openSUSE Security Update: nut: fixed a denial of service
______________________________________________________________________________
Announcement ID: openSUSE-SU-2012:1069-1
Rating: low
References: #764699
Cross-References: CVE-2012-2944
Affected Products:
openSUSE 12.2
openSUSE 12.1
openSUSE 11.4
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
The nut upsd is prone to multiple flaws that allow remote
attackers to cause a denial of service (application crash)
by sending unexpected data.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.2:
zypper in -t patch openSUSE-2012-539
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-539
- openSUSE 11.4:
zypper in -t patch openSUSE-2012-539
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.2 (i586 x86_64):
libupsclient1-2.6.3-2.4.3
libupsclient1-debuginfo-2.6.3-2.4.3
nut-2.6.3-2.4.3
nut-cgi-2.6.3-2.4.3
nut-cgi-debuginfo-2.6.3-2.4.3
nut-debuginfo-2.6.3-2.4.3
nut-debugsource-2.6.3-2.4.3
nut-devel-2.6.3-2.4.3
nut-drivers-net-2.6.3-2.4.3
nut-drivers-net-debuginfo-2.6.3-2.4.3
- openSUSE 12.1 (i586 x86_64):
libupsclient1-2.6.1-3.4.1
libupsclient1-debuginfo-2.6.1-3.4.1
nut-2.6.1-3.4.1
nut-cgi-2.6.1-3.4.1
nut-cgi-debuginfo-2.6.1-3.4.1
nut-debuginfo-2.6.1-3.4.1
nut-debugsource-2.6.1-3.4.1
nut-devel-2.6.1-3.4.1
nut-drivers-net-2.6.1-3.4.1
nut-drivers-net-debuginfo-2.6.1-3.4.1
- openSUSE 11.4 (i586 x86_64):
libupsclient1-2.6.0-4.11.1
libupsclient1-debuginfo-2.6.0-4.11.1
nut-2.6.0-4.11.1
nut-cgi-2.6.0-4.11.1
nut-cgi-debuginfo-2.6.0-4.11.1
nut-classic-2.6.0-4.11.1
nut-classic-debuginfo-2.6.0-4.11.1
nut-debuginfo-2.6.0-4.11.1
nut-debugsource-2.6.0-4.11.1
nut-devel-2.6.0-4.11.1
nut-drivers-net-2.6.0-4.11.1
nut-drivers-net-debuginfo-2.6.0-4.11.1
nut-hal-2.6.0-4.11.1
nut-hal-debuginfo-2.6.0-4.11.1
References:
http://support.novell.com/security/cve/CVE-2012-2944.htmlhttps://bugzilla.novell.com/764699
openSUSE Security Update: tor: fixed some security bugs
______________________________________________________________________________
Announcement ID: openSUSE-SU-2012:1068-1
Rating: moderate
References: #776642
Cross-References: CVE-2012-3517 CVE-2012-3518 CVE-2012-3519
Affected Products:
openSUSE 12.2
______________________________________________________________________________
An update that fixes three vulnerabilities is now available.
Description:
Tor 0.2.2.38 fixes a rare race condition that can crash
exit relays; fixes a remotely triggerable crash bug; and
fixes a timing attack that could in theory leak path
information.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.2:
zypper in -t patch openSUSE-2012-541
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.2 (i586 x86_64):
tor-0.2.2.38-3.4.1
tor-debuginfo-0.2.2.38-3.4.1
tor-debugsource-0.2.2.38-3.4.1
References:
http://support.novell.com/security/cve/CVE-2012-3517.htmlhttp://support.novell.com/security/cve/CVE-2012-3518.htmlhttp://support.novell.com/security/cve/CVE-2012-3519.htmlhttps://bugzilla.novell.com/776642
openSUSE Security Update: openttd: update to 1.2.2
______________________________________________________________________________
Announcement ID: openSUSE-SU-2012:1063-1
Rating: low
References: #775023
Cross-References: CVE-2012-3436
Affected Products:
openSUSE 12.2
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
openttd was updated to 1.2.2
- many bugfixes including: Fix: In some cases ships could
be covered with land [FS#5254] (CVE-2012-3436,
bnc#775023)
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.2:
zypper in -t patch openSUSE-2012-537
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.2 (i586 x86_64):
openttd-1.2.2-2.4.1
openttd-debuginfo-1.2.2-2.4.1
openttd-dedicated-1.2.2-2.4.1
openttd-dedicated-debuginfo-1.2.2-2.4.1
- openSUSE 12.2 (noarch):
openttd-data-1.2.2-2.4.1
References:
http://support.novell.com/security/cve/CVE-2012-3436.htmlhttps://bugzilla.novell.com/775023
openSUSE Security Update: phpMyAdmin: update to 3.5.2.2
______________________________________________________________________________
Announcement ID: openSUSE-SU-2012:1062-1
Rating: moderate
References: #776698 #776701
Cross-References: CVE-2012-4219 CVE-2012-4345
Affected Products:
openSUSE 12.2
openSUSE 12.1
______________________________________________________________________________
An update that fixes two vulnerabilities is now available.
Description:
phpMyAdmin was updated to 3.5.2.2
- fix for bnc#776698, bnc#776701
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.2:
zypper in -t patch openSUSE-2012-535
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-535
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.2 (noarch):
phpMyAdmin-3.5.2.2-1.4.1
- openSUSE 12.1 (noarch):
phpMyAdmin-3.5.2.2-1.27.1
References:
http://support.novell.com/security/cve/CVE-2012-4219.htmlhttp://support.novell.com/security/cve/CVE-2012-4345.htmlhttps://bugzilla.novell.com/776698https://bugzilla.novell.com/776701
openSUSE Security Update: calligra: security and bugfix update.
______________________________________________________________________________
Announcement ID: openSUSE-SU-2012:1061-1
Rating: important
References: #774534
Cross-References: CVE-2012-3456
Affected Products:
openSUSE 12.2
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
Fix buffer overflow in MS Word ODF filter among other
non-security related bugs.
Also a version update to 2.4.3 happened:
* Words:
- Always show vertical scroll bar to avoid race
condition (kde#301076)
- Do not save with an attribue that makes LibreOffice
and OpenOffice crash (kde#298689 )
* Kexi:
- Fixed import from csv when “Start at Line” value
changed (kde#302209)
- Set limit to 255 characters for Text type (VARCHAR)
(kde#301277 and 301136)
+ - Remove limits for Text data type, leave as option
(kde#301277)
- Fixed data saving when focus policy for one of
widgets is NoFocus (kde#301109)
* Krita:
- Read and set the resolution for psd images
* Charts:
- Fix load/save styles of all shapes
(title,subtitle,axistitles,footer,etc.)
- Lines in the chart should be displayed (kde#271771)
- Combined Bar and Line Charts only show bars
(Trendlines not supported) (kde#288537)
- Load/save chart type for each dataset (kde#271771 and
288537)
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.2:
zypper in -t patch openSUSE-2012-533
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.2 (i586 x86_64):
calligra-2.4.3-2.4.1
calligra-braindump-2.4.3-2.4.1
calligra-braindump-debuginfo-2.4.3-2.4.1
calligra-debuginfo-2.4.3-2.4.1
calligra-debugsource-2.4.3-2.4.1
calligra-devel-2.4.3-2.4.1
calligra-flow-2.4.3-2.4.1
calligra-flow-debuginfo-2.4.3-2.4.1
calligra-karbon-2.4.3-2.4.1
calligra-karbon-debuginfo-2.4.3-2.4.1
calligra-kexi-2.4.3-2.4.1
calligra-kexi-debuginfo-2.4.3-2.4.1
calligra-kexi-mssql-driver-2.4.3-2.4.1
calligra-kexi-mssql-driver-debuginfo-2.4.3-2.4.1
calligra-kexi-mysql-driver-2.4.3-2.4.1
calligra-kexi-mysql-driver-debuginfo-2.4.3-2.4.1
calligra-kexi-postgresql-driver-2.4.3-2.4.1
calligra-kexi-postgresql-driver-debuginfo-2.4.3-2.4.1
calligra-kexi-spreadsheet-import-2.4.3-2.4.1
calligra-kexi-spreadsheet-import-debuginfo-2.4.3-2.4.1
calligra-kexi-xbase-driver-2.4.3-2.4.1
calligra-kexi-xbase-driver-debuginfo-2.4.3-2.4.1
calligra-krita-2.4.3-2.4.1
calligra-krita-debuginfo-2.4.3-2.4.1
calligra-kthesaurus-2.4.3-2.4.1
calligra-kthesaurus-debuginfo-2.4.3-2.4.1
calligra-plan-2.4.3-2.4.1
calligra-plan-debuginfo-2.4.3-2.4.1
calligra-sheets-2.4.3-2.4.1
calligra-sheets-debuginfo-2.4.3-2.4.1
calligra-stage-2.4.3-2.4.1
calligra-stage-debuginfo-2.4.3-2.4.1
calligra-tools-2.4.3-2.4.1
calligra-tools-debuginfo-2.4.3-2.4.1
calligra-words-2.4.3-2.4.1
calligra-words-debuginfo-2.4.3-2.4.1
- openSUSE 12.2 (noarch):
calligra-doc-2.4.3-2.4.1
References:
http://support.novell.com/security/cve/CVE-2012-3456.htmlhttps://bugzilla.novell.com/774534
openSUSE Security Update: koffice: Fix buffer overflow in MS Word ODF import filter
______________________________________________________________________________
Announcement ID: openSUSE-SU-2012:1060-1
Rating: moderate
References: #774533
Cross-References: CVE-2012-3455
Affected Products:
openSUSE 12.1
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update fixes a buffer overflow in MS Word ODF import
filter.
Patch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 12.1:
zypper in -t patch openSUSE-2012-532
To bring your system up-to-date, use "zypper patch".
Package List:
- openSUSE 12.1 (i586 x86_64):
koffice2-2.3.1-12.4.1
koffice2-debuginfo-2.3.1-12.4.1
koffice2-debugsource-2.3.1-12.4.1
koffice2-devel-2.3.1-12.4.1
koffice2-karbon-2.3.1-12.4.1
koffice2-karbon-debuginfo-2.3.1-12.4.1
koffice2-kexi-2.3.1-12.4.1
koffice2-kexi-debuginfo-2.3.1-12.4.1
koffice2-kformula-2.3.1-12.4.1
koffice2-kformula-debuginfo-2.3.1-12.4.1
koffice2-kplato-2.3.1-12.4.1
koffice2-kplato-debuginfo-2.3.1-12.4.1
koffice2-kpresenter-2.3.1-12.4.1
koffice2-kpresenter-debuginfo-2.3.1-12.4.1
koffice2-krita-2.3.1-12.4.1
koffice2-krita-debuginfo-2.3.1-12.4.1
koffice2-kspread-2.3.1-12.4.1
koffice2-kspread-debuginfo-2.3.1-12.4.1
koffice2-kthesaurus-2.3.1-12.4.1
koffice2-kthesaurus-debuginfo-2.3.1-12.4.1
koffice2-kword-2.3.1-12.4.1
koffice2-kword-debuginfo-2.3.1-12.4.1
- openSUSE 12.1 (noarch):
koffice2-doc-2.3.1-12.4.1
References:
http://support.novell.com/security/cve/CVE-2012-3455.htmlhttps://bugzilla.novell.com/774533