Frugalware Security Announcements (FSAs)

This is a list of security announcments that have been released for the current stable version of Frugalware

wireshark

  • Author: kikadf
  • Vulnerable: 1.8.15-1arcturus1
  • Unaffected: 1.8.15-1arcturus2

Multiple vulnerabilities were discovered in the dissectors/parsers for SigComp UDVM, AMQP, NCP and TN5250, which could result in denial of service.

CVEs:

drupal6

  • Author: kikadf
  • Vulnerable: 6.33-1arcturus1
  • Unaffected: 6.34-1arcturus1

Aaron Averill discovered that a specially crafted request can give a user access to another user’s session, allowing an attacker to hijack a random session. Michael Cullum, Javier Nieto and Andres Rojas Guerrero discovered that the password hashing API allows an attacker to send specially crafted requests resulting in CPU and memory exhaustion.

CVEs:

drupal7

  • Author: kikadf
  • Vulnerable: 7.22-2arcturus5
  • Unaffected: 7.22-2arcturus6

Aaron Averill discovered that a specially crafted request can give a user access to another user’s session, allowing an attacker to hijack a random session. Michael Cullum, Javier Nieto and Andres Rojas Guerrero discovered that the password hashing API allows an attacker to send specially crafted requests resulting in CPU and memory exhaustion.

CVEs:

ruby

  • Author: kikadf
  • Vulnerable: 1.9.2-2
  • Unaffected: 1.9.2-3arcturus1

Off-by-one error in the encodes function in pack.c, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow. Tomas Hoger discovered that Ruby incorrectly handled XML entity expansion.

CVEs: