ALT-BU-2016-2717-1
Branch p8 update bulletin.
Closed bugs
удалите поддержку /lib/udev/devices
Closed vulnerabilities
Modified: 2024-11-21
CVE-2015-8864
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.
- openSUSE-SU-2016:2108
- openSUSE-SU-2016:2108
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2127
- openSUSE-SU-2016:2127
- https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18
- https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18
- https://github.com/roundcube/roundcubemail/issues/4949
- https://github.com/roundcube/roundcubemail/issues/4949
- https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
- https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
Modified: 2024-11-21
CVE-2016-4068
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
- openSUSE-SU-2016:2108
- openSUSE-SU-2016:2108
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2127
- openSUSE-SU-2016:2127
- https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18#commitcomment-15294218
- https://github.com/roundcube/roundcubemail/commit/40d7342dd9c9bd2a1d613edc848ed95a4d71aa18#commitcomment-15294218
- https://github.com/roundcube/roundcubemail/issues/4949
- https://github.com/roundcube/roundcubemail/issues/4949
- https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
- https://github.com/roundcube/roundcubemail/releases/tag/1.0.9
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
Modified: 2024-11-21
CVE-2016-4069
Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.
- openSUSE-SU-2016:2109
- openSUSE-SU-2016:2109
- [oss-security] 20160423 Re: CVE Request: Roundcube: XSS issue in SVG image handling and protection for download urs against CSRF
- [oss-security] 20160423 Re: CVE Request: Roundcube: XSS issue in SVG image handling and protection for download urs against CSRF
- 92654
- 92654
- https://github.com/roundcube/roundcubemail/commit/4a408843b0ef816daf70a472a02b78cd6073a4d5
- https://github.com/roundcube/roundcubemail/commit/4a408843b0ef816daf70a472a02b78cd6073a4d5
- https://github.com/roundcube/roundcubemail/commit/699af1e5206ed9114322adaa3c25c1c969640a53
- https://github.com/roundcube/roundcubemail/commit/699af1e5206ed9114322adaa3c25c1c969640a53
- https://github.com/roundcube/roundcubemail/issues/4957
- https://github.com/roundcube/roundcubemail/issues/4957
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/releases/tag/1.1.5
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
- https://github.com/roundcube/roundcubemail/wiki/Changelog#release-115
Package clementine updated to version 1.3.1-alt1 for branch p8 in task 163772.
Closed bugs
clementine не запускается в Сизифе
Package update-kernel updated to version 0.9.9-alt1 for branch p8 in task 163779.
Closed bugs
remove-old-kernels удаляет файлы другого флавора
Package qt5-phonon updated to version 4.8.3-alt4 for branch p8 in task 163782.
Closed bugs
libphonon4qt5-debuginfo конфликтует с libphonon-debuginfo