Mandriva Linux Security Advisory 2015-166 - Updated clamav packages fix multiple security vulnerabilities.
b72156fd29a265cdca5bd3634cd1acd0
Mandriva Linux Security Advisory 2015-165 - By making use of maliciously-constructed zones or a rogue server, an attacker can exploit an oversight in the code BIND 9 uses to follow delegations in the Domain Name Service, causing BIND to issue unlimited queries in an attempt to follow the delegation. This can lead to resource exhaustion and denial of service.
93f80b863f6566dcd74d041586495e43
Mandriva Linux Security Advisory 2015-161 - Updated icu packages fix multiple security vulnerabilities.
5174e84f93e47624210f241d05182f0e
Mandriva Linux Security Advisory 2015-163 - An integer overflow in liblzo before 2.07 allows attackers to cause a denial of service or possibly code execution in applications using performing LZO decompression on a compressed payload from the attacker. The grub2 package is built with a bundled copy of minilzo, which is a part of liblzo containing the vulnerable code.
59da96cfb85e217573f8ad76115f3b9a
Mandriva Linux Security Advisory 2015-162 - Clemens Fries reported that, when using Cinnamon, it was possible to bypass the screensaver lock. An attacker with physical access to the machine could use this flaw to take over the locked desktop session. This was fixed by including a patch for the root cause of the issue in gtk+3.0, which came from the implementation of popup menus in GtkWindow. This update also includes other patches from upstream to fix bugs affecting GtkFileChooser and GtkSpinButton, and a crash related to clipboard handling.
7020f01886735b070af02e5e56665e48
Mandriva Linux Security Advisory 2015-160 - In IPython before 1.2, the origin of websocket requests was not verified within the IPython notebook server. If an attacker has knowledge of an IPython kernel id they can run arbitrary code on a user's machine when the client visits a crafted malicious page.
d7a7fa5bfc4c18d8dc3e0649c647edfd
Mandriva Linux Security Advisory 2015-185 - Updated dokuwiki packages fix multiple security vulnerabilities.
76ba0dc99857420bf3a20f93a8dc6880
HP Security Bulletin HPSBHF03271 1 - A potential security vulnerability has been identified with certain HP PCs and workstations running Windows 7 and NVidia Graphics Driver. This vulnerability could be exploited resulting in elevation of privilege. Note: The NVIDIA Display Drivers kernel administrator check improperly validates local client impersonation levels in some cases. Revision 1 of this advisory.
77a30b7140c52bb955869f780c2dc7c4
Debian Linux Security Advisory 3209-1 - Multiple vulnerabilities were found in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol.
b5cbd317e7a03415e2fc3ace55384ad6
HP Security Bulletin HPSBGN03270 1 - A potential security vulnerability has been identified with HP Operations Analytics. This is the GlibC vulnerability known as "GHOST" which could be exploited remotely resulting in execution of code.. Revision 1 of this advisory.
b52448af2a63d89d8d18d27e82513686
Mandriva Linux Security Advisory 2015-184 - An issue has been identified in Mandriva Business Server 2's setup package where the /etc/shadow and /etc/gshadow files containing password hashes were created with incorrect permissions, making them world-readable. This update fixes this issue by enforcing that those files are owned by the root user and shadow group, and are only readable by those two entities. Note that this issue only affected new Mandriva Business Server 2 installations. Systems that were updated from previous Mandriva versions were not affected.
1dbebb54e1adb002d282db0efe35bbd4
Mandriva Linux Security Advisory 2015-183 - Updated wireshark packages fix multiple security vulnerabilities.
b67448f4f52d4e767404dccaf457275c
Mandriva Linux Security Advisory 2015-159 - Josh Duart of the Google Security Team discovered heap-based buffer overflow flaws in JasPer, which could lead to denial of service or the execution of arbitrary code. A double free flaw was found in the way JasPer parsed ICC color profiles in JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code. A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code. An off-by-one flaw, leading to a heap-based buffer overflow, was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code. An unrestricted stack memory use flaw was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code.
50e01e2bc9562e9c187ab9204028fd15
Mandriva Linux Security Advisory 2015-182 - Several vulnerabilities have been discovered in tcpdump. These vulnerabilities might result in denial of service (application crash) or, potentially, execution of arbitrary code.
b1a9d099720fc757045b11638001e9bc
Mandriva Linux Security Advisory 2015-145 - Ilja van Sprundel discovered that libXfont incorrectly handled font metadata file parsing. A local attacker could use this issue to cause libXfont to crash, or possibly execute arbitrary code in order to gain privileges. Ilja van Sprundel discovered that libXfont incorrectly handled X Font Server replies. A malicious font server could return specially-crafted data that could cause libXfont to crash, or possibly execute arbitrary code. The bdf parser reads a count for the number of properties defined in a font from the font file, and allocates arrays with entries for each property based on that count. It never checked to see if that count was negative, or large enough to overflow when multiplied by the size of the structures being allocated, and could thus allocate the wrong buffer size, leading to out of bounds writes. If the bdf parser failed to parse the data for the bitmap for any character, it would proceed with an invalid pointer to the bitmap data and later crash when trying to read the bitmap from that pointer. The bdf parser read metrics values as 32-bit integers, but stored them into 16-bit integers. Overflows could occur in various operations leading to out-of-bounds memory access.
7e6347413032d379e2435fe41b73959d
Mandriva Linux Security Advisory 2015-147 - The libtiff image decoder library contains several issues that could cause the decoder to crash when reading crafted TIFF images.
9135f52f67d759887f476401c5fb1441
Mandriva Linux Security Advisory 2015-181 - Updated drupal packages fix multiple security vulnerabilities.
0240fabab23e9a0a598709267a074bb3
Mandriva Linux Security Advisory 2015-178 - A denial of service issue was discovered in ctags 5.8. A remote attacker could cause excessive CPU usage and disk space consumption via a crafted JavaScript file by triggering an infinite loop.
70c32609d4f7a47cd7a03468a4c2f640
Mandriva Linux Security Advisory 2015-179 - Bertrand Jacquin and Fiedler Roman discovered date and touch incorrectly handled user-supplied input. An attacker could possibly use this to cause a denial of service or potentially execute code.
fae55ac4ab0aeee301549761ee7808cc
Mandriva Linux Security Advisory 2015-180 - apache-mod_wsgi before 4.2.4 contained an off-by-one error in applying a limit to the number of supplementary groups allowed for a daemon process group. The result could be that if more groups than the operating system allowed were specified to the option supplementary-groups, then memory corruption or a process crash could occur. It was discovered that mod_wsgi incorrectly handled errors when setting up the working directory and group access rights. A malicious application could possibly use this issue to cause a local privilege escalation when using daemon mode.
a249871eea00d12b6aac55948e64e240
Mandriva Linux Security Advisory 2015-029 - Multiple integer overflows in the _objalloc_alloc function in objalloc.c and objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service via vectors related to the addition of CHUNK_HEADER_SIZE to the length, which triggers a heap-based buffer overflow. Various other issues have also been addressed. The updated packages provide a solution for these security issues.
ebc3ac8d951ed689ba83ea71521f9f29
Mandriva Linux Security Advisory 2015-177 - ctdb before 2.5 is vulnerable to symlink attacks to due the use of predictable filenames in /tmp, such as /tmp/ctdb.socket.
e5b6cc0ddfa311bc913b65f58cbb26d0
Mandriva Linux Security Advisory 2015-176 - Updated dbus packages fix multiple security vulnerabilities.
6dfaf1bc91e6464b570e446008dda2a9
Mandriva Linux Security Advisory 2015-175 - A flaw was discovered in ejabberd that allows clients to connect with an unencrypted connection even if starttls_required is set.
e3063af24b90e5f87f9cfa2c56f2661f
Mandriva Linux Security Advisory 2015-174 - An FTP command injection flaw was found in Erlang's FTP module. Several functions in the FTP module do not properly sanitize the input before passing it into a control socket. A local attacker can use this flaw to execute arbitrary FTP commands on a system that uses this module. This update also disables SSLv3 by default to mitigate the POODLE issue.
fe6a09b0b453ba1c5f7782e7ee89000b