This bulletin summary lists two re-released Microsoft security bulletins for March, 2015.
7121bb1c0c9dd73bd283bdf972df6edf
Ubuntu Security Notice 2532-1 - It was discovered that cups-browsed incorrectly filtered remote printer names and strings. A remote attacker could use this issue to possibly execute arbitrary commands.
8471c42929eaf56ffbecbe57ff84a9d9
Ubuntu Security Notice 2531-1 - Matthew Daley discovered that Requests incorrectly handled cookies without host values when being redirected. A remote attacker could possibly use this issue to perform session fixation or cookie stealing attacks.
e5fb1d6b2ab2fe853fe2bd3bdaa94528
Ubuntu Security Notice 2533-1 - Jakub Wilk and Stephane Chazelas discovered that Sudo incorrectly handled the TZ environment variable. An attacker with Sudo access could possibly use this issue to open arbitrary files, bypassing intended permissions.
7f53c228e440e358414ce9d89419789d
Mandriva Linux Security Advisory 2015-061 - Sibiao Luo discovered that QEMU incorrectly handled device hot-unplugging. A local user could possibly use this flaw to cause a denial of service. Michael S. Tsirkin discovered that QEMU incorrectly handled vmxnet3 devices. A local guest could possibly use this issue to cause a denial of service, or possibly execute arbitrary code on the host. Multiple integer overflow, input validation, logic error, and buffer overflow flaws were discovered in various QEMU block drivers. An attacker able to modify a disk image file loaded by a guest could use these flaws to crash the guest, or corrupt QEMU process memory on the host, potentially resulting in arbitrary code execution on the host with the privileges of the QEMU process. Various other issues have also been addressed.
c9b55834c404543fea26edb504ed3e3e
Debian Linux Security Advisory 3191-1 - Multiple vulnerabilities have been discovered in GnuTLS, a library implementing the TLS and SSL protocols.
8fe44d1e05476d9e15b9790d2677c966
Debian Linux Security Advisory 3189-1 - Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library.
1e7f0b35c7f598d7a099be0599c8228f
Debian Linux Security Advisory 3190-1 - Patrick Coleman discovered that the Putty SSH client failed to wipe out unused sensitive memory.
cf56925f389c2350775816a0d992faa5
Debian Linux Security Advisory 3188-1 - Mateusz Jurczyk discovered multiple vulnerabilities in Freetype. Opening malformed fonts may result in denial of service or the execution of arbitrary code.
b34b412fe501019976313a3212c6df3d
Debian Linux Security Advisory 3187-1 - Several vulnerabilities were discovered in the International Components for Unicode (ICU) library.
26dd6b19dbfefc1c781d098ed5c9873a
Mandriva Linux Security Advisory 2015-060 - Florian Weimer of the Red Hat Product Security Team discovered a heap-based buffer overflow flaw in LibYAML, a fast YAML 1.1 parser and emitter library. A remote attacker could provide a YAML document with a specially-crafted tag that, when parsed by an application using libyaml, would cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application. Ivan Fratric of the Google Security Team discovered a heap-based buffer overflow vulnerability in LibYAML, a fast YAML 1.1 parser and emitter library. A remote attacker could provide a specially-crafted YAML document that, when parsed by an application using libyaml, would cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application. An assertion failure was found in the way the libyaml library parsed wrapped strings. An attacker able to load specially crafted YAML input into an application using libyaml could cause the application to crash.
58623aa93e3abcf6f58d5b3c93e753fd
Mandriva Linux Security Advisory 2015-059 - Multiple vulnerabilities has been found and corrected in the Mozilla NSS and NSPR packages. The updated packages provides a solution for these security issues.
2c77270c2fd4ff12cd5ee2996304f911
Gentoo Linux Security Advisory 201503-7 - An out-of-bounds error in hivex may result in execution of arbitrary code or Denial of Service. Versions less than 1.3.11 are affected.
4c71773f1a39e39ad3e0d766894b78d4
Gentoo Linux Security Advisory 201503-6 - Multiple vulnerabilities have been found in ICU, possibly resulting in Denial of Service. Versions less than 54.1-r1 are affected.
fcb78ecc23ea112d82885be32074aeb8
Foxit Reader version 7.0.6.1126 suffers from an unquoted service path elevation of privilege vulnerability.
6405d325fb84e1ef1b0864584fec84bb
724CMS versions 5.01, 4.59, 4.01, and 3.01 suffer from directory traversal vulnerabilities.
cb84ff6b5489670664e40338d60cf02f
WordPress Reflex Gallery plugin version 3.1.3 suffers from a remote shell upload vulnerability.
5d0c580555da0c2ca98431e3de69c5e7
724CMS versions 5.01, 4.59, 4.01, and 3.01 suffer from multiple information leakage vulnerabilities.
3c6fd9456b1f7e5392fc23281ce36401
Obfuscated shellcode for Windows x86/x64 that downloads and executes a binary using powershell.
568c605c2b2da654b50180ab952c88c3