Lector de Noticias
MDVSA-2008:154: Updated xemacs packages fix vulnerability
A vulnerability in xemacs was found where an attacker could provide
a group of files containing local variable definitions and arbitrary
Lisp code to be executed when one of the provided files is opened by
xemacs (CVE-2008-2142).
The updated packages have been patched to correct this issue.
a group of files containing local variable definitions and arbitrary
Lisp code to be executed when one of the provided files is opened by
xemacs (CVE-2008-2142).
The updated packages have been patched to correct this issue.
Categorías: Actualizaciones de Seguridad
MDVSA-2008:153: Updated emacs packages fix vulnerability
A vulnerability in emacs was found where an attacker could provide
a group of files containing local variable definitions and arbitrary
Lisp code to be executed when one of the provided files is opened by
emacs (CVE-2008-2142).
The updated packages have been patched to correct this issue.
a group of files containing local variable definitions and arbitrary
Lisp code to be executed when one of the provided files is opened by
emacs (CVE-2008-2142).
The updated packages have been patched to correct this issue.
Categorías: Actualizaciones de Seguridad
MDVSA-2008:152: Updated wireshark packages fix denial of service vulnerability
A number of vulnerabilities were discovered in Wireshark that could
cause it to crash while processing malicious packets (CVE-2008-3137,
CVE-2008-3138, CVE-2008-3139, CVE-2008-3140, CVE-2008-3141,
CVE-2008-3145).
This update provides Wireshark 1.0.2, which is not vulnerable to
these issues.
cause it to crash while processing malicious packets (CVE-2008-3137,
CVE-2008-3138, CVE-2008-3139, CVE-2008-3140, CVE-2008-3141,
CVE-2008-3145).
This update provides Wireshark 1.0.2, which is not vulnerable to
these issues.
Categorías: Actualizaciones de Seguridad
MDVSA-2008:151: Updated libxslt packages fix buffer overflow vulnerability
A buffer overflow vulnerability in libxslt could be exploited via an
XSL style sheet file with a long XLST transformation match condition,
which could possibly lead to the execution of arbitrary code
(CVE-2008-1767).
The updated packages have been patched to correct this issue.
XSL style sheet file with a long XLST transformation match condition,
which could possibly lead to the execution of arbitrary code
(CVE-2008-1767).
The updated packages have been patched to correct this issue.
Categorías: Actualizaciones de Seguridad
MDVA-2008:106-1: Updated openoffice.org-voikko provides Finnish support for new OpenOffice.org
openoffice.org-voikko provides Finnish spellchecker and hyphenator
component for OpenOffice.org.
The package is being updated for the new OpenOffice.org version.
Update:
Due to a build error, the previous update for i586 architecture was
built against the old OpenOffice.org. This update fixes that.
component for OpenOffice.org.
The package is being updated for the new OpenOffice.org version.
Update:
Due to a build error, the previous update for i586 architecture was
built against the old OpenOffice.org. This update fixes that.
Categorías: Actualizaciones de Seguridad
MDVSA-2008:150: Updated mysql packages fix vulnerabilities
Multiple buffer overflows in yaSSL, which is used in MySQL, allowed
remote attackers to execute arbitrary code (CVE-2008-0226) or cause
a denial of service via a special Hello packet (CVE-2008-0227).
Sergei Golubchik found that MySQL did not properly validate optional
data or index directory paths given in a CREATE TABLE statement; as
well it would not, under certain conditions, prevent two databases
from using the same paths for data or index files. This could allow
an authenticated user with appropriate privilege to create tables in
one database to read and manipulate data in tables later created in
other databases, regardless of GRANT privileges (CVE-2008-2079).
The updated packages have been patched to correct these issues.
remote attackers to execute arbitrary code (CVE-2008-0226) or cause
a denial of service via a special Hello packet (CVE-2008-0227).
Sergei Golubchik found that MySQL did not properly validate optional
data or index directory paths given in a CREATE TABLE statement; as
well it would not, under certain conditions, prevent two databases
from using the same paths for data or index files. This could allow
an authenticated user with appropriate privilege to create tables in
one database to read and manipulate data in tables later created in
other databases, regardless of GRANT privileges (CVE-2008-2079).
The updated packages have been patched to correct these issues.
Categorías: Actualizaciones de Seguridad
MDVSA-2008:149: Updated mysql packages fix vulnerabilities
Sergei Golubchik found that MySQL did not properly validate optional
data or index directory paths given in a CREATE TABLE statement; as
well it would not, under certain conditions, prevent two databases
from using the same paths for data or index files. This could allow
an authenticated user with appropriate privilege to create tables in
one database to read and manipulate data in tables later created in
other databases, regardless of GRANT privileges (CVE-2008-2079).
The updated packages have been patched to correct this issue.
data or index directory paths given in a CREATE TABLE statement; as
well it would not, under certain conditions, prevent two databases
from using the same paths for data or index files. This could allow
an authenticated user with appropriate privilege to create tables in
one database to read and manipulate data in tables later created in
other databases, regardless of GRANT privileges (CVE-2008-2079).
The updated packages have been patched to correct this issue.
Categorías: Actualizaciones de Seguridad
MDVSA-2008:148: Updated Firefox packages fix vulnerabilities
Security vulnerabilities have been discovered and corrected in the
latest Mozilla Firefox program, version 2.0.0.16 (CVE-2008-2785,
CVE-2008-2933).
This update provides the latest Firefox to correct these issues.
latest Mozilla Firefox program, version 2.0.0.16 (CVE-2008-2785,
CVE-2008-2933).
This update provides the latest Firefox to correct these issues.
Categorías: Actualizaciones de Seguridad
MDVA-2008:109: Updated timezone packages provide updated DST information
Updated timezone packages are being provided for older Mandriva Linux
systems that do not contain the new Daylight Savings Time information
for 2008 and later for certain time zones. These updated packages
contain the new information.
systems that do not contain the new Daylight Savings Time information
for 2008 and later for certain time zones. These updated packages
contain the new information.
Categorías: Actualizaciones de Seguridad
MDVSA-2008:147: Updated pcre packages fix vulnerability
Tavis Ormandy of the Google Security Team discovered a heap-based
buffer overflow when compiling certain regular expression patterns.
This could be used by a malicious attacker by sending a specially
crafted regular expression to an application using the PCRE library,
resulting in the possible execution of arbitrary code or a denial of
service (CVE-2008-2371).
The updated packages have been patched to correct this issue.
buffer overflow when compiling certain regular expression patterns.
This could be used by a malicious attacker by sending a specially
crafted regular expression to an application using the PCRE library,
resulting in the possible execution of arbitrary code or a denial of
service (CVE-2008-2371).
The updated packages have been patched to correct this issue.
Categorías: Actualizaciones de Seguridad
MDVSA-2008:146: Updated poppler packages fix arbitrary code execution vulnerability
A memory management issue was found in libpoppler by Felipe Andres
Manzano that could allow for the execution of arbitrary code with
the privileges of the user running a poppler-based application,
if they opened a specially crafted PDF file (CVE-2008-2950).
The updated packages have been patched to correct this issue.
Manzano that could allow for the execution of arbitrary code with
the privileges of the user running a poppler-based application,
if they opened a specially crafted PDF file (CVE-2008-2950).
The updated packages have been patched to correct this issue.
Categorías: Actualizaciones de Seguridad
MDVA-2008:108: Updated x11-server packages fix offscreen pixmaps drawing issue
This x11-sever update disables offscreen pixmaps by default as they
were causing drawing issues with Firefox 3 and other applications.
To re-enable this option, use 'Option XaaOffscreenPixmaps on'
in xorg.conf.
were causing drawing issues with Firefox 3 and other applications.
To re-enable this option, use 'Option XaaOffscreenPixmaps on'
in xorg.conf.
Categorías: Actualizaciones de Seguridad
pyDict-0.2.5.1-14mdv2009.0.src.rpm
Olivier Blin 0.2.5.1-14mdv2009.0
+ Revision: 136445
- restore BuildRoot
+ Thierry Vignaud
- kill re-definition of %buildroot on Pixel's request
Categorías: RPMs
pygame-1.7.1-5mdv2009.0.src.rpm
Thierry Vignaud 1.7.1-5mdv2009.0
+ Revision: 242365
- rebuild
- kill re-definition of %buildroot on Pixel's request
+ Olivier Blin
- restore BuildRoot
Categorías: RPMs
python2.4-elementtree-1.2.6-3mdv2009.0.src.rpm
Thierry Vignaud 1.2.6-3mdv2009.0
+ Revision: 242384
- rebuild
- kill re-definition of %buildroot on Pixel's request
+ Olivier Blin
- restore BuildRoot
Categorías: RPMs
python-fchksum-1.7.1-7mdv2009.0.src.rpm
Thierry Vignaud 1.7.1-7mdv2009.0
+ Revision: 242396
- rebuild
- kill re-definition of %buildroot on Pixel's request
+ Olivier Blin
- restore BuildRoot
Categorías: RPMs
python-fuse-2.5-3mdv2009.0.src.rpm
Thierry Vignaud 2.5-3mdv2009.0
+ Revision: 242410
- rebuild
- kill re-definition of %buildroot on Pixel's request
+ Olivier Blin
- restore BuildRoot
Categorías: RPMs
mugshot-1.2.1-1mdv2009.0.src.rpm
Götz Waschk 1.2.1-1mdv2009.0
+ Revision: 242330
- new version
- update deps
- fix build
- drop patch
- remove library packages, now in desktop-data-model
- update file list
+ Pixel
- do not call ldconfig in %post/%postun, it is now handled by filetriggers
Categorías: RPMs
proxychains-3.1-3mdv2009.0.src.rpm
Thierry Vignaud 3.1-3mdv2009.0
+ Revision: 242357
- rebuild
- kill re-definition of %buildroot on Pixel's request
- fix summary-ended-with-dot
+ Pixel
- do not call ldconfig in %post/%postun, it is now handled by filetriggers
+ Olivier Blin
- restore BuildRoot
Categorías: RPMs
Propaganda-1-14mdv2009.0.src.rpm
Thierry Vignaud 1-14mdv2009.0
+ Revision: 242356
- rebuild
- kill re-definition of %buildroot on Pixel's request
+ Olivier Blin
- restore BuildRoot
Categorías: RPMs



