Security
Jun 3, 2017, 04:20 PM
samba
Version: 3.5.14-alt1.M60P.1.M60C.1
Summary: Server and Client software to interoperate with Windows machines
Changelog:
- smbd: applied upstream patch for remote code execution from a writable share (fixes CVE-2017-7494).
Feb 17, 2017, 08:19 PM
libX11
Version: 1.4.3-alt1.M60C.2
Summary: X11 Library
Changelog:
- Fixed changelog entry. - Fixed CVE-2013-7439.
Feb 17, 2017, 08:07 PM
bzip2
Version: 1.0.6-alt3.M60C.2
Summary: Extremely powerful file compression utility
Changelog:
- Fixed changelog entry. - Fixed CVE-2016-3189.
Feb 17, 2017, 08:02 PM
file
Version: 4.26-alt7.M60C.2
Summary: A utility for determining file types
Changelog:
- Fixed changelog entry. - Fixed CVE-2014-9653.
Feb 17, 2017, 07:57 PM
bash
Feb 17, 2017, 07:46 PM
tar
Version: 1.23-alt5.M60C.2
Summary: A GNU file archiving program
Changelog:
- Fixed changelog entry. - Fixed CVE-2016-6321.
Feb 17, 2017, 07:41 PM
libidn
Version: 1.24-alt1.M60C.3
Summary: Internationalized Domain Name support library
Changelog:
- Fixed changelog entry. - Fixed CVE-2016-6261. - Fixed CVE-2016-6262. - Fixed CVE-2015-8948. - Fixed CVE-2016-6263.
Feb 17, 2017, 07:35 PM
libgcrypt
Feb 17, 2017, 06:48 PM
glibc
Version: 2.11.3-alt8.M60C.4
Summary: The GNU libc libraries
Changelog:
Oct 20, 2016, 04:10 PM
openssh
Version: 5.9p1-alt7.M60C.2
Summary: OpenSSH free Secure Shell (SSH) implementation
Changelog:
- Backported upstream fixes for CVE-2015-8325, CVE-2016-3115, CVE-2016-6210, CVE-2016-8858.
Sep 13, 2016, 07:26 PM
libtasn1
Version: 2.12-alt1.M60C.2
Summary: The ASN.1 library used in GNUTLS
Changelog:
- Fix stack overflow in asn1_der_decoding (CVE-2015-2806).
Sep 13, 2016, 07:19 PM
libxml2
Version: 2.9.3-alt0.M60C.3
Summary: The library for manipulating XML files
Changelog:
- Fix CVE-2016-4448: + More format string warnings with possible format string vulnerability. + Fix some format string warnings with possible format string vulnerability. - Fix CVE-2016-4447: + Heap-based buffer-underreads due to xmlParseName. - Fix CVE-2016-4449: + Fix inappropriate fetch of entities content.
Jun 14, 2016, 09:06 PM
libsndfile
Version: 1.0.25-alt1.M60C.2
Summary: A library to handle various audio file formats
Changelog:
- Fixed CVE-2015-7805.
Jun 14, 2016, 08:48 PM
grub2
Jun 14, 2016, 08:12 PM
cpio
Jun 14, 2016, 07:31 PM
qemu-kvm-el
Version: 0.12.1.2-alt11.M60C.3
Summary: Kernel Virtual Machine virtualization environment
Changelog:
- Fix CVE-2012-0029.
Dec 25, 2015, 04:23 PM
e2fsprogs
Version: 1.41.14-alt1.M60C.2
Summary: The filesystem utilities for the ext2/ext3 filesystems
Changelog:
- CVE-2015-1572, CVE-2015-0247 fixed
Nov 27, 2015, 01:28 PM
libcap
Version: 2.16-alt4.M60C.2
Summary: Library for getting and setting POSIX.1e capabilities
Changelog:
- CVE-2011-4099 fixed
Nov 26, 2015, 05:28 PM
elfutils
Version: 0.152-alt1.M60C.2
Summary: A collection of utilities and DSOs to handle compiled objects
Changelog:
- CVE-2014-9447 fixed
Nov 26, 2015, 04:59 PM
expat
Version: 2.0.1-alt5.M60C.2
Summary: An XML parser written in C
Changelog:
- CVE-2012-0876, CVE-2012-1147, CVE-2012-1148 fixed
Nov 25, 2015, 02:07 PM
less
Version: 444-alt1.M60C.2
Summary: A text file browser similar to more, but better
Changelog:
- CVE-2014-9488 fixed
Nov 25, 2015, 01:00 PM
libssh2
Version: 1.2.8-alt1.M60C.2
Summary: A library implementing the SSH2 protocol
Changelog:
- CVE-2015-1782 fixed
Nov 25, 2015, 12:06 PM
libxcb
Nov 25, 2015, 11:24 AM
perl
Version: 5.12.3-alt4.M60C.2
Summary: Practical Extraction and Report Language
Changelog:
Nov 23, 2015, 03:03 PM
logrotate
Version: 3.7.9-alt3.M60C.2
Summary: Rotates, compresses, and mails system logs
Changelog:
- CVE-2011-1155, CVE-2011-1154, CVE-2011-1098 fixed
Nov 19, 2015, 06:01 PM
rpcbind
Apr 8, 2012, 02:50 AM
libtiff
Version: 3.9.6-alt1
Summary: A library of functions for manipulating TIFF format image files
Changelog:
- Updated to Release-v3-9-6-1-gc8ae292 (fixes CVE-2012-1173).
Apr 5, 2012, 04:38 AM
libpng
Version: 1.2.49-alt1
Summary: A library of functions for manipulating PNG image format files
Changelog:
- Updated to 1.2.49 (fixes CVE-2011-3048).
Mar 15, 2012, 12:08 PM
quagga
Version: 0.99.20.1-alt1
Summary: Quagga routing suite (a fork of the GNU Zebra)
Changelog:
- new version (CVE-2012-0249, CVE-2012-0250)
Mar 14, 2012, 12:12 AM
pidgin
Version: 2.10.1-alt0.M60P.1
Summary: A GTK+ based multiprotocol instant messaging client
Changelog:
- p6 security update (fix CVE-2011-3594 CVE-2011-4601 CVE-2011-4602 CVE-2011-4603)
Dec 16, 2011, 12:44 AM
bind
Version: 9.3.6-alt7
Summary: ISC BIND - DNS server
Changelog:
- Imported fixes for several DNSSEC vulnerabilities from RH bind (CVE-2009-4022, CVE-2010-0097, CVE-2010-3762, CVE-2011-4313); note that DNSSEC is not enabled by default. - Enabled IPv6 support. - Fixed RPATH issue.
Dec 5, 2011, 12:14 PM
tuxguitar
Version: 1.2-alt1.M60P.1
Summary: A multitrack guitar tablature editor and player
Changelog:
- Backport to p6 branch (CVE-2010-3385)
Dec 1, 2011, 08:59 PM
subversion
Version: 1.6.17-alt0.M60P.1
Summary: A version control system
Changelog:
- Backport to p6 branch (CVE-2011-1752 CVE-2011-1783 CVE-2011-1921)
Nov 1, 2011, 11:32 PM
cyrus-imapd
Version: 2.4.12-alt0.M60P.1
Summary: A high-performance mail store with IMAP and POP3 support
Changelog:
- Backport to p6 branch (fixes CVE-2011-3372)
Oct 7, 2011, 04:16 PM
radvd
Version: 1.8.2-alt1
Summary: A Router Advertisement daemon
Changelog:
- 1.8.2. Security fixes: + CVE-2011-3601 + CVE-2011-3602 + CVE-2011-3603 + CVE-2011-3604 + CVE-2011-3605
Sep 3, 2011, 06:21 PM
libmodplug
Version: 0.8.8.4-alt1
Summary: Modplug mod music file format library
Changelog:
- NMU: 0.8.8.4 - Security fixes: CVE-2011-2911 CVE-2011-2912 CVE-2011-2913 CVE-2011-2914 CVE-2011-2915
Aug 11, 2011, 11:27 AM
gimp
Version: 2.6.11-alt4.M60P.1
Summary: The GNU Image Manipulation Program
Changelog:
- Backport to p6 branch (fixed CVE-2011-1782)
Aug 3, 2011, 02:31 AM
libsoup
Version: 2.34.3-alt1
Summary: Simple Object Access Protocol implementation
Changelog:
- Updated to 2.34.3 (fixes CVE-2011-2524).
Jun 25, 2011, 04:53 AM
libgdk-pixbuf
Version: 2.23.4-alt2
Summary: An image loading and rendering library for Gdk
Changelog:
- fixed CVE-2011-2485 (ALT #25816)
Jun 25, 2011, 04:20 AM
tor
Version: 0.2.1.30-alt1
Summary: Anonymizing overlay network for TCP (The onion router)
Changelog:
- Blindly updated 0.2.1.30 (fixes numerous bugs including CVE-2011-0427). - Updated build dependencies.
Jun 21, 2011, 10:45 AM
tigervnc
Version: 1.0.90-alt5
Summary: A TigerVNC remote display system
Changelog:
- updated xorg-server-source to 1.10.2 - enabled ipv6 - fixed CVE-2011-1775
Jun 16, 2011, 12:41 PM
xen
Version: 4.1.1-alt1
Summary: Xen is a virtual machine monitor
Changelog:
- 4.1.1 including CVE-2011-1898 fix
Jun 12, 2011, 09:03 PM
bind9.8
Version: 9.8.0-alt0.2
Summary: ISC BIND - DNS server
Changelog:
- 9.8.0-P2 (security fixes for CVE-2011-1907 and CVE-2011-1910).
Jun 7, 2011, 03:08 PM
fetchmail
Version: 6.3.20-alt1
Summary: Full-featured POP/IMAP/ETRN mail retrieval daemon
Changelog:
- 6.3.20 + fixes CVE-2011-1947: STARTTLS denial of service vulnerability (thanks ldv@ for heads-up)
May 13, 2011, 06:26 PM
apr1
Version: 1.4.4-alt1
Summary: Apache Portable Runtime
Changelog:
- New version (1.4.4) - Security fixes (CVE-2011-0419)
Apr 26, 2011, 09:12 AM
request-tracker
Version: 3.8.10-alt1
Summary: Request Tracker (RT) is an enterprise-grade issue tracking system
Changelog:
- 3.8.10. Security fixes: + CVE-2011-1689 + CVE-2011-1688 + CVE-2011-1687 + CVE-2011-1686 + CVE-2011-1685 - Enhance findreq skiplist.
Apr 25, 2011, 11:28 AM
polkit
Version: 0.101-alt2
Summary: PolicyKit Authorization Framework
Changelog:
- update to master git.7c59052 (fixed CVE-2011-1485)
Apr 13, 2011, 11:07 PM
ikiwiki
Mar 14, 2011, 02:11 PM
libgdiplus
Version: 2.6.7-alt2
Summary: An Open Source implementation of the GDI+ API.
Changelog:
- snapshot of 2.6 branch (20101015) - fixed CVE-2010-1526 (ALT #24399)
Mar 9, 2011, 03:38 AM
ncpfs
Version: 2.2.6-alt9
Summary: Utilities for the ncpfs filesystem, a NetWare client for Linux
Changelog:
- Imported fix of race conditions in ncpmount/ncpumount operations from Fedora (fixes CVE-2009-3297).
Mar 3, 2011, 02:17 PM
libcgroup
Version: 0.37.1-alt1
Summary: Libraries for allow to control and monitor control groups
Changelog:
- 0.37.1 - Fix buffer overflow when processing list of controllers from command line (CVE-2011-1006)
Jan 19, 2011, 10:52 PM
perl-CGI
Version: 3.49-alt2
Summary: Simple CGI class for Perl
Changelog:
- fixes for CVE-2010-4410 and CVE-2010-4411 (v5.12.3-RC2-1-gb7fa2ac)
Oct 25, 2010, 06:15 PM
libsmi
Version: 0.4.8-alt2
Summary: A library to access SMI MIB information
Changelog:
- some backports - security fix: CVE-2010-2891 (ALT #24394)
Oct 23, 2010, 08:39 AM
gnome-subtitles
Version: 1.0-alt1.git.75.gcf1c9d0
Summary: subtitle editor
Changelog:
- new version - fix CVE-2010-3357 (closes: #24316)
Oct 23, 2010, 02:36 AM
kernel-image-hpc-skif
Version: 2.6.32-alt24
Summary: The Linux kernel (the core of the Linux operating system)
Changelog:
- 2.6.32.24 - CVE-2010-3904 fixed
Oct 5, 2010, 10:43 AM
libesmtp
Version: 1.0.6-alt1
Summary: LibESMTP is a library to manage posting email using SMTP
Changelog:
- New version 1.0.6: + Fixed CVE-2010-1192, CVE-2010-1194 (certificate validation flaws) - Build changes: + Disabled static build + Fixed install section + Plugins moved from devel subpackage to the main
Jun 2, 2010, 03:33 PM
sudo
Version: 1.6.8p12-alt8
Summary: Allows command execution as another user
Changelog:
- Backported upstream fix for CVE-2010-1163 (env_reset, ignore_dot and secure_path sudoers options all had to be explicitly disabled to make an attack possible). - Backported upstream fix for CVE-2010-1646 (env_reset sudoers option had to be explicitly disabled to make an attack possible).
Feb 8, 2010, 12:09 PM
chrony
Version: 1.24-alt1
Summary: Chrony clock synchronization program
Changelog:
- 1.24. Contains security fixes for CVE-2010-0292, CVE-2010-0293, CVE-2010-0294.
Oct 5, 2009, 07:56 PM
ss5
Version: 3.6.4-alt2.rel3.2
Summary: Full featured SOCKS4 and SOCKS5 server
Changelog:
- NMU: security fix for CVE-2009-2368 (array index overflow) (ALT #20701) + thanks crux@ for heads-up
Jul 19, 2009, 03:24 AM
scponly
Version: 4.8-alt2
Summary: Limited shell for secure file transfers
Changelog:
- fix build with gcc - Add patch to prevent restriction bypass using OpenSSH's scp options -F and -o (CVE-2007-6415)
May 19, 2009, 06:54 PM
ntp
Version: 4.2.4-alt5.p7
Summary: The Network Time Protocol (NTP)
Changelog:
- 4.2.4p7 - fix for CVE-2009-1252 (closes: #20099) - fix for CVE-2009-0159 (closes: #19779)
May 18, 2009, 03:44 PM
eggdrop
Version: 1.6.19-alt2
Summary: Eggdrop is an IRC bot, written in C
Changelog:
- Security fix: eggdrop remote crash vulnerability (incomplete patch for CVE-2007-2807) (Closes: #20067)
May 8, 2009, 04:38 AM
cscope
Version: 15.7a-alt1
Summary: Cscope is a text screen based source browsing tool
Changelog:
- [15.7a] (closes: #19952) + CVE-2009-0148
Jan 27, 2009, 09:23 AM
smarty
Version: 2.6.22-alt1
Summary: Template engine for PHP
Changelog:
- Updated to 2.6.22. Security fixes: + CVE-2008-4810 + CVE-2008-4811
Apr 16, 2007, 12:14 AM
lha
Version: 1.14i-alt2
Summary: An archiving and compression utility for LHarc format archives
Changelog:
- ac20050924p1: security fixes for CVE-2006-4335, CVE-2006-4337, CVE-2006-4338 (DoS, system access) - removed patch1, patch2, patch4, patch5 (didn't apply)