Репозиторий Sisyphus
Последнее обновление: 21 мая 2018 | Пакетов: 18347 | Посещений: 11529984
en ru br
Исправления уязвимостей

thunderbird-52.8.0-alt1   сборка Andrey Cherepanov, 2018-05-19


- New version (52.8.0).
- Enigmail 2.0.4.
- Fixes:
+ CVE-2018-5183 Backport critical security fixes in Skia
+ CVE-2018-5184 Full plaintext recovery in S/MIME via chosen-ciphertext attack
+ CVE-2018-5154 Use-after-free with SVG animations and clip paths
+ CVE-2018-5155 Use-after-free with SVG animations and text paths
+ CVE-2018-5159 Integer overflow and out-of-bounds write in Skia
+ CVE-2018-5161 Hang via malformed headers
+ CVE-2018-5162 Encrypted mail leaks plaintext through src attribute
+ CVE-2018-5170 Filename spoofing for external attachments
+ CVE-2018-5168 Lightweight themes can be installed without user interaction
+ CVE-2018-5178 Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
+ CVE-2018-5185 Leaking plaintext through HTML forms
+ CVE-2018-5150 Memory safety bugs fixed in Firefox 60, Firefox ESR 52.8, and Thunderbird 52.8
- Build in several threads.

glusterfs3-3.12.9-alt1   сборка Vitaly Lipatov, 2018-05-17


- new version 3.12.9 (with rpmrb script)
- CVE-2018-1088

curl-7.60.0-alt1.S1   сборка Anton Farygin, 2018-05-16


- 7.60.0
- fixes:
* CVE-2018-1000300 FTP shutdown response buffer overflow
* CVE-2018-1000301 RTSP bad headers buffer over-read

kernel-image-un-def-4.16.9-alt1   сборка Kernel Bot, 2018-05-16


- v4.16.9 (Fixes: CVE-2018-1000200)

postgresql10-10.4-alt1   сборка Alexei Takaseev, 2018-05-09


- 10.4
- Fix CVE-2018-1115

postgresql9.3-9.3.23-alt1   сборка Alexei Takaseev, 2018-05-09


- 9.3.23
- Fix CVE-2018-1115

postgresql9.4-9.4.18-alt1   сборка Alexei Takaseev, 2018-05-09


- 9.4.18
- Fix CVE-2018-1115

postgresql9.5-9.5.13-alt1   сборка Alexei Takaseev, 2018-05-09


- 9.5.13
- Fix CVE-2018-1115

postgresql9.6-1C-9.6.9-alt1   сборка Alexei Takaseev, 2018-05-09


- 9.6.9
- Fix CVE-2018-1115

postgresql9.6-9.6.9-alt1   сборка Alexei Takaseev, 2018-05-09


- 9.6.9
- Fix CVE-2018-1115

php5-5.6.36-alt1.S1   сборка Anton Farygin, 2018-05-08


- 5.6.33 (fixes: CVE-2018-10549, CVE-2018-10546, CVE-2018-10548, CVE-2018-10547, CVE-2018-10545, CVE-2018-7584)

libwebkitgtk4-2.20.2-alt1   сборка Yuri N. Sedunov, 2018-05-08


- 2.20.2 (fixed CVE-2018-4200)

adobe-flash-player-ppapi-29-alt1.S1   сборка Sergey V Turchin, 2018-05-07


- new version (ALT#34555)
- security fixes:
CVE-2018-4919, CVE-2018-4920, CVE-2018-4932, CVE-2018-4933,
CVE-2018-4934, CVE-2018-4935, CVE-2018-4936, CVE-2018-4937

kernel-image-std-pae-4.4.131-alt1   сборка Kernel Bot, 2018-05-06


- v4.4.131 (Fixes: CVE-2018-1093)

kernel-image-std-def-4.9.98-alt1   сборка Kernel Bot, 2018-05-06


- v4.9.98 (Fixes: CVE-2018-1093, CVE-2018-1108)

kernel-image-un-def-4.16.7-alt1   сборка Kernel Bot, 2018-05-06


- v4.16.7 (Fixes: CVE-2018-1093, CVE-2018-1108)

plasma5-kwallet-pam-5.12.5-alt1.S1   сборка Sergey V Turchin, 2018-05-03


- new version
- security fixes: CVE-2018-10380

kernel-image-std-pae-4.4.129-alt1   сборка Kernel Bot, 2018-04-24


- v4.4.129 (Fixes: CVE-2018-1092)

kernel-image-std-def-4.9.96-alt1   сборка Kernel Bot, 2018-04-24


- v4.9.96 (Fixes: CVE-2018-1092, CVE-2018-1108)

kernel-image-un-def-4.16.4-alt1   сборка Kernel Bot, 2018-04-24


- v4.16.4 (Fixes: CVE-2018-1092, CVE-2018-1094, CVE-2018-1095, CVE-2018-1108)

kernel-image-std-def-4.9.95-alt1   сборка Kernel Bot, 2018-04-21


- v4.9.95 (Fixes: CVE-2017-5715)

chromium-66.0.3359.117-alt1   сборка Alexey Gladkov, 2018-04-19


- New version (66.0.3359.117).
- Security fixes:
- CVE-2018-6085: Use after free in Disk Cache.
- CVE-2018-6086: Use after free in Disk Cache.
- CVE-2018-6087: Use after free in WebAssembly.
- CVE-2018-6088: Use after free in PDFium.
- CVE-2018-6089: Same origin policy bypass in Service Worker.
- CVE-2018-6090: Heap buffer overflow in Skia.
- CVE-2018-6091: Incorrect handling of plug-ins by Service Worker.
- CVE-2018-6092: Integer overflow in WebAssembly.
- CVE-2018-6093: Same origin bypass in Service Worker.
- CVE-2018-6094: Exploit hardening regression in Oilpan.
- CVE-2018-6095: Lack of meaningful user interaction requirement before file upload.
- CVE-2018-6096: Fullscreen UI spoof.
- CVE-2018-6097: Fullscreen UI spoof.
- CVE-2018-6098: URL spoof in Omnibox.
- CVE-2018-6099: CORS bypass in ServiceWorker.
- CVE-2018-6100: URL spoof in Omnibox.
- CVE-2018-6101: Insufficient protection of remote debugging prototol in DevTools .
- CVE-2018-6102: URL spoof in Omnibox.
- CVE-2018-6103: UI spoof in Permissions.
- CVE-2018-6104: URL spoof in Omnibox.
- CVE-2018-6105: URL spoof in Omnibox.
- CVE-2018-6106: Incorrect handling of promises in V8.
- CVE-2018-6107: URL spoof in Omnibox.
- CVE-2018-6108: URL spoof in Omnibox.
- CVE-2018-6109: Incorrect handling of files by FileAPI.
- CVE-2018-6110: Incorrect handling of plaintext files via file:// .
- CVE-2018-6111: Heap-use-after-free in DevTools.
- CVE-2018-6112: Incorrect URL handling in DevTools.
- CVE-2018-6113: URL spoof in Navigation.
- CVE-2018-6114: CSP bypass.
- CVE-2018-6115: SmartScreen bypass in downloads.
- CVE-2018-6116: Incorrect low memory handling in WebAssembly.
- CVE-2018-6117: Confusing autofill settings.
- CVE-2018-6084: Incorrect use of Distributed Objects in Google Software Updater on MacOS.

kernel-image-std-def-4.9.93-alt1   сборка Kernel Bot, 2018-04-09


- v4.9.93 (Fixes: CVE-2017-5754)

acpica-20180209-alt1.S1   сборка Alexey Shabalin, 2018-04-02


- 20180209
- Fixes:
+ CVE-2017-13693
+ CVE-2017-13694
+ CVE-2017-13695

kernel-image-std-pae-4.4.126-alt1   сборка Kernel Bot, 2018-04-01


- v4.4.126 (Fixes: CVE-2017-8824)
 
дизайн и разработка: Vladimir Lettiev aka crux © 2004-2005, Andrew Avramenko aka liks © 2007-2008
текущий майнтейнер: Michael Shigorin