ALT-BU-2016-2711-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2015-8864
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.
- openSUSE-SU-2016:2108
- openSUSE-SU-2016:2108
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2127
- openSUSE-SU-2016:2127
- https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18
- https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18
- https://github.com/roundcube/roundcubemail/issues/4949
- https://github.com/roundcube/roundcubemail/issues/4949
- https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
- https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
Modified: 2024-11-21
CVE-2016-4068
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
- openSUSE-SU-2016:2108
- openSUSE-SU-2016:2108
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2127
- openSUSE-SU-2016:2127
- https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18#commitcomment-15294218
- https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18#commitcomment-15294218
- https://github.com/roundcube/roundcubemail/issues/4949
- https://github.com/roundcube/roundcubemail/issues/4949
- https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
- https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
Modified: 2024-11-21
CVE-2016-4069
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2109
- [oss-security] 20160423 Re: CVE Request: Roundcube: XSS issue in SVG image handling and protection for download urs against CSRF
- [oss-security] 20160423 Re: CVE Request: Roundcube: XSS issue in SVG image handling and protection for download urs against CSRF
- 92654
- 92654
- https://github.com/roundcube/roundcubemail/commit/4a408843b0ef816daf70a472a02b78cd6073a4d5
- https://github.com/roundcube/roundcubemail/commit/4a408843b0ef816daf70a472a02b78cd6073a4d5
- https://github.com/roundcube/roundcubemail/commit/699af1e5206ed9114322adaa3c25c1c969640a53
- https://github.com/roundcube/roundcubemail/commit/699af1e5206ed9114322adaa3c25c1c969640a53
- https://github.com/roundcube/roundcubemail/issues/4957
- https://github.com/roundcube/roundcubemail/issues/4957
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
Closed bugs
Обновить версию
Closed bugs
Обновить до 3.12
Package NetworkManager updated to version 1.2.0-alt1 for branch sisyphus in task 163679.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2015-0272
GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.
- http://cgit.freedesktop.org/NetworkManager/NetworkManager/commit/?id=d5fc88e573fa58b93034b04d35a2454f5d28cad9
- http://cgit.freedesktop.org/NetworkManager/NetworkManager/commit/?id=d5fc88e573fa58b93034b04d35a2454f5d28cad9
- SUSE-SU-2015:2108
- SUSE-SU-2015:2108
- SUSE-SU-2015:2194
- SUSE-SU-2015:2194
- SUSE-SU-2015:2292
- SUSE-SU-2015:2292
- SUSE-SU-2015:2339
- SUSE-SU-2015:2339
- SUSE-SU-2015:2350
- SUSE-SU-2015:2350
- SUSE-SU-2016:0354
- SUSE-SU-2016:0354
- SUSE-SU-2016:2074
- SUSE-SU-2016:2074
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 76814
- 76814
- USN-2792-1
- USN-2792-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1192132
- https://bugzilla.redhat.com/show_bug.cgi?id=1192132
Closed bugs
удалите поддержку /lib/udev/devices
Closed vulnerabilities
BDU:2016-01034
Уязвимость программного средства для оптимизации PNG OptiPNG, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-01035
Уязвимость программного средства для оптимизации PNG OptiPNG, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2024-11-21
CVE-2015-7802
gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
Modified: 2024-11-21
CVE-2016-3981
Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file.
- http://bugs.fi/media/afl/optipng/1/
- http://bugs.fi/media/afl/optipng/1/
- openSUSE-SU-2016:1078
- openSUSE-SU-2016:1078
- openSUSE-SU-2016:1082
- openSUSE-SU-2016:1082
- DSA-3546
- DSA-3546
- USN-2951-1
- USN-2951-1
- GLSA-201608-01
- GLSA-201608-01
- https://sourceforge.net/p/optipng/bugs/56/
- https://sourceforge.net/p/optipng/bugs/56/
Modified: 2024-11-21
CVE-2016-3982
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, which triggers a heap-based buffer overflow.
- http://bugs.fi/media/afl/optipng/2/
- http://bugs.fi/media/afl/optipng/2/
- openSUSE-SU-2016:1078
- openSUSE-SU-2016:1078
- openSUSE-SU-2016:1082
- openSUSE-SU-2016:1082
- DSA-3546
- DSA-3546
- USN-2951-1
- USN-2951-1
- GLSA-201608-01
- GLSA-201608-01
- https://sourceforge.net/p/optipng/bugs/57/
- https://sourceforge.net/p/optipng/bugs/57/