Security
Jan 27, 2010, 01:26 AM
MySQL
Version: 5.0.89-alt1
Summary: MySQL: A very fast and reliable SQL database engine
Changelog:
- new version (closes #18943) - fixed CVE-2009-2446 from upstream (closes #20724) - setup utf8 encoding instead of latin1 by default (closes #12390) - include C99 aliasing violation patch from mythtv (closes #22452) - removed username-length patch - wait for mysqld shutdown (closes #22234) - don't run initial setup mysql database if mysql.user table already exists
Jan 20, 2010, 06:05 PM
gzip
Version: 1.3.5-alt4.M40.1
Summary: The GNU data compression program
Changelog:
- Applied upstream fix for integer underflow bug (CVE-2010-0001).
Jul 29, 2009, 03:01 AM
bind
Version: 9.3.6-alt5
Summary: ISC BIND - DNS server
Changelog:
- Backported upstream fix for a remote DoS bug (CVE-2009-0696).
May 4, 2009, 01:01 PM
libwmf
Version: 0.2.8.4-alt6
Summary: A library to convert wmf files
Changelog:
- fixed CAN-2004-0941, CAN-2004-0990, CVE-2007-2756, CVE-2007-3473
Apr 30, 2009, 07:29 PM
gnutls26
Version: 2.6.6-alt0.M50.1
Summary: Transport Layer Security library
Changelog:
- 2.6.6 release. + fix Corrected double free on signature verification failure (CVE-2009-1415) + fix DSA key generation (CVE-2009-1416) + fix gnutls-cli expiration/activation time check (CVE-2009-1417)
Apr 27, 2009, 11:41 AM
wireshark
Version: 1.0.7-alt1
Summary: The BugTraq Award Winning Network Traffic Analyzer
Changelog:
- [1.0.7] + CVE-2009-1210 + CVE-2009-1267 + CVE-2009-1268 + CVE-2009-1269
Apr 23, 2009, 11:31 AM
dbus
Version: 1.2.12-alt3
Summary: D-BUS is a simple IPC framework based on messages.
Changelog:
- fixed CVE-2009-1189
Apr 15, 2009, 10:47 AM
libfreetype
Version: 2.3.9-alt2
Summary: The FreeType2 library
Changelog:
- fixed CVE-2009-0946
Mar 20, 2009, 04:07 PM
ghostscript
Version: 8.64-alt3
Summary: PostScript interpreter and renderer, most printer drivers
Changelog:
- CVE-2009-0583, CVE-2009-0584
Feb 12, 2009, 05:16 PM
audiofile
Version: 0.2.6-alt2.M50.1
Summary: Library to handle various audio file formats
Changelog:
- Fix CVE-2008-5824.
Feb 12, 2009, 04:48 PM
ffmpeg
Version: 15151-alt5.M50.1
Summary: Hyper fast MPEG1/MPEG4/H263/RV and AC3/MPEG audio encoder
Changelog:
- Fix ffmpeg <r16846 Type conversion vulnerability (CVE-2009-0385).
Jan 27, 2009, 09:23 AM
smarty
Version: 2.6.22-alt1
Summary: Template engine for PHP
Changelog:
- Updated to 2.6.22. Security fixes: + CVE-2008-4810 + CVE-2008-4811
Dec 28, 2008, 11:37 PM
wordnet
Version: 3.0-alt4
Summary: WordNet English lexical reference system
Changelog:
- applied patches against CVE-2008-2149, CVE-2008-3908 (fix bug #15678)
Dec 1, 2008, 01:12 PM
fetchmail
Version: 6.3.9-alt1
Summary: Full-featured POP/IMAP/ETRN mail retrieval daemon
Changelog:
- 6.3.9 + CVE-2007-4565: Denial of service + CVE-2008-2711: Denial of service + close memory leak when SSL connection fails and other - remove obsolete update_menus/clean_menus macroses
Nov 25, 2008, 09:37 AM
libxml2
Version: 2.7.2-alt2
Summary: The library for manipulating XML files
Changelog:
- updated to svn revision 3803 (fixes CVE-2008-4225, CVE-2008-4226)
Nov 21, 2008, 05:09 PM
imlib2
Version: 1.4.0-alt3
Summary: Powerful image loading and rendering library
Changelog:
- Fix CVE-2008-5187.
Nov 10, 2008, 04:26 PM
net-snmp
Version: 5.4.2.1-alt1
Summary: Tools and servers for the SNMP protocol
Changelog:
- 5.4.2.1 release (fixes CVE-2008-4309).
Sep 27, 2008, 02:30 PM
perl-Tk
Version: 804.028-alt2
Summary: Perl modules providing the Tk graphics library
Changelog:
- merged two fixes from https://svn.perl.org/modules/Tk + fixed a buffer overflow in tkImgGIF.c (CVE-2006-4484) + fixed event handling for newer X servers (cpan#38745) - applied perl-Tk-seg.patch from Fedora (RH#235666, RH#431330) - disabled t/unicode.t test which fails under Xvfb
Aug 13, 2008, 10:33 AM
uudeview
Version: 0.5.20-alt3
Summary: smart uuenc/xxenc/base64 encoder/decoder
Changelog:
- Security fix: CVE-2008-2266 - Pull in source patches from Debian: + Fix temporary file issue (CVE-2004-2265, CVE-2008-2266, DEB#222275) + Update uudeview man page, include uuwish man page + Don't force overwrite mode if auto-rename enabled, DEB#378076 - Drop uudeview-0.5.20-mkstemp.patch
Aug 9, 2008, 04:16 AM
libxslt
Version: 1.1.24-alt1
Summary: Library providing XSLT support
Changelog:
- 1.1.23 -> 1.1.24 - applied upstream fix for libexslt/crypto overflow (CVE-2008-2935)
Jun 26, 2008, 10:56 PM
pear-MDB2
Version: 2.5.0b1-alt1
Summary: database abstraction layer
Changelog:
- new version 2.5.0b1 (with rpmrb script) - due CVE-2007-5934 (fix bug #16173)
May 17, 2008, 02:34 AM
libid3tag
Version: 0.15.1b-alt6
Summary: ID3 Tag manipulation library
Changelog:
- Fix CVE-2008-2109.
May 14, 2008, 07:47 PM
libvorbis
Version: 1.2.0-alt3
Summary: The Vorbis General Audio Compression Codec
Changelog:
- CVE-2008-1419 (patch from upstream) - CVE-2008-1420 (patch from upstream) - CVE-2008-1423 (patch from upstream)
Apr 30, 2008, 03:01 PM
perl-Imager
Version: 0.64-alt1
Summary: Perl module for generating 24 bit Images
Changelog:
- New version 0.64 -- fix buffer overflow in image fills (CVE-2008-1928) -- multiple improvements in image converting code -- several other bug fixes and improvements, see Changes for details
Mar 18, 2008, 10:44 AM
unzip
Version: 5.52-alt5
Summary: An utility for unpacking zip archives
Changelog:
- fix CVE-2008-0888
Feb 14, 2008, 09:57 AM
SDL_image
Version: 1.2.6-alt3
Summary: Simple DirectMedia Layer - image
Changelog:
- Buffer overflow fix in RLE decompression (CVE-2008-0544).
Feb 5, 2008, 10:56 AM
scponly
Version: 4.8-alt1
Summary: Limited shell for secure file transfers
Changelog:
- Updated to new version 4.8, fixes CVE-2007-6415 problem - Change source URL to SourceForge
Nov 30, 2007, 04:57 PM
ircservices
Version: 5.0.63-alt1
Summary: IRC Services is a system of services to be used with Internet Relay Chat networks
Changelog:
- Security fix: CVE-2007-6122
Apr 16, 2007, 12:14 AM
lha
Version: 1.14i-alt2
Summary: An archiving and compression utility for LHarc format archives
Changelog:
- ac20050924p1: security fixes for CVE-2006-4335, CVE-2006-4337, CVE-2006-4338 (DoS, system access) - removed patch1, patch2, patch4, patch5 (didn't apply)