Mandriva security advisories
Updated: 1 min 58 sec ago
1 min 58 sec ago
This update of the IaOra theme for KDE4 contains several bugfixes,
including:
- check boxes are not visible (#50260)
- arabic text overlaps in KDE 4.2 menus (#50993)
1 min 58 sec ago
This update fixes a number of issues with msec shipped with Mandriva
Linux 2009.1:
- Msec would send an error message when desktop notification support
(NOTIFY_WARN) was not found in the security configuration file
(#51364, #51464)
- In some locales, msec would show an error message or incorrectly
translated messages when running in console (#50869)
This update also adds updated translation files for msec.
1 min 58 sec ago
Mandriva Linux 2009 Spring was released with KDE4 version 4.2.2.
This update upgrades KDE4 in Mandriva Linux 2009 Spring to version
4.2.4, which brings many bugfixes and overall improvements.
1 min 58 sec ago
Updated timezone packages are being provided for older Mandriva Linux
systems that do not contain new Daylight Savings Time information
and Time Zone information for some locations. These updated packages
contain the new information.
Update:
Packages for MNF2/CS3/CS4 is now also provided.
1 min 58 sec ago
Security vulnerabilities has been identified and fixed in pidgin:
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin
(formerly Gaim) before 2.5.6 allows remote authenticated users to
execute arbitrary code via vectors involving an outbound XMPP file
transfer. NOTE: some of these details are obtained from third party
information (CVE-2009-1373).
Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim)
before 2.5.6 allows remote attackers to cause a denial of service
(application crash) via a QQ packet (CVE-2009-1374).
The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before
2.5.6 does not properly maintain a certain buffer, which allows
remote attackers to cause a denial of service (memory corruption
and application crash) via vectors involving the (1) XMPP or (2)
Sametime protocol (CVE-2009-1375).
Multiple integer overflows in the msn_slplink_process_msg functions in
the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and
(2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim)
before 2.5.6 on 32-bit platforms allow remote attackers to execute
arbitrary code via a malformed SLP message with a crafted offset
value, leading to buffer overflows. NOTE: this issue exists because
of an incomplete fix for CVE-2008-2927 (CVE-2009-1376).
This update provides pidgin 2.5.8, which is not vulnerable to these
issues.
1 min 58 sec ago
Updated timezone packages are being provided for older Mandriva Linux
systems that do not contain new Daylight Savings Time information
and Time Zone information for some locations. These updated packages
contain the new information.
1 min 58 sec ago
Security vulnerabilities has been identified and fixed in University
of Washington IMAP Toolkit:
Multiple stack-based buffer overflows in (1) University of Washington
IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine
2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain
privileges by specifying a long folder extension argument on the
command line to the tmail or dmail program; and (b) remote attackers to
execute arbitrary code by sending e-mail to a destination mailbox name
composed of a username and '+' character followed by a long string,
processed by the tmail or possibly dmail program (CVE-2008-5005).
smtp.c in the c-client library in University of Washington IMAP Toolkit
2007b allows remote SMTP servers to cause a denial of service (NULL
pointer dereference and application crash) by responding to the QUIT
command with a close of the TCP connection instead of the expected
221 response code (CVE-2008-5006).
Off-by-one error in the rfc822_output_char function in the RFC822BUFFER
routines in the University of Washington (UW) c-client library, as
used by the UW IMAP toolkit before imap-2007e and other applications,
allows context-dependent attackers to cause a denial of service (crash)
via an e-mail message that triggers a buffer overflow (CVE-2008-5514).
The updated packages have been patched to prevent this. Note that the
software was renamed to c-client starting from Mandriva Linux 2009.0
and only provides the shared c-client library for the imap functions
in PHP.
1 min 58 sec ago
A vulnerability has been found and corrected in PHP:
- Fixed upstream bug #48378 (exif_read_data() segfaults on certain
corrupted .jpeg files).
The updated packages have been patched to correct these issues.
1 min 58 sec ago
Multiple security vulnerabilities has been identified and fixed
in ghostscript:
Multiple integer overflows in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via a crafted
image file, related to integer multiplication for memory allocation
(CVE-2008-3520).
Buffer overflow in the jas_stream_printf function in
libjasper/base/jas_stream.c in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via
vectors related to the mif_hdr_put function and use of vsprintf
(CVE-2008-3522).
Previousely the ghostscript packages were statically built against
a bundled and private copy of the jasper library. This update makes
ghostscript link against the shared system jasper library which
makes it easier to address presumptive future security issues in the
jasper library.
1 min 58 sec ago
Multiple security vulnerabilities has been identified and fixed
in netpbm:
Multiple integer overflows in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via a crafted
image file, related to integer multiplication for memory allocation
(CVE-2008-3520).
Buffer overflow in the jas_stream_printf function in
libjasper/base/jas_stream.c in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via
vectors related to the mif_hdr_put function and use of vsprintf
(CVE-2008-3522).
The updated packages have been patched to prevent this.
Fri, 07/03/2009 - 18:20
Multiple security vulnerabilities has been identified and fixed
in jasper:
The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer
JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted
attackers to cause a denial of service (crash) and possibly corrupt
the heap via malformed image files, as originally demonstrated using
imagemagick convert (CVE-2007-2721).
Multiple integer overflows in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via a crafted
image file, related to integer multiplication for memory allocation
(CVE-2008-3520).
The jas_stream_tmpfile function in libjasper/base/jas_stream.c in
JasPer 1.900.1 allows local users to overwrite arbitrary files via
a symlink attack on a tmp.XXXXXXXXXX temporary file (CVE-2008-3521).
Buffer overflow in the jas_stream_printf function in
libjasper/base/jas_stream.c in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via
vectors related to the mif_hdr_put function and use of vsprintf
(CVE-2008-3522).
The updated packages have been patched to prevent this.
Thu, 07/02/2009 - 21:10
Multiple bugs has been identified and corrected in pulseaudio:
- alsa: allow configuration of fallback device strings in profiles
util: if NULL is passed to pa_path_get_filename() just hand it through
alsa: don't hit an assert when invalid module arguments are passed
- alsa: fix wording, we are speaking of card profiles, not output
profiles
- alsa: initialize buffer size before number of periods to improve
compat with some backends
- conf: remove obsolete module-idle-time directive from default config
file/man page
- core: make sure soft mute status stays in sync with hw mute status
endian: fix LE/BE order for 24 bit accessor functions
- log: print file name only when we have it
- man: document 24bit sample types in man page
- man: document log related daemon.conf options
- man: document that tsched doesn't use fragment settings
- mutex: when we fail to fill in mutex into static mutex ptr free
it again
- oss: don't deadlock when we try to resume an OSS device that lacks
a mixer
- simple-protocol: don't hit an assert when we call connection_unlink()
early
- idxset: add enumeration macro PA_IDXSET_FOREACH
- rescue-streams: when one stream move fails try to continue with
the remaining ones
- sample: correctly pass s24-32 formats
- sample-util: fix iteration loop when adjusting volume of s24 samples
- sample-util: properly allocate silence block for s24-32 formats
- sconv: fix a few minor conversion issues
- alsa: be a bit more verbose when a hwparam call fails
- rescue: make we don't end up in an endless loop when we can't move
a sink input
- core: introduce pa_{sink,source}_set_fixed_latency()
- core: cache requested latency only when we are running, not while
we are still constructing
- sample: fix build on BE archs
- alsa: properly convert return values of snd_strerror() to utf8
- alsa: remove debug codeAdditional
In addition to these fixes, several patches were recommended by
upstream and QAed with help from Mandriva volunteers. These patches
are also included.
Wed, 07/01/2009 - 23:20
The outdated aspell-no package was deprecated due to change of the
'no' (Norwegian) language code to 'nb' (Norwegian Bokml) resulting
in breakage with tools attempting to use the 'nb' dictionary.
Wed, 07/01/2009 - 10:40
The Yelp help browser shipped with Mandriva 2009 Spring was built
without support for LZMA compression. As this is needed to view the
compressed manual and GNU Info pages, LZMA support was enabled in
this update.
Update:
On the previous yelp update we added a require on liblzmadec0 for
i586 and lib64lzmadec for x86_64.
This fixes the update, which would not work via MandrivaUpdate.
Tue, 06/30/2009 - 14:50
The Yelp help browser shipped with Mandriva 2009 Spring was built
without support for LZMA compression. As this is needed to view the
compressed manual and GNU Info pages, LZMA support was enabled in
this update.
Mon, 06/29/2009 - 15:00
Mandriva Linux 2009 was released with KDE4 version 4.1.
This update upgrades KDE4 in Mandriva Linux 2009 to version 4.2,
which brings many bugfixes and overall improvements.
Update:
The previous kde4 update added additional dependencies that was
not fulfilled.
This fixes the update, which would not work via MandrivaUpdate.
Mon, 06/29/2009 - 14:00
Multiple security vulnerabilities has been identified and fixed
in gaim:
Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin before
2.5.6 allows remote authenticated users to execute arbitrary code via
vectors involving an outbound XMPP file transfer. NOTE: some of these
details are obtained from third party information (CVE-2009-1373).
Multiple integer overflows in the msn_slplink_process_msg functions
in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c
and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.5.6
on 32-bit platforms allow remote attackers to execute arbitrary code
via a malformed SLP message with a crafted offset value, leading to
buffer overflows. NOTE: this issue exists because of an incomplete
fix for CVE-2008-2927 (CVE-2009-1376).
The updated packages have been patched to prevent this.
Sun, 06/28/2009 - 16:00
A security vulnerability has been identified and corrected in
libtorrent-rasterbar:
Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar
libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge
Torrent, and other applications, allows remote attackers to create
or overwrite arbitrary files via a .. (dot dot) and partial relative
pathname in a Multiple File Mode list element in a .torrent file
(CVE-2009-1760).
The updated packages have been patched to prevent this.
Sat, 06/27/2009 - 16:10
A vulnerability has been identified and corrected in squirrelmail:
The map_yp_alias function in functions/imap_general.php in SquirrelMail
before 1.4.19 allows remote attackers to execute arbitrary commands
via shell metacharacters in a username string that is used by the
ypmatch program. NOTE: this issue exists because of an incomplete
fix for CVE-2009-1579. (CVE-2009-1381)
Basically this is a syncronization with the latest squirrelmail package
found in Mandriva Cooker. The rpm changelog will reveal all the changes
(rpm -q --changelog squirrelmail).
The updated packages have been upgraded to the latest version of
squirrelmail to prevent this.
Fri, 06/26/2009 - 20:10
Mandriva Linux 2009 was released with KDE4 version 4.1.
This update upgrades KDE4 in Mandriva Linux 2009 to version 4.2,
which brings many bugfixes and overall improvements.