LWN.net Logo

Security advisories for Monday

CentOS has updated firefox (multiple vulnerabilities).

Debian has updated courier-authlib (SQL injection), perl (fix regression in earlier security update), moodle (multiple vulnerabilities).

Fedora has updated openvpn (F8, F9: arbitrary code execution), seamonkey (F8, F9, F10: multiple vulnerabilities), roundcubemail (F8, F9, F10: denial of service), phpPgAdmin (F8, F9, F10: directory traversal), galeon (F8, F9, F10: multiple Gecko vulnerabilities), devhelp (F8, F9, F10: multiple Gecko vulnerabilities), epiphany-extensions (F8, F9, F10: multiple Gecko vulnerabilities), epiphany (F8, F9, F10: multiple Gecko vulnerabilities), firefox (F8, F9, F10: multiple Gecko vulnerabilities), cairo-dock (F8, F9: multiple Gecko vulnerabilities), chmsee (F8 , F9: multiple Gecko vulnerabilities), blam (F8, F9, F10: multiple Gecko vulnerabilities), Miro (F8, F9, F10: multiple Gecko vulnerabilities), liferea (F8: multiple Gecko vulnerabilities), kazehakase (F8, F9, F10: multiple Gecko vulnerabilities), ruby-gnome (F8, F9, F10: multiple Gecko vulnerabilities), gnome-python2-extras (F8, F9, F10: multiple Gecko vulnerabilities), gnome-web-photo (F8, F9, F10: multiple Gecko vulnerabilities), evolution-rss (F8, F9, F10: multiple Gecko vulnerabilities), yelp (F8, F9, F10: multiple Gecko vulnerabilities), openvrml (F8: multiple Gecko vulnerabilities), git (F8, F9, F10: privilege escalation), libvirt (F9, F10: read-only bypass), moodle (F9, F10: arbitrary code execution), drupal-views (F9, F10: SQL injection), gtkmozembedmm (F9: multiple Gecko vulnerabilities), google-gadgets (F9, F10: multiple Gecko vulnerabilities), xulrunner (F9, F10: multiple Gecko vulnerabilities), mozvoikko (F9, F10: multiple Gecko vulnerabilities), totem (F9: multiple Gecko vulnerabilities), mugshot (F9, F10: multiple Gecko vulnerabilities), rsyslog (F9, F10: multiple vulnerabilities), gecko-sharp2 (F10: multiple Gecko vulnerabilities), pcmanx-gtk2 (F10: multiple Gecko vulnerabilities), wordpress-mu (F10: cross-site scripting).

Gentoo has updated PowerDNS (multiple vulnerabilities), phpCollab (multiple vulnerabilities).

rPath has updated cups (multiple vulnerabilities).

SUSE has updated flash-player (arbitrary code execution).

Ubuntu has updated Blender (multiple vulnerabilities), imlib2 (arbitrary code execution), nagios (authentication bypass), nagios3 (multiple vulnerabilities).


(Log in to post comments)

Security advisories for Monday

Posted Dec 22, 2008 22:05 UTC (Mon) by sbergman27 (guest, #10767) [Link]

For clarity, the Fedora part could stand to be broken out into paragraphs.

Security advisories for Monday

Posted Dec 22, 2008 22:43 UTC (Mon) by danpb (subscriber, #4831) [Link]

I was thinking the packages should be listed alphabetically too, so you can more easily spot a specific package you're looking for

Security advisories for Monday

Posted Dec 22, 2008 23:38 UTC (Mon) by jspaleta (subscriber, #50639) [Link]

Maybe organized in paragraphs by reason as seen in the parentheses following the packagename and then alphabetical inside that group.

Because of how xulrunner is developed, many apps in Fedora get rebuilt when xulrunner needs to be updated because they make use of an unstable xulrunner API and not just the stable API.

LWN flags all of these with a common parenthetical comment sting, but the output format doesn't group these together.

A paragraph layout when multiple packages are updated for the same underlying reason might be helpful.

-jef

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds