Commit graph

227353 commits

Author SHA1 Message Date
obache
5be2a0a5f4 Apply following update to suse131_openssl, bump PKGREVISION.
openSUSE Security Update: Security update for openssl
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2015:0130-1
Rating:             important
References:         #911399 #912014 #912015 #912018 #912292 #912293
                    #912294 #912296
Cross-References:   CVE-2014-3569 CVE-2014-3570 CVE-2014-3571
                    CVE-2014-3572 CVE-2014-8275 CVE-2015-0204
                    CVE-2015-0205 CVE-2015-0206
Affected Products:
                    openSUSE 13.2
                    openSUSE 13.1
______________________________________________________________________________

   An update that fixes 8 vulnerabilities is now available.

Description:


   openssl was updated to 1.0.1k to fix various security issues and bugs.

   More information can be found in the openssl advisory:
   http://openssl.org/news/secadv_20150108.txt

   Following issues were fixed:

   * CVE-2014-3570 (bsc#912296): Bignum squaring (BN_sqr) may have produced
     incorrect results on some platforms, including x86_64.

   * CVE-2014-3571 (bsc#912294): Fixed crash in dtls1_get_record whilst in
     the listen state where you get two separate reads performed - one for
     the header and one for the body of the handshake record.

   * CVE-2014-3572 (bsc#912015): Don't accept a handshake using an ephemeral
     ECDH ciphersuites with the server key exchange message omitted.

   * CVE-2014-8275 (bsc#912018): Fixed various certificate fingerprint issues.

   * CVE-2015-0204 (bsc#912014): Only allow ephemeral RSA keys in export
     ciphersuites

   * CVE-2015-0205 (bsc#912293): A fixwas added to prevent use of DH client
     certificates without sending certificate verify message.

   * CVE-2015-0206 (bsc#912292): A memory leak was fixed in
     dtls1_buffer_record.

References:

   http://support.novell.com/security/cve/CVE-2014-3569.html
   http://support.novell.com/security/cve/CVE-2014-3570.html
   http://support.novell.com/security/cve/CVE-2014-3571.html
   http://support.novell.com/security/cve/CVE-2014-3572.html
   http://support.novell.com/security/cve/CVE-2014-8275.html
   http://support.novell.com/security/cve/CVE-2015-0204.html
   http://support.novell.com/security/cve/CVE-2015-0205.html
   http://support.novell.com/security/cve/CVE-2015-0206.html
   https://bugzilla.suse.com/show_bug.cgi?id=911399
   https://bugzilla.suse.com/show_bug.cgi?id=912014
   https://bugzilla.suse.com/show_bug.cgi?id=912015
   https://bugzilla.suse.com/show_bug.cgi?id=912018
   https://bugzilla.suse.com/show_bug.cgi?id=912292
   https://bugzilla.suse.com/show_bug.cgi?id=912293
   https://bugzilla.suse.com/show_bug.cgi?id=912294
   https://bugzilla.suse.com/show_bug.cgi?id=912296
2015-01-24 01:01:54 +00:00
mef
386fe0d978 Updated print/abcm2ps to 7.8.12 2015-01-24 00:58:45 +00:00
mef
0659d2f33e Update 6.6.6 to 7.8.12
---- Version 7.8.12 - 14/12/16 ----

Fix bad handling of "K:none", especially when transposition.
Fix bad transposition of latin guitar chord "La".
Fix loss of 'exp none' in K:.
Fix some compilation warnings
	(reported by John Chambers).
Fix problems with decorations or guitar chords/annotations
		in sequence/measure repeat.
	(reported by Frédéric Boulanger).

---- Version 7.8.11 - 14/11/26 ----

Fix bad position of grace notes in overlay voices at start of measure
	(reported by Jean-Luc Zins).
Fix bad repeat font when staves/voices with different scales
	(reported by  Gerhard Schacherl).

---- Version 7.8.10 - 14/11/01 ----

Change the PS font scale of the accidentals according to the FontMatrix
	(reported by Chuck Boody).
Fix loss of voice options when many %%voice's without "%%voice end" in %%tune.
Fix lost of lyrics when ABC version 2.1 and generation restart.
Fix bad transposition of notes when %%transpose after K:.

Too long to list all the ChangeLog, so
list of the version and date for the rest of ChangeLog
---- Version 7.8.9 - 14/10/14 ----
---- Version 7.8.8 - 14/08/29 ----
---- Version 7.8.7 - 14/08/09 ----
---- Version 7.8.6 - 14/07/17 ----
---- Version 7.8.5 - 14/07/01 ----
---- Version 7.8.4 - 14/06/18 ----
---- Version 7.8.3 - 14/05/23 ----
---- Version 7.8.2 - 14/05/05 ----
---- Version 7.8.1 - 14/04/02 ----
---- Version 7.8.0 - 14/03/26 ----
---- Version 7.7.2 - 14/03/07 ----
---- Version 7.7.1 - 14/02/18 ----
---- Version 7.7.0 - 14/02/17 ----
---- Version 7.6.10 - 14/01/23 ----
---- Version 7.6.9 - 14/01/23 ----
---- Version 7.6.8 - 13/11/21 ----
---- Version 7.6.7 - 13/11/03 ----
---- Version 7.6.6 - 13/11/03 ----
---- Version 7.6.5 - 13/11/02 ----
---- Version 7.6.4 - 13/11/01 ----
---- Version 7.6.3 - 13/10/25 ----
---- Version 7.6.2 - 13/10/18 ----
---- Version 7.6.1 - 13/10/16 ----
---- Version 7.6.0 - 13/08/20 ----
---- Version 7.5.8 - 13/08/07 ----
---- Version 7.5.7 - 13/07/16 ----
---- Version 7.5.6 - 13/06/17 ----
---- Version 7.5.5 - 13/06/06 ----
---- Version 7.5.4 - 13/05/27 ----
---- Version 7.5.3 - 13/05/24 ----
---- Version 7.5.2 - 13/03/22 ----
---- Version 7.5.1 - 13/03/17 ----
---- Version 7.5.0 - 13/03/01 ----
---- Version 7.4.2 - 13/02/13 ----
---- Version 7.4.1 - 13/02/11 ----
---- Version 7.4.0 - 13/01/29 ----
---- Version 7.3.5 - 13/01/15 ----
---- Version 7.3.4 - 13/01/08 ----
---- Version 7.3.3 - 12/12/14 ----
---- Version 7.3.2 - 12/12/07 ----
---- Version 7.3.1 - 12/11/28 ----
---- Version 7.3.0 - 12/11/17 ----
---- Version 7.2.2 - 12/11/07 ----
---- Version 7.2.1 - 12/10/30 ----
---- Version 7.2.0 - 12/10/25 ----
---- Version 7.1.3 - 12/10/18 ----
---- Version 7.1.2 - 12/10/09 ----
---- Version 7.1.1 - 12/09/29 ----
---- Version 7.1.0 - 12/09/13 ----
---- Version 7.0.16 - 12/09/06 ----
---- Version 7.0.15 - 12/08/27 ----
---- Version 7.0.14 - 12/07/22 ----
---- Version 7.0.13 - 12/06/17 ----
---- Version 7.0.12 - 12/06/10 ----
---- Version 7.0.11 - 12/06/02 ----
---- Version 7.0.10 - 12/05/28 ----
---- Version 7.0.9 - 12/05/23 ----
---- Version 7.0.8 - 12/05/21 ----
---- Version 7.0.7 - 12/05/16 ----
---- Version 7.0.6 - 12/05/13 ----
---- Version 7.0.5 - 12/04/30 ----
---- Version 7.0.4 - 12/03/31 ----
---- Version 7.0.3 - 12/03/03 ----
---- Version 7.0.2 - 12/02/21 ----
---- Version 7.0.1 - 12/02/06 ----
---- Version 7.0.0 - 12/02/02 ----
2015-01-24 00:58:36 +00:00
wiedi
781b53ceff Updated mail/rspamd to 0.8.1 2015-01-23 21:48:32 +00:00
wiedi
38f6db8b14 Update rspamd to 0.8.1
Remove patches that have been integrated upstream.

0.8.1:
	* Add sqlite and perl as dependencies for RPM/Debian packages (by @fatalbanana)
	* Remove whitelist.lua from RPM file list (by @fatalbanana)
	* Make Exim pass hostnames to rspamd (by @fatalbanana)
	* Fix building on Fedora (by @fatalbanana)
	* Add toggle for disabling installation of systemd units on Linux (by @fatalbanana)
	* Fix double format rounding that caused output corruption (reported by @fatalbanana)
	* Revert broken change for destructors ordering that led to memory corruption
	* Do not reset symbols case of settings if parsed from lua (reported by @andrejzverev)
	* Fix build on SunOS (by @wiedi)
	* Fix multiple crashes on broken DKIM DNS records
	* Fix critical issue with composites weights removing
	* Fix memory corruption in composites processing code
	* Ignore non-SPF TXT records when parsing SPF includes
2015-01-23 21:47:44 +00:00
pho
994a39ba08 Check for aligned memory functions with cmake
Not all platforms have posix_memalign(3) so we need to check if it
exists. This fixes build failure on Darwin 9. See:
https://www.gnu.org/software/gnulib/manual/html_node/posix_005fmemalign.html
2015-01-23 17:15:09 +00:00
taca
f705c811e2 Note remove of www/contao33 package. 2015-01-23 16:19:35 +00:00
taca
4d62a147ab Remove contao33 (Contao Open Source CMS 3.3.x) package since it was
replaced by contao34 (Contao Open Source CMS 3.4.x).
2015-01-23 16:19:14 +00:00
taca
903a394140 Remove contao33 entry. 2015-01-23 16:18:22 +00:00
taca
a00e7f3732 Note update of www/contao32 package to 3.2.17 and www/contao34 package to
3.4.2.
2015-01-23 16:17:06 +00:00
taca
75778502e1 Update to contao34 to 3.4.2.
Version 3.4.2 (2015-01-22)
--------------------------

### Fixed
Fix an infinite recursion problem in the `FilesModel` class (see #7588).


Version 3.4.1 (2015-01-22)
--------------------------

### Fixed
Fix the position of the input field hints (see #7561).

### Fixed
Do not apply the GDlib maximum dimensions to SVG images (see #7435).

### Fixed
Do not show the diff icon if a record has been deleted (see #7429).

### Fixed
Remove a left-over headline from the `ce_text.xhtml` template (see #7502).

### Fixed
Preserve comments when exporting CSS files (see #7482).

### Fixed
Fix the LESS import path in the Combiner (see #7533).

### Fixed
Hide the width and height attributes if there is a sizes attribute (see #7500).

### Fixed
Remove the hardcoded figcaption width (see #7549).

### Fixed
Only load the model in the file/page picker if the class exists (see #7490).

### Fixed
Romanize style sheet names (see #7526).

### Fixed
Add the username to the "account has been locked" log entry (see #7551).

### Fixed
Consider the suhosin.memory_limit when raising the PHP limits (see #7035).

### Fixed
Added two missing `exclude` flags in the `tl_page` data container (see #7522).

### Fixed
Send an UTF-8 charset header in the `die_nicely()` function (see #7519).

### Fixed
Correctly validate dates in the `Widget` class (see #7498).

### Fixed
Back port the fixes from #7475 and #7473.

### Fixed
Send the same cache headers for cached and uncached pages (see #7455).

### Fixed
Fix the `current() expects parameter 1 to be array` issue (see #6739).

### Fixed
Correctly replace the `*_teaser` insert tags (see #7488).

### Fixed
Adjust the last and previous login labels (see #7426).

### Fixed
Unset the `postUnsafeRaw` cache in `Input::setPost()` (see #7481).
2015-01-23 16:16:23 +00:00
wiz
b8aeb2d124 Fix build on NetBSD-current with strtoi.
From Kamil Rytarowski <n54@gmx.com>
2015-01-23 16:15:42 +00:00
taca
88f1d860f7 Update contao32 pacakge to 3.2.17.
Version 3.2.17 (2015-01-22)
---------------------------

### Fixed
Romanize style sheet names (see #7526).

### Fixed
Add the username to the "account has been locked" log entry (see #7551).

### Fixed
Consider the suhosin.memory_limit when raising the PHP limits (see #7035).

### Fixed
Added two missing `exclude` flags in the `tl_page` data container (see #7522).

### Fixed
Send an UTF-8 charset header in the `die_nicely()` function (see #7519).

### Fixed
Correctly validate dates in the `Widget` class (see #7498).

### Fixed
Back port the fixes from #7475 and #7473.

### Fixed
Send the same cache headers for cached and uncached pages (see #7455).

### Fixed
Fix the `current() expects parameter 1 to be array` issue (see #6739).

### Fixed
Correctly replace the `*_teaser` insert tags (see #7488).

### Fixed
Adjust the last and previous login labels (see #7426).

### Fixed
Unset the `postUnsafeRaw` cache in `Input::setPost()` (see #7481).
2015-01-23 16:14:35 +00:00
taca
4813a8b78a Note update oh php packages:
lang/php54	5.4.37
	lang/php55	5.5.21
	lang/php56	5.6.5
2015-01-23 16:12:43 +00:00
taca
42d22f7ab8 Update php56 to 5.6.5.
22 Jan 2015, PHP 5.6.5

- Core:
  . Upgraded crypt_blowfish to version 1.3. (Leigh)
  . Fixed bug #60704 (unlink() bug with some files path).
  . Fixed bug #65419 (Inside trait, self::class != __CLASS__). (Julien)
  . Fixed bug #68536 (pack for 64bits integer is broken on bigendian). (Remi)
  . Fixed bug #55541 (errors spawn MessageBox, which blocks test automation).
    (Anatol)
  . Fixed bug #68297 (Application Popup provides too few information). (Anatol)
  . Fixed bug #65769 (localeconv() broken in TS builds). (Anatol)
  . Fixed bug #65230 (setting locale randomly broken). (Anatol)
  . Fixed bug #66764 (configure doesn't define EXPANDED_DATADIR / PHP_DATADIR
    correctly). (Ferenc)
  . Fixed bug #68583 (Crash in timeout thread). (Anatol)
  . Fixed bug #65576 (Constructor from trait conflicts with inherited
    constructor). (dunglas at gmail dot com)
  . Fixed bug #68676 (Explicit Double Free). (Kalle)
  . Fixed bug #68710 (Use After Free Vulnerability in PHP's unserialize()).
    (CVE-2015-0231) (Stefan Esser)

- CGI:
  . Fixed bug #68618 (out of bounds read crashes php-cgi). (CVE-2014-9427)
    (Stas)

- CLI server:
  . Fixed bug #68745 (Invalid HTTP requests make web server segfault). (Adam)

- cURL:
  . Fixed bug #67643 (curl_multi_getcontent returns '' when
    CURLOPT_RETURNTRANSFER isn't set). (Jille Timmermans)

- Date:
  . Implemented FR #68268 (DatePeriod: Getter for start date, end date and
    interval). (Marc Bennewitz)

- EXIF:
  . Fixed bug #68799: Free called on unitialized pointer. (CVE-2015-0232)
    (Stas)

- Fileinfo:
  . Fixed bug #68398 (msooxml matches too many archives). (Anatol)
  . Fixed bug #68665 (invalid free in libmagic). (Joshua Rogers, Anatol Belski)
  . Fixed bug #68671 (incorrect expression in libmagic).
    (Joshua Rogers, Anatol Belski)
  . Removed readelf.c and related code from libmagic sources
    (Remi, Anatol)
  . Fixed bug #68735 (fileinfo out-of-bounds memory access).
    (Anatol)

- FPM:
  . Fixed request #68526 (Implement POSIX Access Control List for UDS). (Remi)
  . Fixed bug #68751 (listen.allowed_clients is broken). (Remi)

- GD:
  . Fixed bug #68601 (buffer read overflow in gd_gif_in.c). (Jan Bee, Remi)
  . Fixed request #68656 (Report gd library version). (Remi)

- mbstring:
  . Fixed bug #68504 (--with-libmbfl configure option not present on Windows).
    (Ashesh Vashi)

- Opcache:
  . Fixed bug #68644 (strlen incorrect : mbstring + func_overload=2 +UTF-8
    + Opcache). (Laruence)
  . Fixed bug #67111 (Memory leak when using "continue 2" inside two foreach
    loops). (Nikita)

- OpenSSL:
  . Improved handling of OPENSSL_KEYTYPE_EC keys. (Dominic Luechinger)

- pcntl:
  . Fixed bug #60509 (pcntl_signal doesn't decrease ref-count of old handler
    when setting SIG_DFL). (Julien)

- PCRE:
  . Fixed bug #66679 (Alignment Bug in PCRE 8.34 upstream).
    (Rainer Jung, Anatol Belski)

- pgsql:
  . Fixed bug #68697 (lo_export return -1 on failure). (Ondřej Surý)

- PDO:
  . Fixed bug #68371 (PDO#getAttribute() cannot be called with platform-specifi
    attribute names). (Matteo)

- PDO_mysql:
  . Fixed bug #68424 (Add new PDO mysql connection attr to control multi
    statements option). (peter dot wolanin at acquia dot com)

- SPL:
  . Fixed bug #66405 (RecursiveDirectoryIterator::CURRENT_AS_PATHNAME
    breaks the RecursiveIterator). (Paul Garvin)
  . Fixed bug #68479 (Added escape parameter to SplFileObject::fputcsv). (Salathe)

- SQLite:
  . Fixed bug #68120 (Update bundled libsqlite to 3.8.7.2). (Anatol)

- Streams:
  . Fixed bug #68532 (convert.base64-encode omits padding bytes).
    (blaesius at krumedia dot de)
2015-01-23 16:11:38 +00:00
taca
b019ab3429 Update php55 to 5.5.21.
22 Jan 2014, PHP 5.5.21

- Core:
  . Upgraded crypt_blowfish to version 1.3. (Leigh)
  . Fixed bug #60704 (unlink() bug with some files path).
  . Fixed bug #65419 (Inside trait, self::class != __CLASS__). (Julien)
  . Fixed bug #65576 (Constructor from trait conflicts with inherited
    constructor). (dunglas at gmail dot com)
  . Fixed bug #55541 (errors spawn MessageBox, which blocks test automation).
    (Anatol)
  . Fixed bug #68297 (Application Popup provides too few information). (Anatol)
  . Fixed bug #65769 (localeconv() broken in TS builds). (Anatol)
  . Fixed bug #65230 (setting locale randomly broken). (Anatol)
  . Fixed bug #66764 (configure doesn't define EXPANDED_DATADIR / PHP_DATADIR
    correctly). (Ferenc)
  . Fixed bug #68583 (Crash in timeout thread). (Anatol)
  . Fixed bug #68594 (Use after free vulnerability in unserialize()).
    (CVE-2014-8142) (Stefan Esser)
  . Fixed bug #68676 (Explicit Double Free). (Kalle)
  . Fixed bug #68710 (Use After Free Vulnerability in PHP's unserialize()).
    (CVE-2015-0231) (Stefan Esser)

- CGI:
  . Fixed bug #68618 (out of bounds read crashes php-cgi).(CVE-2014-9427)
    (Stas)

- CLI server:
  . Fixed bug #68745 (Invalid HTTP requests make web server segfault). (Adam)

- cURL:
  . Fixed bug #67643 (curl_multi_getcontent returns '' when
    CURLOPT_RETURNTRANSFER isn't set). (Jille Timmermans)

- EXIF:
  . Fixed bug #68799: Free called on unitialized pointer. (CVE-2015-0232)
    (Stas)

- Fileinfo:
  . Fixed bug #68671 (incorrect expression in libmagic).
    (Joshua Rogers, Anatol Belski)
  . Removed readelf.c and related code from libmagic sources
    (Remi, Anatol)
  . Fixed bug #68735 (fileinfo out-of-bounds memory access).
    (Anatol)

- FPM:
  . Fixed bug #68751 (listen.allowed_clients is broken). (Remi)

- GD:
  . Fixed bug #68601 (buffer read overflow in gd_gif_in.c). (Jan Bee, Remi)

- Mbstring:
  . Fixed bug #68504 (--with-libmbfl configure option not present on Windows).
    (Ashesh Vashi)

- Mcrypt:
  . Fixed possible read after end of buffer and use after free. (Dmitry)

- Opcache:
  . Fixed bug #67111 (Memory leak when using "continue 2" inside two foreach
    loops). (Nikita)

- OpenSSL:
  . Fixed bug #55618 (use case-insensitive cert name matching). (Daniel Lowrey)

- Pcntl:
  . Fixed bug #60509 (pcntl_signal doesn't decrease ref-count of old handler
    when setting SIG_DFL). (Julien)

- PCRE:
  . Fixed bug #66679 (Alignment Bug in PCRE 8.34 upstream).
    (Rainer Jung, Anatol Belski)

- pgsql:
  . Fixed bug #68697 (lo_export return -1 on failure). (Ondřej Surý)

- PDO:
  . Fixed bug #68371 (PDO#getAttribute() cannot be called with platform-specific
    attribute names). (Matteo)

- PDO_mysql:
  . Fixed bug #68424 (Add new PDO mysql connection attr to control multi
    statements option). (peter dot wolanin at acquia dot com)

- SPL:
  . Fixed bug #66405 (RecursiveDirectoryIterator::CURRENT_AS_PATHNAME
    breaks the RecursiveIterator). (Paul Garvin)
  . Fixed bug #65213 (cannot cast SplFileInfo to boolean) (Tjerk)
  . Fixed bug #68479 (Added escape parameter to SplFileObject::fputcsv). (Salathe)

- SQLite:
  . Fixed bug #68120 (Update bundled libsqlite to 3.8.7.2). (Anatol)

- Streams:
  . Fixed bug #68532 (convert.base64-encode omits padding bytes).
    (blaesius at krumedia dot de)
2015-01-23 16:10:34 +00:00
taca
f02c689193 Update to php54 to 5.4.37.
22 Jan 2015 PHP 5.4.37
- Core:
  . Fixed bug #68710 (Use After Free Vulnerability in PHP's unserialize()).
    (CVE-2015-0231) (Stefan Esser)

- CGI:
  . Fixed bug #68618 (out of bounds read crashes php-cgi). (CVE-2014-9427)
    (Stas)

- EXIF:
  . Fixed bug #68799: Free called on unitialized pointer. (CVE-2015-0232) (Stas)

- Fileinfo:
  . Removed readelf.c and related code from libmagic sources
    (Remi, Anatol)
  . Fixed bug #68735 (fileinfo out-of-bounds memory access).
    (Anatol)

- OpenSSL:
  . Fixed bug #55618 (use case-insensitive cert name matching).
    (Daniel Lowrey)
2015-01-23 16:09:26 +00:00
wiz
1471d10b05 Rename strtoi to vlc_strtoi to avoid conflict with NetBSD built-in
function strtoi.
From Kamil Rytarowski <n54@gmx.com>.
2015-01-23 16:01:40 +00:00
joerg
b5c94e3a8c Explicitly export ANT_OPTS to make sure they are visible. 2015-01-23 15:43:45 +00:00
joerg
8b86c9cf15 Don't depend on the optimizer inlining a function to get immediates in
inline asm, clang 3.6+ explicitly checks and rejects this.
2015-01-23 15:10:51 +00:00
joerg
ab75586cc9 Not MAKE_JOBS_SAFE. 2015-01-23 15:09:26 +00:00
joerg
6708bba9df Rename private strtoi function. Bump revision. 2015-01-23 15:07:53 +00:00
joerg
962855d175 Rename local strtoi function. 2015-01-23 15:06:44 +00:00
joerg
211ffd2618 Apply strtoi fix for NetBSD/current to all PostgreSQL versions. 2015-01-23 15:06:00 +00:00
hauke
7d75382c00 Patches to build on SunOS (OI here)
Declare license
2015-01-23 14:31:38 +00:00
wiz
e1aeeaa79a Fix build with cmake-3.1. 2015-01-23 14:09:36 +00:00
wiz
0032e44c4f Updated mail/dovecot to 1.2.17nb15 2015-01-23 12:17:56 +00:00
wiz
c98b0b6cf2 Fix for CVE-2014-3430.
Based on http://hg.dovecot.org/dovecot-1.2/raw-rev/8ba4253adc9b
adapted to pkgsrc by Edgar Fuß in PR 49599.
Bump PKGREVISION.

regen patch-ab while here
2015-01-23 12:17:47 +00:00
jdc
7ca43c7e4b Update for build fix for big-endian hosts patch. 2015-01-23 11:28:41 +00:00
jdc
2e362c70f7 Add build fix for big-endian hosts (sent upstream). 2015-01-23 11:26:40 +00:00
obache
b3c05d84e5 Updated emulators/suse131_libdbus to 13.1nb6 2015-01-23 10:34:18 +00:00
obache
ac2517ed34 Apply following update for suse131_libdbus, bump PKGREVISION.
openSUSE Security Update: Security update for dbus-1
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2015:0111-1
Rating:             moderate
References:         #912016
Cross-References:   CVE-2012-3524 CVE-2014-8148
Affected Products:
                    openSUSE 13.2
                    openSUSE 13.1
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.

Description:


         This update fixes the following security issues:
     * CVE-2014-8148:
       - Do not allow calls to UpdateActivationEnvironment from uids
         other than the uid of the dbus-daemon. If a system service installs
   unsafe security policy rules that allow arbitrary method calls (such as
   CVE-2014-8148) then this prevents memory consumption and possible
   privilege escalation via UpdateActivationEnvironment.
    * CVE-2012-3524: Don't access environment variables (bnc#912016)

References:

   http://support.novell.com/security/cve/CVE-2012-3524.html
   http://support.novell.com/security/cve/CVE-2014-8148.html
   https://bugzilla.suse.com/show_bug.cgi?id=912016
2015-01-23 10:34:08 +00:00
wiz
a527090fa9 Remove c from USE_LANGUAGES, this is C++ source code. 2015-01-23 10:12:44 +00:00
wiz
d1713f8686 Add some bug report URLs. 2015-01-23 10:11:47 +00:00
wiz
2ac58a2a9b Update HOMEPAGE. 2015-01-23 09:50:55 +00:00
obache
dfeec74657 Updated math/ruby-spreadsheet to 1.0.1 2015-01-23 08:30:53 +00:00
obache
b816eece03 Update ruby-spreadsheet to 1.0.1.
### 1.0.1 / 22.01.2015

* Fixing Excel::Worksheet#dimensions
2015-01-23 08:30:45 +00:00
obache
14b8bc4e55 tell pidfile name 2015-01-23 08:09:37 +00:00
obache
f8314ecd70 PYVERSSUFFIX also must be in FILES_SUBST, for ALTERNATIVES. 2015-01-23 07:07:42 +00:00
obache
bc8c0a3ff6 canonicalize HOMEPAGE url. 2015-01-23 06:58:42 +00:00
obache
f61af0fde3 Simplify MASTER_SITES subdirectory. 2015-01-23 06:52:03 +00:00
obache
64cdfeec3d Simplify MASTER_SITES subdirectory, and change HOMEPAGE to same as others. 2015-01-23 06:50:07 +00:00
obache
191488f208 Simplify MASTER_SITES subdirectory, and change HOMEPAGE to permalink. 2015-01-23 06:48:12 +00:00
obache
3c3fce2920 Simplify MASTER_SITES subdirectory, change HOMEPAGE url to same as others. 2015-01-23 06:43:56 +00:00
obache
e899de84ae Simplify MASTER_SITES subdirectory. 2015-01-23 06:38:14 +00:00
obache
c5e1a7d221 simplify MASTER_SITES subdirectory, and canonicalize HOMEPAGE url. 2015-01-23 06:33:36 +00:00
obache
c811308510 simplify MASTER_SITES subdirectory. 2015-01-23 06:22:20 +00:00
obache
6c28c75dd3 Updated multimedia/adobe-flash-plugin11 to 11.2.202.438 2015-01-23 06:08:48 +00:00
obache
dd62605ec5 Update adobe-flash-plugin11 to 11.2.202.438 for APSB15-02. 2015-01-23 06:08:40 +00:00
wiz
89005d9db1 Updated devel/cmake to 3.1.0nb1 2015-01-23 04:06:17 +00:00