ALT-BU-2016-2670-2
Branch sisyphus update bulletin.
Package libmatekbd updated to version 1.12.1-alt2_1 for branch sisyphus in task 162105.
Closed bugs
*.gir не в devel пакете
Package mate-menus updated to version 1.12.0-alt2_3 for branch sisyphus in task 162107.
Closed bugs
Зависимость на mate-menus
Package libgdk-pixbuf updated to version 2.34.0-alt1 for branch sisyphus in task 162032.
Closed vulnerabilities
Modified: 2025-04-12
CVE-2015-8875
Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image, which triggers a heap-based buffer overflow.
- http://www.debian.org/security/2016/dsa-3589
- http://www.openwall.com/lists/oss-security/2016/05/12/3
- http://www.openwall.com/lists/oss-security/2016/05/16/1
- http://www.openwall.com/lists/oss-security/2016/05/17/7
- http://www.ubuntu.com/usn/USN-3085-1
- https://git.gnome.org/browse/gdk-pixbuf/commit/?id=dbfe8f70471864818bf458a39c8a99640895bd22
- http://www.debian.org/security/2016/dsa-3589
- http://www.openwall.com/lists/oss-security/2016/05/12/3
- http://www.openwall.com/lists/oss-security/2016/05/16/1
- http://www.openwall.com/lists/oss-security/2016/05/17/7
- http://www.ubuntu.com/usn/USN-3085-1
- https://git.gnome.org/browse/gdk-pixbuf/commit/?id=dbfe8f70471864818bf458a39c8a99640895bd22
Package libwebkitgtk4 updated to version 2.12.0-alt1 for branch sisyphus in task 162032.
Closed vulnerabilities
Modified: 2021-03-23
BDU:2016-01450
Уязвимость операционной системы iOS и браузера Safari, позволяющая нарушителю получить конфиденциальную информацию
Modified: 2025-04-12
CVE-2016-1858
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.
- http://lists.apple.com/archives/security-announce/2016/May/msg00001.html
- http://lists.apple.com/archives/security-announce/2016/May/msg00002.html
- http://lists.apple.com/archives/security-announce/2016/May/msg00005.html
- http://packetstormsecurity.com/files/137229/WebKitGTK-Code-Execution-Denial-Of-Service-Memory-Corruption.html
- http://www.securityfocus.com/archive/1/538522/100/0/threaded
- http://www.securitytracker.com/id/1035888
- https://support.apple.com/HT206564
- https://support.apple.com/HT206565
- https://support.apple.com/HT206568
- http://lists.apple.com/archives/security-announce/2016/May/msg00001.html
- http://lists.apple.com/archives/security-announce/2016/May/msg00002.html
- http://lists.apple.com/archives/security-announce/2016/May/msg00005.html
- http://packetstormsecurity.com/files/137229/WebKitGTK-Code-Execution-Denial-Of-Service-Memory-Corruption.html
- http://www.securityfocus.com/archive/1/538522/100/0/threaded
- http://www.securitytracker.com/id/1035888
- https://support.apple.com/HT206564
- https://support.apple.com/HT206565
- https://support.apple.com/HT206568
Package openstack-nova updated to version 12.0.2-alt1 for branch sisyphus in task 162066.
Closed vulnerabilities
Modified: 2025-04-12
CVE-2015-7548
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.
Modified: 2025-04-12
CVE-2015-8749
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.
- http://www.openwall.com/lists/oss-security/2016/01/07/8
- http://www.openwall.com/lists/oss-security/2016/01/07/9
- http://www.securityfocus.com/bid/80189
- https://bugs.launchpad.net/nova/+bug/1516765
- https://security.openstack.org/ossa/OSSA-2016-002.html
- http://www.openwall.com/lists/oss-security/2016/01/07/8
- http://www.openwall.com/lists/oss-security/2016/01/07/9
- http://www.securityfocus.com/bid/80189
- https://bugs.launchpad.net/nova/+bug/1516765
- https://security.openstack.org/ossa/OSSA-2016-002.html
Modified: 2024-05-15
GHSA-c36r-g737-9qp8
OpenStack Nova Potential Xen connection password leak via StorageError
- https://nvd.nist.gov/vuln/detail/CVE-2015-8749
- https://github.com/openstack/nova/commit/8b289237ed6d53738c22878decf0c429301cf3d0
- https://github.com/openstack/nova/commit/b2acc9fa864b6fe10bc0c5f3786b976b472b1b27
- https://github.com/openstack/nova/commit/cf197ec2d682fb4da777df2291ca7ef101f73b77
- https://github.com/openstack/nova/commit/ef1ccdaca9512b88878155f7d8c2c77853d91252
- https://bugs.launchpad.net/nova/+bug/1516765
- https://github.com/openstack/nova
- https://security.openstack.org/ossa/OSSA-2016-002.html
- http://www.openwall.com/lists/oss-security/2016/01/07/8
- http://www.openwall.com/lists/oss-security/2016/01/07/9
- http://www.securityfocus.com/bid/80189
Package openstack-keystone updated to version 8.1.0-alt1 for branch sisyphus in task 162066.
Closed vulnerabilities
Modified: 2025-04-12
CVE-2015-7546
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/80498
- https://bugs.launchpad.net/keystone/+bug/1490804
- https://security.openstack.org/ossa/OSSA-2016-005.html
- https://wiki.openstack.org/wiki/OSSN/OSSN-0062
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/80498
- https://bugs.launchpad.net/keystone/+bug/1490804
- https://security.openstack.org/ossa/OSSA-2016-005.html
- https://wiki.openstack.org/wiki/OSSN/OSSN-0062
Modified: 2024-09-28
GHSA-8c4w-v65p-jvcv
OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
- https://nvd.nist.gov/vuln/detail/CVE-2015-7546
- https://github.com/openstack/keystone/commit/bff03b5726fe5cac93d44a66715eea49b89c8cb0
- https://github.com/openstack/keystone/commit/d5378f173da14a34ca010271477337879002d6d0
- https://github.com/openstack/keystonemiddleware/commit/96ab58e6863c92575ada57615b19652e502adfd8
- https://bugs.launchpad.net/keystone/+bug/1490804
- https://github.com/pypa/advisory-database/tree/main/vulns/keystonemiddleware/PYSEC-2016-20.yaml
- https://security.openstack.org/ossa/OSSA-2016-005.html
- https://web.archive.org/web/20200228002640/http://www.securityfocus.com/bid/80498
- https://wiki.openstack.org/wiki/OSSN/OSSN-0062
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
