- Previous versions of cyrus-imapd would not allow its users to disable old protocols like SSLv1 and SSLv2 that are unsafe due to various known attacks like BEAST and POODLE. https://bugzilla.cyrusimap.org/show_bug.cgi?id=3867 remedies this issue by adding the configuration option "tls_versions" to the imapd.conf file. Note that users who upgrade existing installation of this package will *not* ha ...

Specially crafted JPEG2000 files could cause a heap buffer overflow in jasper

This update adds openssl patches since 2007 for: - CVE-2008-5077 - CVE-2009-0590 - CVE-2009-0789 - CVE-2009-3555 - CVE-2010-4180

This update fixes the following security issues: - 718056: OSPF6D buffer overflow while decoding Link State Update with Inter Area Prefix Lsa - 718058: OSPF6D DoS while decoding Database Description packet - 718059: OSPFD DoS while decoding Hello packet - 718061: OSPFD DoS while decoding Link State Update - 718062: DoS while decoding EXTENDED_COMMUNITIES in Quagga"s BGP

Mozilla Thunderbird was updated to the 3.1.11 release. It has new features, fixes lots of bugs, and also fixes the following security issues: * MFSA 2011-19/CVE-2011-2374 CVE-2011-2376 CVE-2011-2364 CVE-2011-2365 Miscellaneous memory safety hazards * MFSA 2011-20/CVE-2011-2373 Use-after-free vulnerability when viewing XUL document with script disabled * MFSA 2011-21/CVE-2011-2377 Memory corrupti ...

- docs-xml: fix default name resolve order; . - s3-aio-fork: Fix a segfault in vfs_aio_fork; . - docs: remove whitespace in example samba.ldif; . - s3-smbd: move print_backend_init behind init_system_info; . - s3-docs: Prepend "/" to filename argument; . - Restrict self granting privileges where security=ads for Samba post-3.3.16; CVE-2012-2111; .

Samba upgrade to version 3.6.3 fixes the following security issue: - PIDL based autogenerated code allows overwriting beyond of allocated array. Remove attackers could exploit that to execute arbitrary code as root Please see /usr/share/doc/packages/samba/WHATSNEW.txt from the samba-doc package or the package change log for more details of the version update.

- Add the ldapsmb sources as else patches against them have no chance to apply. - Samba pre-3.6.4 are affected by a vulnerability that allows remote code exe- cution as the "root" user; PIDL based autogenerated code allows overwriting beyond of allocated array; CVE-2012-1182; ; . - s3-winbindd: Only use SamLogonEx when we can get unencrypted session keys; . - Correctly handle DENY ACEs w ...

This update of krb5 applications fixes two security issues. CVE-2011-4862: A remote code execution in the kerberized telnet daemon was fixed. CVE-2011-1526 / MITKRB5-SA-2011-005: Fixed krb5 ftpd unauthorized file access problems.

This update of freetype2 fixes multiple security flaws that could allow attackers to cause a denial of service or to execute arbitrary code via specially crafted fonts .

