/phpmyadmin/phpmyadmin/commit/0cd293f5e13aa245e4a57b8d373597cc0e421b6f
- https://github.com/phpmyadmin/phpmyadmin/commit/0cd293f5e13aa245e4a57b8d373597cc0e421b6f
Package python-module-django-horizon updated to version 2014.1.2-alt2 for branch t7 in task 129339.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2014-3594
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.
- openSUSE-SU-2015:0078
- openSUSE-SU-2015:0078
- RHSA-2014:1335
- RHSA-2014:1335
- RHSA-2014:1336
- RHSA-2014:1336
- [oss-security] 20140819 [OSSA 2014-027] Persistent XSS in Horizon Host Aggregates interface (CVE-2014-3594)
- [oss-security] 20140819 [OSSA 2014-027] Persistent XSS in Horizon Host Aggregates interface (CVE-2014-3594)
- 69291
- 69291
- https://bugs.launchpad.net/horizon/+bug/1349491
- https://bugs.launchpad.net/horizon/+bug/1349491
- openstack-horizon-cve20143594-xss(95378)
- openstack-horizon-cve20143594-xss(95378)
- https://review.openstack.org/#/c/115310
- https://review.openstack.org/#/c/115310
- https://review.openstack.org/#/c/115311
- https://review.openstack.org/#/c/115311
- https://review.openstack.org/#/c/115313/
- https://review.openstack.org/#/c/115313/
Package thunderbird-lightning-ru updated to version 3.3-alt1 for branch t7 in task 129339.
Closed bugs
Дополнение Lightning для Thunderbird не работает после обновления Thunderbird.
Package coolreader3 updated to version 3.0.56-alt1.M70T.1 for branch t7 in task 129406.
Closed bugs
Не сохраняются настройки