4638
- Import commit 1d852a8a57a583ea3e4064191b71d917839c975e
low
openSUSE 13.1 Update
- Import commit 1d852a8a57a583ea3e4064191b71d917839c975e
727538c udev: readd nvme entries to 60-persistent-storage.rules (boo#980303)
14982a6 Always create dependencies for loop device mounts
ec89121 Always create dependencies for bind mounts (bsc#964934)
ae9bfc2 build: fix build issue on TW with latest linux-glibc-devel package
cbf8f8a transaction_add_job_and_dependencies(): return ENOENT when a unit is not found (bsc#960158)
c06dd31 Fix backport of "tmpfiles: add ability to mask access mode by pre-existing access mode on files/directories" (bsc#973848)
- Make sure that initrd-udevadm-cleanup-db.service is packaged only once.
Previous change make it part to both systemd and udev packages.
- Restore initrd-udevadm-cleanup-db.service (bsc#978275, bsc#976766, boo#980325)
It's been removed accidentally.
libudev-mini-devel-210-49.1.i586.rpm
libudev-mini1-210-49.1.i586.rpm
libudev-mini1-debuginfo-210-49.1.i586.rpm
systemd-mini-210-49.1.i586.rpm
systemd-mini-210-49.1.src.rpm
systemd-mini-debuginfo-210-49.1.i586.rpm
systemd-mini-debugsource-210-49.1.i586.rpm
systemd-mini-devel-210-49.1.i586.rpm
systemd-mini-sysvinit-210-49.1.i586.rpm
udev-mini-210-49.1.i586.rpm
udev-mini-debuginfo-210-49.1.i586.rpm
libgudev-1_0-0-210-49.1.i586.rpm
libgudev-1_0-0-32bit-210-49.1.x86_64.rpm
libgudev-1_0-0-debuginfo-210-49.1.i586.rpm
libgudev-1_0-0-debuginfo-32bit-210-49.1.x86_64.rpm
libgudev-1_0-devel-210-49.1.i586.rpm
libudev-devel-210-49.1.i586.rpm
libudev1-210-49.1.i586.rpm
libudev1-32bit-210-49.1.x86_64.rpm
libudev1-debuginfo-210-49.1.i586.rpm
libudev1-debuginfo-32bit-210-49.1.x86_64.rpm
nss-myhostname-210-49.1.i586.rpm
nss-myhostname-32bit-210-49.1.x86_64.rpm
nss-myhostname-debuginfo-210-49.1.i586.rpm
nss-myhostname-debuginfo-32bit-210-49.1.x86_64.rpm
systemd-210-49.1.i586.rpm
systemd-210-49.1.src.rpm
systemd-32bit-210-49.1.x86_64.rpm
systemd-bash-completion-210-49.1.noarch.rpm
systemd-debuginfo-210-49.1.i586.rpm
systemd-debuginfo-32bit-210-49.1.x86_64.rpm
systemd-debugsource-210-49.1.i586.rpm
systemd-devel-210-49.1.i586.rpm
systemd-journal-gateway-210-49.1.i586.rpm
systemd-journal-gateway-debuginfo-210-49.1.i586.rpm
systemd-logger-210-49.1.i586.rpm
systemd-sysvinit-210-49.1.i586.rpm
typelib-1_0-GUdev-1_0-210-49.1.i586.rpm
udev-210-49.1.i586.rpm
udev-debuginfo-210-49.1.i586.rpm
libudev-mini-devel-210-49.1.x86_64.rpm
libudev-mini1-210-49.1.x86_64.rpm
libudev-mini1-debuginfo-210-49.1.x86_64.rpm
systemd-mini-210-49.1.x86_64.rpm
systemd-mini-debuginfo-210-49.1.x86_64.rpm
systemd-mini-debugsource-210-49.1.x86_64.rpm
systemd-mini-devel-210-49.1.x86_64.rpm
systemd-mini-sysvinit-210-49.1.x86_64.rpm
udev-mini-210-49.1.x86_64.rpm
udev-mini-debuginfo-210-49.1.x86_64.rpm
libgudev-1_0-0-210-49.1.x86_64.rpm
libgudev-1_0-0-debuginfo-210-49.1.x86_64.rpm
libgudev-1_0-devel-210-49.1.x86_64.rpm
libudev-devel-210-49.1.x86_64.rpm
libudev1-210-49.1.x86_64.rpm
libudev1-debuginfo-210-49.1.x86_64.rpm
nss-myhostname-210-49.1.x86_64.rpm
nss-myhostname-debuginfo-210-49.1.x86_64.rpm
systemd-210-49.1.x86_64.rpm
systemd-debuginfo-210-49.1.x86_64.rpm
systemd-debugsource-210-49.1.x86_64.rpm
systemd-devel-210-49.1.x86_64.rpm
systemd-journal-gateway-210-49.1.x86_64.rpm
systemd-journal-gateway-debuginfo-210-49.1.x86_64.rpm
systemd-logger-210-49.1.x86_64.rpm
systemd-sysvinit-210-49.1.x86_64.rpm
typelib-1_0-GUdev-1_0-210-49.1.x86_64.rpm
udev-210-49.1.x86_64.rpm
udev-debuginfo-210-49.1.x86_64.rpm
openSUSE_Evergreen_Maintenance_4643
lupdate-qt5/lrelease-qt5 can't find qmake configuration file "default".
low
openSUSE 13.1 Update
lupdate-qt5/lrelease-qt5 can't find qmake configuration file "default".
libqt5-qttools-5.1.1-3.3.i586.rpm
libqt5-qttools-5.1.1-3.3.src.rpm
libqt5-qttools-debuginfo-5.1.1-3.3.i586.rpm
libqt5-qttools-debugsource-5.1.1-3.3.i586.rpm
libqt5-qttools-devel-5.1.1-3.3.i586.rpm
libqt5-qttools-private-headers-devel-5.1.1-3.3.i586.rpm
libqt5-qttools-5.1.1-3.3.x86_64.rpm
libqt5-qttools-debuginfo-5.1.1-3.3.x86_64.rpm
libqt5-qttools-debugsource-5.1.1-3.3.x86_64.rpm
libqt5-qttools-devel-5.1.1-3.3.x86_64.rpm
libqt5-qttools-private-headers-devel-5.1.1-3.3.x86_64.rpm
4657
July 2016 security update dump
low
openSUSE 13.1 Update
July 2016 security update dump
java-1_7_0-openjdk-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-1.7.0.111-24.39.1.src.rpm
java-1_7_0-openjdk-accessibility-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-debuginfo-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-debugsource-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-demo-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-demo-debuginfo-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-devel-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-devel-debuginfo-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-headless-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-headless-debuginfo-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-javadoc-1.7.0.111-24.39.1.noarch.rpm
java-1_7_0-openjdk-src-1.7.0.111-24.39.1.i586.rpm
java-1_7_0-openjdk-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-accessibility-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-debuginfo-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-debugsource-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-demo-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-demo-debuginfo-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-devel-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-devel-debuginfo-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-headless-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-headless-debuginfo-1.7.0.111-24.39.1.x86_64.rpm
java-1_7_0-openjdk-src-1.7.0.111-24.39.1.x86_64.rpm
typo3-cms-4_7
Important security fixes for Typo3
important
openSUSE 13.1 Update
Important security fixes for vulnerabilities in typo3 which can be used for Cross-Site Scripting or Denial of Service attacks or for authentication bypassing.
typo3-cms-4_5-4.5.40-2.7.1.noarch.rpm
typo3-cms-4_5-4.5.40-2.7.1.src.rpm
typo3-cms-4_7-4.7.20-3.3.1.noarch.rpm
typo3-cms-4_7-4.7.20-3.3.1.src.rpm
openSUSE_Evergreen_Maintenance_4659
Security update for MozillaFirefox, mozilla-nss
important
openSUSE 13.1 Update
Mozilla Firefox was updated to 48.0 to fix security issues, bugs, and deliver various improvements.
The following major changes are included:
- Process separation (e10s) is enabled for some users
- Add-ons that have not been verified and signed by Mozilla will not load
- WebRTC enhancements
- The media parser has been redeveloped using the Rust programming language
- better Canvas performance with speedy Skia support
- Now requires NSS 3.24
The following security issues were fixed: (boo#991809)
- CVE-2016-2835/CVE-2016-2836: Miscellaneous memory safety hazards
- CVE-2016-2830: Favicon network connection can persist when page is closed
- CVE-2016-2838: Buffer overflow rendering SVG with bidirectional content
- CVE-2016-2839: Cairo rendering crash due to memory allocation issue with FFmpeg 0.10
- CVE-2016-5251: Location bar spoofing via data URLs with malformed/invalid mediatypes
- CVE-2016-5252: Stack underflow during 2D graphics rendering
- CVE-2016-0718: Out-of-bounds read during XML parsing in Expat library
- CVE-2016-5254: Use-after-free when using alt key and toplevel menus
- CVE-2016-5255: Crash in incremental garbage collection in JavaScript
- CVE-2016-5258: Use-after-free in DTLS during WebRTC session shutdown
- CVE-2016-5259: Use-after-free in service workers with nested sync events
- CVE-2016-5260: Form input type change from password to text can store plain text password in session restore file
- CVE-2016-5261: Integer overflow in WebSockets during data buffering
- CVE-2016-5262: Scripts on marquee tag can execute in sandboxed iframes
- CVE-2016-2837: Buffer overflow in ClearKey Content Decryption Module (CDM) during video playback
- CVE-2016-5263: Type confusion in display transformation
- CVE-2016-5264: Use-after-free when applying SVG effects
- CVE-2016-5265: Same-origin policy violation using local HTML file and saved shortcut file
- CVE-2016-5266: Information disclosure and local file manipulation through drag and drop
- CVE-2016-5268: Spoofing attack through text injection into internal error pages
- CVE-2016-5250: Information disclosure through Resource Timing API during page navigation
The following non-security changes are included:
- The AppData description and screenshots were updated.
- Fix Firefox crash on startup on i586 (boo#986541)
- The Selenium WebDriver may have caused Firefox to crash at startup
- fix build issues with gcc/binutils combination used in Leap 42.2 (boo#984637)
- Fix running on 48bit va aarch64 (boo#984126)
- fix XUL dialog button order under KDE session (boo#984403)
Mozilla NSS was updated to 3.24 as a dependency.
Changes in mozilla-nss:
- NSS softoken updated with latest NIST guidance
- NSS softoken updated to allow NSS to run in FIPS Level 1 (no password)
- Various added and deprecated functions
- Remove most code related to SSL v2, including the ability to actively send a SSLv2-compatible client hello.
- Protect against the Cachebleed attack.
- Disable support for DTLS compression.
- Improve support for TLS 1.3. This includes support for DTLS 1.3. (experimental)
MozillaFirefox-48.0-119.1.i586.rpm
MozillaFirefox-48.0-119.1.src.rpm
MozillaFirefox-branding-upstream-48.0-119.1.i586.rpm
MozillaFirefox-buildsymbols-48.0-119.1.i586.rpm
MozillaFirefox-debuginfo-48.0-119.1.i586.rpm
MozillaFirefox-debugsource-48.0-119.1.i586.rpm
MozillaFirefox-devel-48.0-119.1.i586.rpm
MozillaFirefox-translations-common-48.0-119.1.i586.rpm
MozillaFirefox-translations-other-48.0-119.1.i586.rpm
libfreebl3-3.24-83.1.i586.rpm
libfreebl3-32bit-3.24-83.1.x86_64.rpm
libfreebl3-debuginfo-3.24-83.1.i586.rpm
libfreebl3-debuginfo-32bit-3.24-83.1.x86_64.rpm
libsoftokn3-3.24-83.1.i586.rpm
libsoftokn3-32bit-3.24-83.1.x86_64.rpm
libsoftokn3-debuginfo-3.24-83.1.i586.rpm
libsoftokn3-debuginfo-32bit-3.24-83.1.x86_64.rpm
mozilla-nss-3.24-83.1.i586.rpm
mozilla-nss-3.24-83.1.src.rpm
mozilla-nss-32bit-3.24-83.1.x86_64.rpm
mozilla-nss-certs-3.24-83.1.i586.rpm
mozilla-nss-certs-32bit-3.24-83.1.x86_64.rpm
mozilla-nss-certs-debuginfo-3.24-83.1.i586.rpm
mozilla-nss-certs-debuginfo-32bit-3.24-83.1.x86_64.rpm
mozilla-nss-debuginfo-3.24-83.1.i586.rpm
mozilla-nss-debuginfo-32bit-3.24-83.1.x86_64.rpm
mozilla-nss-debugsource-3.24-83.1.i586.rpm
mozilla-nss-devel-3.24-83.1.i586.rpm
mozilla-nss-sysinit-3.24-83.1.i586.rpm
mozilla-nss-sysinit-32bit-3.24-83.1.x86_64.rpm
mozilla-nss-sysinit-debuginfo-3.24-83.1.i586.rpm
mozilla-nss-sysinit-debuginfo-32bit-3.24-83.1.x86_64.rpm
mozilla-nss-tools-3.24-83.1.i586.rpm
mozilla-nss-tools-debuginfo-3.24-83.1.i586.rpm
MozillaFirefox-48.0-119.1.x86_64.rpm
MozillaFirefox-branding-upstream-48.0-119.1.x86_64.rpm
MozillaFirefox-buildsymbols-48.0-119.1.x86_64.rpm
MozillaFirefox-debuginfo-48.0-119.1.x86_64.rpm
MozillaFirefox-debugsource-48.0-119.1.x86_64.rpm
MozillaFirefox-devel-48.0-119.1.x86_64.rpm
MozillaFirefox-translations-common-48.0-119.1.x86_64.rpm
MozillaFirefox-translations-other-48.0-119.1.x86_64.rpm
libfreebl3-3.24-83.1.x86_64.rpm
libfreebl3-debuginfo-3.24-83.1.x86_64.rpm
libsoftokn3-3.24-83.1.x86_64.rpm
libsoftokn3-debuginfo-3.24-83.1.x86_64.rpm
mozilla-nss-3.24-83.1.x86_64.rpm
mozilla-nss-certs-3.24-83.1.x86_64.rpm
mozilla-nss-certs-debuginfo-3.24-83.1.x86_64.rpm
mozilla-nss-debuginfo-3.24-83.1.x86_64.rpm
mozilla-nss-debugsource-3.24-83.1.x86_64.rpm
mozilla-nss-devel-3.24-83.1.x86_64.rpm
mozilla-nss-sysinit-3.24-83.1.x86_64.rpm
mozilla-nss-sysinit-debuginfo-3.24-83.1.x86_64.rpm
mozilla-nss-tools-3.24-83.1.x86_64.rpm
mozilla-nss-tools-debuginfo-3.24-83.1.x86_64.rpm