Репозиторий Sisyphus
Последнее обновление: 21 июня 2018 | Пакетов: 18578 | Посещений: 11721370
en ru br
Исправления уязвимостей

kernel-image-std-def-4.9.109-alt1   сборка Kernel Bot, 2018-06-19


- v4.9.109 (Fixes: CVE-2018-10853)

kernel-image-un-def-4.16.16-alt1   сборка Kernel Bot, 2018-06-19


- v4.16.16 (Fixes: CVE-2018-10853)

libgcrypt-1.7.10-alt1.S1   сборка Sergey V Turchin, 2018-06-14


- new version
- security fixes: CVE-2018-0495

libwebkitgtk4-2.20.3-alt1   сборка Yuri N. Sedunov, 2018-06-11


- 2.20.3 (fixed CVE-2018-4190, CVE-2018-4199, CVE-2018-4218,
CVE-2018-4222, CVE-2018-4232, CVE-2018-4233, CVE-2018-4246,
CVE-2018-11646)

firefox-esr-60.0.2-alt1   сборка Andrey Cherepanov, 2018-06-11


- New ESR version (60.0.2).
- Fixed:
+ CVE-2018-6126 Heap buffer overflow rasterizing paths in SVG with Skia

gnupg-1.4.22-alt2   сборка Dmitry V. Levin, 2018-06-08


- Backported upstream fixes
(GnuPG-bug-id: 2923, 3329, 3898, 4012; fixes CVE-2018-12020).

gnupg2-2.2.8-alt1.S1   сборка Sergey V Turchin, 2018-06-08


- new version
- security fix: CVE-2018-12020

epiphany-3.28.3.1-alt1   сборка Yuri N. Sedunov, 2018-06-08


- 3.28.3.1 (fixed CVE-2018-11396, CVE-2018-12016)

firefox-60.0.2-alt1   сборка Alexey Gladkov, 2018-06-07


- New release (60.0.2).
- Fixed:
+ CVE-2018-6126: Heap buffer overflow rasterizing paths in SVG with Skia

firefox-esr-60.0.1-alt1   сборка Andrey Cherepanov, 2018-06-05


- New ESR version (60.0.1).
- Fixed:
+ CVE-2018-5154: Use-after-free with SVG animations and clip paths
+ CVE-2018-5155: Use-after-free with SVG animations and text paths
+ CVE-2018-5157: Same-origin bypass of PDF Viewer to view protected PDF files
+ CVE-2018-5158: Malicious PDF can inject JavaScript into PDF Viewer
+ CVE-2018-5159: Integer overflow and out-of-bounds write in Skia
+ CVE-2018-5160: Uninitialized memory use by WebRTC encoder
+ CVE-2018-5152: WebExtensions information leak through webRequest API
+ CVE-2018-5153: Out-of-bounds read in mixed content websocket messages
+ CVE-2018-5163: Replacing cached data in JavaScript Start-up Bytecode Cache
+ CVE-2018-5164: CSP not applied to all multipart content sent with multipart/x-mixed-replace
+ CVE-2018-5166: WebExtension host permission bypass through filterReponseData
+ CVE-2018-5167: Improper linkification of chrome: and javascript: content in web console and JavaScript debugger
+ CVE-2018-5168: Lightweight themes can be installed without user interaction
+ CVE-2018-5169: Dragging and dropping link text onto home button can set home page to include chrome pages
+ CVE-2018-5172: Pasted script from clipboard can run in the Live Bookmarks page or PDF viewer
+ CVE-2018-5173: File name spoofing of Downloads panel with Unicode characters
+ CVE-2018-5174: Windows Defender SmartScreen UI runs with less secure behavior for downloaded files in Windows 10 April 2018 Update
+ CVE-2018-5175: Universal CSP bypass on sites using strict-dynamic in their policies
+ CVE-2018-5176: JSON Viewer script injection
+ CVE-2018-5177: Buffer overflow in XSLT during number formatting
+ CVE-2018-5165: Checkbox for enabling Flash protected mode is inverted in 32-bit Firefox
+ CVE-2018-5180: heap-use-after-free in mozilla::WebGLContext::DrawElementsInstanced
+ CVE-2018-5181: Local file can be displayed in noopener tab through drag and drop of hyperlink
+ CVE-2018-5182: Local file can be displayed from hyperlink dragged and dropped on addressbar
+ CVE-2018-5151: Memory safety bugs fixed in Firefox 60
+ CVE-2018-5150: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8

python-2.7.14-alt4   сборка Aleksei Nikiforov, 2018-05-31


- Fixed heap-use-after-free bug (Fixes: CVE-2018-1000030).

jq-1.5-alt3.S1   сборка Anton Farygin, 2018-05-31


- security update (fixes: CVE-2016-4074)

kernel-image-std-pae-4.4.134-alt1   сборка Kernel Bot, 2018-05-30


- v4.4.134 (Fixes: CVE-2018-6412)

kernel-image-std-def-4.9.104-alt1   сборка Kernel Bot, 2018-05-30


- v4.9.104 (Fixes: CVE-2018-6412)

wireshark-2.6.1-alt1.S1   сборка Anton Farygin, 2018-05-24


- 2.6.1 (fixes: CVE-2018-11359, CVE-2018-11361, CVE-2018-11358, CVE-2018-11360, CVE-2018-11356, CVE-2018-11357, CVE-2018-11355, CVE-2018-11354, CVE-2018-11362)

xen-4.10.1-alt1.S1   сборка Dmitriy D. Shadrinov, 2018-05-24


- 4.10.1 release
- upstream updates upto 7b35e7807, including:
+ x86/HVM: guard against emulator driving ioreq state in weird ways
(thx Jan Beulich) (XSA-262)
+ x86/vpt: add support for IO-APIC routed interrupts (part of XSA-261)
+ x86/traps: Fix handling of #DB exceptions in hypervisor context
x86/traps: Use an Interrupt Stack Table for #DB
x86/pv: Move exception injection into {,compat_}test_all_events()
x86/traps: Fix %dr6 handing in #DB handler
(thx Andrew Cooper) (part of XSA-260 / CVE-2018-8897)

kernel-image-std-def-4.9.101-alt1   сборка Kernel Bot, 2018-05-21


- v4.9.101 (Fixes: CVE-2018-1120)

kernel-image-un-def-4.16.10-alt1   сборка Kernel Bot, 2018-05-21


- v4.16.10 (Fixes: CVE-2018-1120)

thunderbird-52.8.0-alt1   сборка Andrey Cherepanov, 2018-05-19


- New version (52.8.0).
- Enigmail 2.0.4.
- Fixes:
+ CVE-2018-5183 Backport critical security fixes in Skia
+ CVE-2018-5184 Full plaintext recovery in S/MIME via chosen-ciphertext attack
+ CVE-2018-5154 Use-after-free with SVG animations and clip paths
+ CVE-2018-5155 Use-after-free with SVG animations and text paths
+ CVE-2018-5159 Integer overflow and out-of-bounds write in Skia
+ CVE-2018-5161 Hang via malformed headers
+ CVE-2018-5162 Encrypted mail leaks plaintext through src attribute
+ CVE-2018-5170 Filename spoofing for external attachments
+ CVE-2018-5168 Lightweight themes can be installed without user interaction
+ CVE-2018-5178 Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
+ CVE-2018-5185 Leaking plaintext through HTML forms
+ CVE-2018-5150 Memory safety bugs fixed in Firefox 60, Firefox ESR 52.8, and Thunderbird 52.8
- Build in several threads.

mariadb-10.2.15-alt1.S1   сборка Alexey Shabalin, 2018-05-18


- 10.2.15
- rename libmysqlclient18 to libmariadb
- relocate plugindir to %_libdir/%name/plugin
- build without libwrap support
- Fixes for the following security vulnerabilities:
+ CVE-2018-2562
+ CVE-2018-2622
+ CVE-2018-2640
+ CVE-2018-2665
+ CVE-2018-2668
+ CVE-2018-2612
+ CVE-2018-2786
+ CVE-2018-2759
+ CVE-2018-2777
+ CVE-2018-2810
+ CVE-2018-2782
+ CVE-2018-2784
+ CVE-2018-2787
+ CVE-2018-2766
+ CVE-2018-2755
+ CVE-2018-2819
+ CVE-2018-2817
+ CVE-2018-2761
+ CVE-2018-2781
+ CVE-2018-2771
+ CVE-2018-2813

glusterfs3-3.12.9-alt1   сборка Vitaly Lipatov, 2018-05-17


- new version 3.12.9 (with rpmrb script)
- CVE-2018-1088

firefox-60.0.1-alt1   сборка Alexey Gladkov, 2018-05-17


- New release (60.0.1).
- Fixed:
+ CVE-2018-5154: Use-after-free with SVG animations and clip paths
+ CVE-2018-5155: Use-after-free with SVG animations and text paths
+ CVE-2018-5157: Same-origin bypass of PDF Viewer to view protected PDF files
+ CVE-2018-5158: Malicious PDF can inject JavaScript into PDF Viewer
+ CVE-2018-5159: Integer overflow and out-of-bounds write in Skia
+ CVE-2018-5160: Uninitialized memory use by WebRTC encoder
+ CVE-2018-5152: WebExtensions information leak through webRequest API
+ CVE-2018-5153: Out-of-bounds read in mixed content websocket messages
+ CVE-2018-5163: Replacing cached data in JavaScript Start-up Bytecode Cache
+ CVE-2018-5164: CSP not applied to all multipart content sent with multipart/x-mixed-replace
+ CVE-2018-5166: WebExtension host permission bypass through filterReponseData
+ CVE-2018-5167: Improper linkification of chrome: and javascript: content in web console and JavaScript debugger
+ CVE-2018-5168: Lightweight themes can be installed without user interaction
+ CVE-2018-5169: Dragging and dropping link text onto home button can set home page to include chrome pages
+ CVE-2018-5172: Pasted script from clipboard can run in the Live Bookmarks page or PDF viewer
+ CVE-2018-5173: File name spoofing of Downloads panel with Unicode characters
+ CVE-2018-5174: Windows Defender SmartScreen UI runs with less secure behavior for downloaded files in Windows 10 April 2018 Update
+ CVE-2018-5175: Universal CSP bypass on sites using strict-dynamic in their policies
+ CVE-2018-5176: JSON Viewer script injection
+ CVE-2018-5177: Buffer overflow in XSLT during number formatting
+ CVE-2018-5165: Checkbox for enabling Flash protected mode is inverted in 32-bit Firefox
+ CVE-2018-5180: heap-use-after-free in mozilla::WebGLContext::DrawElementsInstanced
+ CVE-2018-5181: Local file can be displayed in noopener tab through drag and drop of hyperlink
+ CVE-2018-5182: Local file can be displayed from hyperlink dragged and dropped on addressbar
+ CVE-2018-5151: Memory safety bugs fixed in Firefox 60
+ CVE-2018-5150: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8

curl-7.60.0-alt1.S1   сборка Anton Farygin, 2018-05-16


- 7.60.0
- fixes:
* CVE-2018-1000300 FTP shutdown response buffer overflow
* CVE-2018-1000301 RTSP bad headers buffer over-read

kernel-image-un-def-4.16.9-alt1   сборка Kernel Bot, 2018-05-16


- v4.16.9 (Fixes: CVE-2018-1000200)

firefox-esr-52.8.0-alt1   сборка Andrey Cherepanov, 2018-05-09


- New ESR version (52.8.0).
- Fixes:
+ CVE-2018-5183 Backport critical security fixes in Skia
+ CVE-2018-5154 Use-after-free with SVG animations and clip paths
+ CVE-2018-5155 Use-after-free with SVG animations and text paths
+ CVE-2018-5157 Same-origin bypass of PDF Viewer to view protected PDF files
+ CVE-2018-5158 Malicious PDF can inject JavaScript into PDF Viewer
+ CVE-2018-5159 Integer overflow and out-of-bounds write in Skia
+ CVE-2018-5168 Lightweight themes can be installed without user interaction
+ CVE-2018-5178 Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
+ CVE-2018-5150 Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8
 
дизайн и разработка: Vladimir Lettiev aka crux © 2004-2005, Andrew Avramenko aka liks © 2007-2008
текущий майнтейнер: Michael Shigorin