Last updated 24 July 2024
Fixed bug (Uninitialized pointer in pharmakedirstream()). (CVE-2016-4343)
Sergey "Shnatsel" Davidoff reported a heap-based buffer overflow in Vala Gstreamer bindings in the Gst.MapInfo() function. Further details are available in the following Red Hat bug:
https://bugzilla.redhat.com/showbug.cgi?id=1177840
This issue was also reported via: https://bugzilla.gnome.org/showbug.cgi?id=678663
and fixed in the following commit:
https://git.gnome.org/browse/vala/commit/?id=3092537db65887e24a3d3e87a27caf9c5295e4f7
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
LibreSSL. Multiple issues were addressed by updating to libressl version 2.6.4.
The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandboxlinux/naclsandboxlinux.cc in Google Chrome before 42.0.2311.90 does not have RLIMITAS and RLIMITDATA limits for Native Client (aka NaCl) processes, which might make it easier for remote attackers to conduct row-hammer attacks or have unspecified other impact by leveraging the ability to run a crafted program in the NaCl sandbox.
Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.
The asn1getsequenceof function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointer in the asn1sequence linked list, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ASN.1 sequence in a certificate.
A vulnerability was found in cairo. A maliciously crafted file can cause out of bounds read in fillxrgb32lerpopaquespans function in cairo, thus crashing the software.
Upstream fix:
https://cgit.freedesktop.org/cairo/patch/src/cairo-image-compositor.c?id=5c82d91a5e15d29b1489dcb413b24ee7fdf59934
References:
http://seclists.org/oss-sec/2016/q1/675
External references:
https://mail.gnome.org/archives/gnome-announce-list/2015-March/msg00047.html