Репозиторий Sisyphus
Последнее обновление: 13 марта 2010 | Пакетов: 9708 | Посещений: 1893212
en ru br
Исправления уязвимостей

tar-1.23-alt1   сборка Dmitry V. Levin, 2010-03-10


- Updated to 1.23 (fixes CVE-2010-0624).

libpng-1.2.43-alt1   сборка Dmitry V. Levin, 2010-03-09


- Updated to 1.2.43 (fixes CVE-2010-0205).

transmission-1.76-alt3   сборка Anton Farygin, 2010-02-24


- add patches from upstream 1.7x branch with fix for CVE-2010-0012 (closes: #23019)

sudo-1.6.8p12-alt7   сборка Dmitry V. Levin, 2010-02-23


- Backported upstream fix for CVE-2010-0426 (a flaw in sudoedit could
give a user with permission to run sudoedit the ability to run
arbitrary commands).

sendmail-8.14.4-alt1   сборка Sergey Y. Afonin, 2010-02-22


- New version, security update (CVE-2009-4565)
addition: look to Errata 2010-01-04 on http://www.sendmail.org/releases/8.14.4
if used FEATURE(`ldap_routing')

pidgin-2.6.6-alt1   сборка Alexey Shabalin, 2010-02-22


- 2.6.6:
+ Fixes a remote MSN SLP crash (CVE-2010-0277) (Closes: #566775)
+ Fixes a remote Finch XMPP crash (CVE-2010-0420)
+ Fixes a remote smiley freeze/CPU pegging DoS (CVE-2010-0423)
- drop %add_findprov_lib_path for %_libdir/pidgin %_libdir/purple-2 %_libdir/finch

otrs-2.4.7-alt1   сборка Pavel Zilke, 2010-02-21


- Security fixes:
+ Vulnerability in OTRS-Core allows SQL-Injection; CVE-2010-0438 (ALT #22947)

netpbm-10.35.73-alt1   сборка Vladimir Lettiev, 2010-02-12


- 10.35.32 -> 10.35.73
+ fixed stack-based buffer overflow (CVE-2009-4274)
- build fixes
+ netpbm-10.35-alt-fix-overflow-destination-buffer.patch
+ netpbm-10.35-alt-fix-userguide-name.patch
- patches merged upstream
+ netpbm-10.33-alt-ppmquantall-syntax.patch
+ netpbm-10.35-rh-pbmtog3-segv.patch
+ netpbm-10.35-rh-pbmtomacp.patch
- sync RedHat patches (10.35.58)
+ netpbm-10.34-rh-security-overflows.patch updated
+ netpbm-10.35-rh-pnmtofiascoleaks.patch (new)
+ netpbm-10.35-rh-docfix.patch (new)
+ netpbm-10.35-rh-glibc.patch (new)
+ netpbm-10.17-rh-time.patch (new)
+ netpbm-10.35-rh-ximtoppmsegfault.patch (new)
+ netpbm-10.35-rh-rgbtxt.patch (new)
+ netpbm-10.35-rh-pnmmontagefix.patch (new)
+ netpbm-10.35-rh-64bitfix.patch (new)
+ netpbm-9.24-rh-strip.patch (new)
+ netpbm-10.35-rh-svgtopam.patch (new)
+ netpbm-10.33-rh-multilib.patch (new)

chrony-1.24-alt1   сборка Victor Forsiuk, 2010-02-08


- 1.24. Contains security fixes for CVE-2010-0292, CVE-2010-0293, CVE-2010-0294.

arts-1.5.10-alt4   сборка Sergey V Turchin, 2010-02-05


- fix to compile (ALT#22891)
- fix CVE-2009-3736

kdelibs-3.5.10-alt12   сборка Sergey V Turchin, 2010-02-05


- update to lastest 3.5 branch
- fix CVE-2009-3736
- fix to build with new autoconf

asterisk1.6.1-1.6.1.14-alt1   сборка Denis Smirnov, 2010-02-04


- 1.6.1.14
- CVE-2010-0441

asterisk1.6.2-1.6.2.2-alt1   сборка Denis Smirnov, 2010-02-04


- 1.6.2.2
- CVE-2010-0441

lighttpd-1.4.25-alt1.svn.2710   сборка Vladimir V. Kamarzin, 2010-02-04


- Update to 2710 revision of 1.4.x branch.
- Security fix: CVE-2010-0295 (lighttpd Slow Request Denial of Service
Vulnerability).

asterisk1.6.0-1.6.0.22-alt1   сборка Denis Smirnov, 2010-02-04


- 1.6.0.22
- CVE-2010-0441

fuse-2.8.2-alt1   сборка Denis Smirnov, 2010-01-27


- 2.8.2
- CVE-2009-3297 (ALT #22834)

openttd-0.7.5-alt1   сборка Anton Farygin, 2010-01-27


- new version (CVE-2009-4007 fixed)

MySQL-5.0.89-alt1   сборка Anton Farygin, 2010-01-25


- new version (closes #18943)
- fixed CVE-2009-2446 from upstream (closes #20724)
- setup utf8 encoding instead of latin1 by default (closes #12390)
- include C99 aliasing violation patch from mythtv (closes #22452)
- removed username-length patch
- wait for mysqld shutdown (closes #22234)
- don't run initial setup mysql database if mysql.user table already exists

GraphicsMagick-1.3.8-alt1   сборка Slava Dubrovskiy, 2010-01-23


- New version
- Fix ALT (#22348)
- Change number of bits in a pixel quantum 8 -> 16
- Fix build with libfpx
- Security Fixes:
+ Fix for CVE-2009-1882 "Integer overflow in the XMakeImage function".
+ Fix lockup due to hanging in loop while parsing malformed
sub-image specification (SourceForge issue 2886560).
+ Libltdl: Updated libtool to 2.2.6b in order to fix security issue.
Resolves CVE-2009-3736 as it pertains to GraphicsMagick.
- Bug fixes:
+ -convolve, -recolor: Validate that user-provided matrix is square
when parsing -convolve and -recolor commands in order to avoid a
core dump.
+ CALS: Reading images taller than the image width resulted in a
failure.
+ ConstituteImage(), DispatchImage(): 'A' and 'T' should indicate
transparency and 'O' should indicate opacity. Behavior was
inconsistent. In some cases 'O' meant transparency while in other
cases it meant opacity. Also, in a few cases, matte was not
getting enabled in the image as it should.
+ DCRAW: Module name was not registered so modules based builds were
not supporting formats provided via 'dcraw'.
+ GetOptimalKernelWidth1D(), GetOptimalKernelWidth2D(): In the Q32
build, convolution kernel size was estimated incorrectly for large
sigmas on 32-bit systems due to arithmetic overflow. This could
cause wrong results for -convolve, -blur, -sharpen, and other
algorithms which use these functions.
+ Image Size: Fixed the ability to pass the image size via the
filename specification like "myfile.jpg[640x480]" rather than
needing to use -size.
+ IPTC: Blob data needed to be padded to an even size. Size is now
correctly reported.
+ IPTC: Returned IPTC string values were one character too short.
+ Large Files: Large pixel cache files were not working under GNU Linux.
+ JP2: Fixed some value scaling problems.
+ JP2: Fix possible crash at exit when Jasper is used by a modules build.
+ MPC: is_monochrome and is_grayscale flags were not managed
properly for the MPC coder.
+ PCL: Page was not always being ejected.
+ PNG: The png8 encoder would fail when trying to write a 1-color image.
+ PSD: PSD parser was confused by 0x0 pixel layers, resulting in
image data corruption of all following layers.
+ -rotate, -shear: Some internally-reported errors were potentially
being lost.
+ Subrange/stdin: Commands now support reading an image from stdin
in conjunction with a subrange specification (e.g. "-[1]").
+ Magick++ STL ShadeImage: Implementation was completely botched.
- New Features:
+ CALS Type 1 files may now be written (Work contributed by John
Sergeant). CALS support is dependent on the TIFF library.
+ GROUP4RAW encoder supports reading/writing RAW Group4 data.
+ JP2: JPEG 2000 may now be written in arbitrary bit depths ranging
from 2 to 16 rather than just 8 or 16.
+ JPEG: IJG JPEG library version 7 is now supported.
+ JPEG: Added jpeg:block-smoothing and jpeg:fancy-upsampling defines
to control these JPEG library options.
+ JPEG: Detect and apply colorspaces appropriately for ITU FAX JPEG.
+ Resource Limits: There is now a "threads" resource limit which
allows specifying the number of OpenMP threads which may be used,
similar to the OMP_NUM_THREADS environment variable.
+ TIFF: Allow CIELAB TIFF to be read.
+ MagickGetImageAttribute()/MagickSetImageAttribute(): New Wand
methods to support getting and setting an image attribute.
Contributed by Mikko Koppanen.
+ ClonePixelWand(): New Wand method to deep-copy an existing pixel wand.
+ ClonePixelWands(): New Wand method to deep-copy an array of
existing pixel wands.
+ MagickCdlImage(): New Wand method to apply the ASC CDL to an
image.
+ MagickGetImageBoundingBox(): New Wand method to return the crop
bounding box required to remove any solid-color border from the
image.
+ MagickGetImageFuzz(), MagickSetImageFuzz(): New Wand methods to
get and set the color comparison fuzz factor.
+ MagickHaldClutImage(): New Wand method to apply a Hald CLUT to an
image.
+ MagickSetResolution(): New Wand method to set the wand resolution.
+ MagickSetResolutionUnits(): New Wand method to set the wand
resolution units.

tomcat6-6.0.18-alt6_8jpp5   сборка Slava Semushin, 2010-01-14


- NMU
- Applied upstream patches to fix following vulnerabilities:
+ CVE-2009-0033: DoS when using Java AJP connector
(Closes: #20313)
+ CVE-2009-0580: User enumeration vulnerability with FORM authentication
(Closes: #20315)
+ CVE-2009-0781: XSS in calendar example

gzip-1.3.5-alt6   сборка Dmitry V. Levin, 2010-01-13


- Applied upstream fix for integer underflow bug (CVE-2010-0001).

fetchmail-6.3.13-alt1   сборка Afanasov Dmitry, 2010-01-01


- 6.3.13
+ new "softbounce" global option;
+ CVE-2009-2666: improper SSL/TLS X.509 certificates validation (fixed
in 6.3.11);
+ translation updates;
see NEWS for details.

ruby-1.9.1-alt1.r26040.1   сборка Alexey I. Froloff, 2009-12-29


- Fix String#ljust, String#rjust and String#center breakage after
CVE-2009-4124 fix

kdegraphics-3.5.10-alt4   сборка Sergey V Turchin, 2009-12-24


- update to lastest branch 3.5
- Security fixes:
- CVE-2009-0945
- CVE-2009-1709

netatalk-2.0.5-alt1   сборка Sergey Kurakin, 2009-12-22


- 2.0.5:
+ fix CVE-2008-5718
+ more bugfixes
 
design & coding: Vladimir Lettiev aka crux © 2004-2005
current maintainer: Andrew Avramenko aka liks © 2007-2008