ArchLinux Essential and Critical Security Patch Updates - Page 84
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
The package tinyproxy before version 1.8.4-1 is vulnerable to denial of service.
The package samba before version 4.1.16-1 is vulnerable to privilege elevation when an Active Directory Domain Controller is configured.
The package curl before version 7.40.0-1 is vulnerable to an URL request injection issue when using a HTTP proxy.
The package flashplugin before version 11.2.202.429-1 is vulnerable to multiple issues, including but not limited to remote code execution.
The package thunderbird before version 31.4.0-1 is vulnerable to multiple issues, that Mozilla believes not to be exploitable through email. Upgrading is still advised.
The package firefox before version 35.0-1 is vulnerable to multiple issues, including but not limited to remote code execution.
The package cpio before version 2.11-5 is vulnerable to a heap buffer overflow.
The package libevent before version 2.0.22-1 is vulnerable to a potential heap overflow.
The package unzip before version 6.0-9 is vulnerable to arbitrary code execution and denial of service through multiple heap buffer overflows.
The package openssl before version 1.0.1.k-1 is vulnerable to multiple issues, including but not limited to denial of service, cipher downgrade, certificate verification bypass and certificate fingerprint modification.
The package imagemagick before version 6.9.0.3-1 is vulnerable to multiple issues, including denial of service and arbitrary code execution.
The package ntp before version 4.2.8-1 is vulnerable to multiple issues including but not limited to arbitrary code execution, denial of service and weak key generation.
The package php before version 5.6.4-1 is suffering from a use after free flaw leading to denial of service and possibly arbitrary code execution.
The package jasper before version 1.900.1-12 is vulnerable to arbitrary code execution and denial of service.
The packages glibc and lib32-glibc before version 2.20-5 are vulnerable to arbitrary code execution and denial of service.
The package unrtf before version 0.21.7-1 is vulnerable to arbitrary code execution.
The package dokuwiki before version 20140929_b-1 is vulnerable to cross-site scripting.
The package nss before version 3.17.3-1 is vulnerable to signature forgery.
The package subversion before version 1.8.11-1 is vulnerable to denial of service in mod_dav_svn through multiple remotely triggerable crashes.
The package docker before version 1:1.4.0-1 is vulnerable to multiple issues including but not limited to privilege escalation and path traversal.