Re: [Mageia-dev] possible security issues affecting Cauldron (please help)

2013-04-06 Thread David Walser
Thanks to Funda and Guillaume for fixing the 4 new ones from Thursday.

There's one new one from Friday added to the bottom of the list.

David Walser wrote:
 
 mediawiki needs updated:
 https://bugs.mageia.org/show_bug.cgi?id=3448
 
 v8 needs updated:
 https://bugs.mageia.org/show_bug.cgi?id=8567
 
 libvirt CVE-2013-1766 (see comment 11):
 https://bugs.mageia.org/show_bug.cgi?id=6526
  
 not sure if all issues in xen are fixed:
 https://bugs.mageia.org/show_bug.cgi?id=6931
 
 util-linux CVE-2013-0157:
 https://bugs.mageia.org/show_bug.cgi?id=8615
 
 nginx possible spec change needed:
 https://bugs.mageia.org/show_bug.cgi?id=9268
 
 openstack-keystone CVE-2013-1865:
 https://bugs.mageia.org/show_bug.cgi?id=9473

Just added
--

subversion needs updated to 1.7.9:
https://bugs.mageia.org/show_bug.cgi?id=9624



Re: [Mageia-dev] possible security issues affecting Cauldron (please help)

2013-04-05 Thread Guillaume Rousse

Le 04/04/2013 19:05, David Walser a écrit :

Just added
--

nrpe CVE-2013-1362:
https://bugs.mageia.org/show_bug.cgi?id=9615

ffmpeg needs updated to 1.1.4:
https://bugs.mageia.org/show_bug.cgi?id=9616

postgresql packages need updated:
https://bugs.mageia.org/show_bug.cgi?id=9617

puppet needs updated to 2.7.21:
http://lwn.net/Vulnerabilities/542701/

Done for all four of them.

--
BOFH excuse #42:

spaghetti cable cause packet failure


Re: [Mageia-dev] possible security issues affecting Cauldron (please help)

2013-04-04 Thread David Walser
And of course as soon as I send this a bunch of new ones show up today.

See the bottom for the additional ones.

mediawiki needs updated:
https://bugs.mageia.org/show_bug.cgi?id=3448

v8 needs updated:
https://bugs.mageia.org/show_bug.cgi?id=8567

libvirt CVE-2013-1766 (see comment 11):
https://bugs.mageia.org/show_bug.cgi?id=6526
 
not sure if all issues in xen are fixed:
https://bugs.mageia.org/show_bug.cgi?id=6931

util-linux CVE-2013-0157:
https://bugs.mageia.org/show_bug.cgi?id=8615

nginx possible spec change needed:
https://bugs.mageia.org/show_bug.cgi?id=9268

openstack-keystone CVE-2013-1865:
https://bugs.mageia.org/show_bug.cgi?id=9473

Just added
--

nrpe CVE-2013-1362:
https://bugs.mageia.org/show_bug.cgi?id=9615

ffmpeg needs updated to 1.1.4:
https://bugs.mageia.org/show_bug.cgi?id=9616

postgresql packages need updated:
https://bugs.mageia.org/show_bug.cgi?id=9617

puppet needs updated to 2.7.21:
http://lwn.net/Vulnerabilities/542701/