Sisyphus repository
Last update: 28 march 2015 | SRPMs: 17701 | Visits: 6459835
en ru br
Security fixes

openssl10-1.0.1k-alt2   build Gleb F-Malinovskiy, 2015-03-19


- Fixed CVE-2015-0209, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288,
CVE-2015-0289, CVE-2015-0293.

adobe-flash-player-11-alt42   build Sergey V Turchin, 2015-03-13


- new version
- security fixes:
CVE-2015-0332, CVE-2015-0333, CVE-2015-0334, CVE-2015-0335,
CVE-2015-0336, CVE-2015-0337, CVE-2015-0338, CVE-2015-0339,
CVE-2015-0340, CVE-2015-0341, CVE-2015-0342

chromium-41.0.2272.76-alt1   build Andrey Cherepanov, 2015-03-04


- New version
- Security fixes:
- High CVE-2015-1212: Out-of-bounds write in media.
- High CVE-2015-1213: Out-of-bounds write in skia filters.
- High CVE-2015-1214: Out-of-bounds write in skia filters.
- High CVE-2015-1215: Out-of-bounds write in skia filters.
- High CVE-2015-1216: Use-after-free in v8 bindings.
- High CVE-2015-1217: Type confusion in v8 bindings.
- High CVE-2015-1218: Use-after-free in dom.
- High CVE-2015-1219: Integer overflow in webgl.
- High CVE-2015-1220: Use-after-free in gif decoder.
- High CVE-2015-1221: Use-after-free in web databases.
- High CVE-2015-1222: Use-after-free in service workers.
- High CVE-2015-1223: Use-after-free in dom.
- High CVE-2015-1230: Type confusion in v8.
- Medium CVE-2015-1224: Out-of-bounds read in vpxdecoder.
- Medium CVE-2015-1225: Out-of-bounds read in pdfium.
- Medium CVE-2015-1226: Validation issue in debugger.
- Medium CVE-2015-1227: Uninitialized value in blink.
- Medium CVE-2015-1228: Uninitialized value in rendering.
- Medium CVE-2015-1229: Cookie injection via proxies.

samba-4.1.17-alt1   build Anton V. Boyarshinov, 2015-02-23


- 4.1.17
- CVE-2015-0240 fixed

libvirt-1.2.12-alt1   build Alexey Shabalin, 2015-02-11


- 1.2.12
- fixed CVE-2015-0236

krb5-1.13-alt3   build Ivan A. Melnikov, 2015-02-08


- fix for MITKRB5-SA-2015-001 (CVE-2014-5352, CVE-2014-9421,
CVE-2014-9422, CVE-2014-9423)

chromium-40.0.2214.111-alt1   build Andrey Cherepanov, 2015-02-06


- New version
- Security fixes:
- High CVE-2015-1211: Privilege escalation using service workers.

adobe-flash-player-11-alt41   build Sergey V Turchin, 2015-02-06


- new version
- security fixes:
CVE-2015-0313, CVE-2015-0314, CVE-2015-0315, CVE-2015-0316,
CVE-2015-0317, CVE-2015-0318, CVE-2015-0319, CVE-2015-0320,
CVE-2015-0321, CVE-2015-0322, CVE-2015-0323, CVE-2015-0324,
CVE-2015-0325, CVE-2015-0326, CVE-2015-0327, CVE-2015-0328,
CVE-2015-0329, CVE-2015-0330

clamav-0.98.6-alt1   build Sergey Y. Afonin, 2015-01-28


- 0.98.6 (CVE-2014-9328)

adobe-flash-player-11-alt40   build Sergey V Turchin, 2015-01-28


- new version
- security fixes: CVE-2015-0311, CVE-2015-0312

pxz-4.999.9beta-alt3   build Michael Shigorin, 2015-01-27


- CVE-2015-1200 fix (patch from debian bug #775306)

adobe-flash-player-11-alt39   build Sergey V Turchin, 2015-01-23


- new version
- security fixes: CVE-2015-0310, CVE-2015-0311

chromium-40.0.2214.91-alt1   build Andrey Cherepanov, 2015-01-23


- New version
- Security fixes:
- High CVE-2014-7923: Memory corruption in ICU.
- High CVE-2014-7924: Use-after-free in IndexedDB.
- High CVE-2014-7925: Use-after-free in WebAudio.
- High CVE-2014-7926: Memory corruption in ICU.
- High CVE-2014-7927: Memory corruption in V8.
- High CVE-2014-7928: Memory corruption in V8.
- High CVE-2014-7930: Use-after-free in DOM.
- High CVE-2014-7931: Memory corruption in V8.
- High CVE-2014-7929: Use-after-free in DOM.
- High CVE-2014-7932: Use-after-free in DOM.
- High CVE-2014-7933: Use-after-free in FFmpeg.
- High CVE-2014-7934: Use-after-free in DOM.
- High CVE-2014-7935: Use-after-free in Speech.
- High CVE-2014-7936: Use-after-free in Views.
- High CVE-2014-7937: Use-after-free in FFmpeg.
- High CVE-2014-7938: Memory corruption in Fonts.
- High CVE-2014-7939: Same-origin-bypass in V8.
- Medium CVE-2014-7940: Uninitialized-value in ICU.
- Medium CVE-2014-7941: Out-of-bounds read in UI.
- Medium CVE-2014-7942: Uninitialized-value in Fonts.
- Medium CVE-2014-7943: Out-of-bounds read in Skia.
- Medium CVE-2014-7944: Out-of-bounds read in PDFium.
- Medium CVE-2014-7945: Out-of-bounds read in PDFium.
- Medium CVE-2014-7946: Out-of-bounds read in Fonts.
- Medium CVE-2014-7947: Out-of-bounds read in PDFium.
- Medium CVE-2014-7948: Caching error in AppCache.

openvpn-2.3.6-alt1   build Nikolay A. Fetisov, 2015-01-15


- New version 2.3.6
- CVE-2014-8104 (Closes: 30529)
- Adding pkcs11 support (Closes: 30614)
- Adding systemd service files (Closes: 28071)

adobe-flash-player-11-alt38   build Sergey V Turchin, 2015-01-14


- new version
- security fixes:
CVE-2015-0301, CVE-2015-0302, CVE-2015-0303, CVE-2015-0304,
CVE-2015-0305, CVE-2015-0306, CVE-2015-0307, CVE-2015-0308,
CVE-2015-0309

openssl10-1.0.1k-alt1   build Gleb F-Malinovskiy, 2015-01-12


- Updated to 1.0.1k (fixes CVE-2014-3571, CVE-2015-0206, CVE-2014-3569,
CVE-2014-3572, CVE-2015-0204, CVE-2015-0205, CVE-2014-8275,
CVE-2014-3570) (closes: 30644).

strongswan-5.2.2-alt1   build Michael Shigorin, 2015-01-05


- new version (watch file uupdate)
- fixes CVE-2014-9221 (DoS)

krb5-1.13-alt2   build Alexey Shabalin, 2014-12-23


- fixed CVE-2014-5353, CVE-2014-5354

libvirt-1.2.11-alt1   build Alexey Shabalin, 2014-12-18


- 1.2.11
- fixed CVE-2014-7823,CVE-2014-8135,CVE-2014-8136,CVE-2014-8131

adobe-flash-player-11-alt37   build Sergey V Turchin, 2014-12-10


- new version
- security fixes:
CVE-2014-0580, CVE-2014-0587, CVE-2014-8443, CVE-2014-9162,
CVE-2014-9163, CVE-2014-9164

adobe-flash-player-11-alt36   build Sergey V Turchin, 2014-11-26


- new version
- security fixes: CVE-2014-8439

chromium-39.0.2171.65-alt1   build Andrey Cherepanov, 2014-11-21


- New version
- Security fixes:
- High CVE-2014-7899: Address bar spoofing.
- High CVE-2014-7900: Use-after-free in pdfium.
- High CVE-2014-7901: Integer overflow in pdfium.
- High CVE-2014-7902: Use-after-free in pdfium.
- High CVE-2014-7903: Buffer overflow in pdfium.
- High CVE-2014-7904: Buffer overflow in Skia.
- High CVE-2014-7905: Flaw allowing navigation to intents that do not
have the BROWSABLE category.
- High CVE-2014-7906: Use-after-free in pepper plugins.
- High CVE-2014-0574: Double-free in Flash.
- High CVE-2014-7907: Use-after-free in blink.
- High CVE-2014-7908: Integer overflow in media.
- Medium CVE-2014-7909: Uninitialized memory read in Skia.
- Mark all files in /etc/chromium as config
- Strip Chromium executables to disable debuginfo generation (became too
huge)

adobe-flash-player-11-alt35   build Sergey V Turchin, 2014-11-12


- new version
- security fixes:
CVE-2014-0573, CVE-2014-0574, CVE-2014-0576, CVE-2014-0577,
CVE-2014-0581, CVE-2014-0582, CVE-2014-0583, CVE-2014-0584,
CVE-2014-0585, CVE-2014-0586, CVE-2014-0588, CVE-2014-0589,
CVE-2014-0590, CVE-2014-8437, CVE-2014-8438, CVE-2014-8440,
CVE-2014-8441, CVE-2014-8442

krb5-1.13-alt1   build Alexey Shabalin, 2014-10-31


- 1.13
- fixed CVE-2014-5351
- move header from /usr/include/krb5 to /usr/include
- drop kdcrotate service
- update krb5.conf:
+ add [logging] example
+ add [realms] example
+ add [domain_realm] example
+ define default_ccache_name as KEYRING:persistent:%{uid}

openssl10-1.0.1j-alt1   build Gleb F-Malinovskiy, 2014-10-30


- Updated to 1.0.1j (fixes CVE-2014-3512, CVE-2014-3511, CVE-2014-3510,
CVE-2014-3507, CVE-2014-3506, CVE-2014-3505, CVE-2014-3509,
CVE-2014-5139, CVE-2014-3508, CVE-2014-3513, CVE-2014-3567,
CVE-2014-3566, CVE-2014-3568).
- Updated patches from Fedora openssl-1.0.1j-2.
- kssl.h: include <krb5/krb5.h> instead of <krb5/krb5/krb5.h> (ldv@).
 
design & coding: Vladimir Lettiev aka crux © 2004-2005, Andrew Avramenko aka liks © 2007-2008
current maintainer: Michael Shigorin