Friday's security updates Arch Linux has updated php (multiple vulnerabilities).
Debian-LTS has updated tzdata (unspecified vulnerability).
Gentoo has updated adobe-flash (multiple vulnerabilities) and xorg-server (multiple vulnerabilities).
openSUSE has updated icecast
(13.1, 13.2:denial of service) and ntop (13.1, 13.2: cross-site scripting).
Red Hat has updated java-1.8.0-oracle (RHEL6,7: multiple vulnerabilities), novnc (RHEL6 OSP; RHEL7 OSP: VNC session hijacking),
openstack-foreman-installer (RHEL6
OSP: root command execution),
openstack-glance (RHEL6 OSP; RHEL7 OSP: denial of service),
openstack-nova (RHEL6 OSP; RHEL7 OSP: multiple vulnerabilities),
openstack-packstack, openstack-puppet-modules (RHEL6 OSP; RHEL7 OSP: root command execution),
openstack-swift (RHEL6 OSP; RHEL7 OSP: metadata constraint bypass),
python-django-horizon, python-django-openstack-auth (RHEL6 OSP; RHEL7 OSP: denial of service), and
redhat-access-plugin-openstack (RHEL6 OSP; RHEL7 OSP: information disclosure).
Ubuntu has updated apport
(14.04, 14.10: privilege escalation).