Security advisories for Tuesday CentOS has updated augeas (C6:
world writable config files) and bind (C6:
denial of service).
Debian has updated drupal7 (multiple vulnerabilities).
Fedora has updated libvirt (F20:
denial of service), nss (F20: information
disclosure), nss-softokn (F20: information
disclosure), nss-util (F20: information disclosure), and rubygem-will_paginate (F19; F20: cross-site scripting).
Gentoo has updated asterisk (multiple vulnerabilities).
Mageia has updated cups
(information disclosure), elinks (does not
properly verify SSL certificates), java-1.7.0-openjdk (multiple vulnerabilities),
libxfont (privilege escalation), memcached (multiple vulnerabilities), net-snmp (denial of service), nss (information disclosure), ruby-i18n (cross-site scripting), spice (denial of service), x11-server (code execution), and zabbix (multiple vulnerabilities).
Mandriva has updated java-1.7.0-openjdk (multiple vulnerabilities), libxfont (privilege escalation), and nss (information disclosure).
openSUSE has updated quassel
(13.1: information leak).
Oracle has updated augeas (OL6:
world writable config files) and bind (OL6:
denial of service).
Red Hat has updated augeas
(RHEL6: world writable config files) and bind (RHEL6: denial of service).
Scientific Linux has updated augeas (SL6: world writable config files) and
bind (SL6: denial of service).
Ubuntu has updated devscripts
(code execution), hplip (multiple vulnerabilities), and mysql-5.5, mysql-dfsg-5.1 (multiple vulnerabilities).