ALT-BU-2016-2921-1
Branch p8 update bulletin.
Package systemd-udev-console-fb updated to version 1.00-alt2 for branch p8 in task 168327.
Closed bugs
Ошибка при загрузке ОС в 991-fb-systemd.rules
Package cups-filters updated to version 1.10.0-alt2 for branch p8 in task 168315.
Closed vulnerabilities
BDU:2016-00006
Уязвимость фильтра печати Foomatic и операционной системы Ubuntu, позволяющая нарушителю выполнить произвольные команды
Modified: 2024-11-21
CVE-2015-8327
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/annotate/head:/NEWS
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/annotate/head:/NEWS
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7406
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7406
- openSUSE-SU-2016:0179
- openSUSE-SU-2016:0179
- RHSA-2016:0491
- RHSA-2016:0491
- DSA-3411
- DSA-3411
- DSA-3429
- DSA-3429
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 78524
- 78524
- USN-2831-1
- USN-2831-1
- USN-2831-2
- USN-2831-2
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806886
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806886
- [debian-printing] 20151126 cups-filters 1.2.0 released!
- [debian-printing] 20151126 cups-filters 1.2.0 released!
- [debian-printing] 20151201 Re: cups-filters 1.2.0 released!
- [debian-printing] 20151201 Re: cups-filters 1.2.0 released!
Modified: 2024-11-21
CVE-2015-8560
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/annotate/head:/NEWS
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/annotate/head:/NEWS
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7419
- http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7419
- RHSA-2016:0491
- RHSA-2016:0491
- DSA-3419
- DSA-3419
- DSA-3429
- DSA-3429
- [oss-security] 20151213 CVE Request: Cups Filters/Foomatic Filters: Does not consider semicolon as an illegal shell escape character
- [oss-security] 20151213 CVE Request: Cups Filters/Foomatic Filters: Does not consider semicolon as an illegal shell escape character
- [oss-security] 20151214 Re: CVE Request: Cups Filters/Foomatic Filters: Does not consider semicolon as an illegal shell escape character
- [oss-security] 20151214 Re: CVE Request: Cups Filters/Foomatic Filters: Does not consider semicolon as an illegal shell escape character
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- USN-2838-1
- USN-2838-1
- USN-2838-2
- USN-2838-2
Package xfce4-settings updated to version 4.12.0-alt2 for branch p8 in task 168332.
Closed bugs
xfsettingsd: segfault libupower-glib.so.3.0.1
Package phpMyAdmin updated to version 4.6.3-alt1 for branch p8 in task 168316.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2015-2206
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
- FEDORA-2015-3287
- FEDORA-2015-3287
- FEDORA-2015-3329
- FEDORA-2015-3329
- FEDORA-2015-3336
- FEDORA-2015-3336
- openSUSE-SU-2015:1191
- openSUSE-SU-2015:1191
- DSA-3382
- DSA-3382
- MDVSA-2015:186
- MDVSA-2015:186
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-1.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-1.php
- 72949
- 72949
- 1031871
- 1031871
- https://github.com/phpmyadmin/phpmyadmin/commit/b2f1e895038a5700bf8e81fb9a5da36cbdea0eeb
- https://github.com/phpmyadmin/phpmyadmin/commit/b2f1e895038a5700bf8e81fb9a5da36cbdea0eeb
Modified: 2024-11-21
CVE-2015-3902
Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.
- openSUSE-SU-2015:1191
- openSUSE-SU-2015:1191
- DSA-3382
- DSA-3382
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-2.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-2.php
- 74657
- 74657
- 1032404
- 1032404
- https://github.com/phpmyadmin/phpmyadmin/commit/ee92eb9bab8e2d546756c1d4aec81ec7c8e44b83
- https://github.com/phpmyadmin/phpmyadmin/commit/ee92eb9bab8e2d546756c1d4aec81ec7c8e44b83
Modified: 2024-11-21
CVE-2015-3903
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- http://cxsecurity.com/issue/WLB-2015050095
- http://cxsecurity.com/issue/WLB-2015050095
- openSUSE-SU-2015:1191
- openSUSE-SU-2015:1191
- http://packetstormsecurity.com/files/131954/phpMyAdmin-4.4.6-Man-In-The-Middle.html
- http://packetstormsecurity.com/files/131954/phpMyAdmin-4.4.6-Man-In-The-Middle.html
- DSA-3382
- DSA-3382
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-3.php
- http://www.phpmyadmin.net/home_page/security/PMASA-2015-3.php
- 20150514 phpMyAdmin 4.4.6 Man-In-the-Middle API Github
- 20150514 phpMyAdmin 4.4.6 Man-In-the-Middle API Github
- 74660
- 74660
- 1032403
- 1032403
- https://github.com/phpmyadmin/phpmyadmin/commit/5ebc4daf131dd3bd646326267f3e765d0249bbb4
- https://github.com/phpmyadmin/phpmyadmin/commit/5ebc4daf131dd3bd646326267f3e765d0249bbb4
Modified: 2024-11-21
CVE-2016-5097
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.
- openSUSE-SU-2016:1556
- openSUSE-SU-2016:1556
- 1035978
- 1035978
- https://github.com/phpmyadmin/phpmyadmin/commit/11eb574242d2526107366d367ab5585fbe29578f
- https://github.com/phpmyadmin/phpmyadmin/commit/11eb574242d2526107366d367ab5585fbe29578f
- https://github.com/phpmyadmin/phpmyadmin/commit/59e56bd63a5e023b797d82eb272cd074e3b4bfd1
- https://github.com/phpmyadmin/phpmyadmin/commit/59e56bd63a5e023b797d82eb272cd074e3b4bfd1
- https://github.com/phpmyadmin/phpmyadmin/commit/5fc8020c5ba9cd2e38beb5dfe013faf2103cdf0f
- https://github.com/phpmyadmin/phpmyadmin/commit/5fc8020c5ba9cd2e38beb5dfe013faf2103cdf0f
- https://github.com/phpmyadmin/phpmyadmin/commit/8326aaebe54083d9726e153abdd303a141fe5ad3
- https://github.com/phpmyadmin/phpmyadmin/commit/8326aaebe54083d9726e153abdd303a141fe5ad3
- GLSA-201701-32
- GLSA-201701-32
- https://www.phpmyadmin.net/security/PMASA-2016-14
- https://www.phpmyadmin.net/security/PMASA-2016-14
Closed bugs
Обновить unixODBC