Frugalware Security Announcements (FSAs)

This is a list of security announcments that have been released for the current stable version of Frugalware

drupal7

  • Author: kikadf
  • Vulnerable: 7.22-2arcturus3
  • Unaffected: 7.22-2arcturus4

A denial of service vulnerability was discovered in Drupal, a fully-featured content management framework. A remote attacker could exploit this flaw to cause CPU and memory exhaustion and the site’s database to reach the maximum number of open connections, leading to the site becoming unavailable or unresponsive.

CVEs:

gpgme

  • Author: kikadf
  • Vulnerable: 1.3.1-5
  • Unaffected: 1.3.1-6arcturus1

Tomáš Trnka discovered a heap-based buffer overflow within the gpgsm status handler of GPGME, a library designed to make access to GnuPG easier for applications. An attacker could use this issue to cause an application using GPGME to crash (denial of service) or possibly to execute arbitrary code.

CVEs:

krb5

  • Author: kikadf
  • Vulnerable: 1.10.1-1
  • Unaffected: 1.10.1-2arcturus1

An unauthenticated remote attacker with the ability to inject packets into a legitimately established GSSAPI application session can cause a program crash due to invalid memory references when attempting to read beyond the end of a buffer. An unauthenticated remote attacker with the ability to inject packets into a legitimately established GSSAPI application session can cause a program crash due to invalid memory references when reading beyond the end of a buffer or by causing a null pointer dereference. An unauthenticated remote attacker with the ability to spoof packets appearing to be from a GSSAPI acceptor can cause a double-free condition in GSSAPI initiators (clients) which are using the SPNEGO mechanism, by returning a different underlying mechanism than was proposed by the initiator. An unauthenticated or partially authenticated remote attacker can cause a NULL dereference and application crash during a SPNEGO negotiation by sending an empty token as the second or later context token from initiator to acceptor. When kadmind is configured to use LDAP for the KDC database, an authenticated remote attacker can cause it to perform an out-of-bounds write (buffer overflow).

lzo

  • Author: kikadf
  • Vulnerable: 2.0.6-1
  • Unaffected: 2.0.6-1arcturus1

Don A. Bailey from Lab Mouse Security discovered an integer overflow flaw in the way the lzo library decompressed certain archives compressed with the LZO algorithm. An attacker could create a specially crafted LZO-compressed input that, when decompressed by an application using the lzo library, would cause that application to crash or, potentially, execute arbitrary code.

CVEs:

openssl

  • Author: kikadf
  • Vulnerable: 1.0.1-5arcturus5
  • Unaffected: 1.0.1-5arcturus6

Multiple vulnerabilities have been identified in OpenSSL, a Secure Sockets Layer toolkit, that may result in denial of service (application crash, large memory consumption), information leak, protocol downgrade. Additionally, a buffer overrun affecting only applications explicitly set up for SRP has been fixed.

CVEs:

wireshark

  • Author: kikadf
  • Vulnerable: 1.8.13-1arcturus1
  • Unaffected: 1.8.15-1arcturus1

Multiple vulnerabilities were discovered in the dissectors for Catapult DCT2000, IrDA, GSM Management, RLC ASN.1 BER, which could result in denial of service.

CVEs:

wordpress

  • Author: kikadf
  • Vulnerable: 3.9-1arcturus1
  • Unaffected: 3.9.2-1arcturus1

Multiple security issues have been discovered in Wordpress, a web blogging tool, resulting in denial of service or information disclosure.

CVEs: