{"affected":[],"aliases":[],"details":"\nThis update provides SUSE Studio 1.3.10, including Amazon's EC2 support for \nSUSE Linux Enterprise 12 appliances.\n\nAdditionally, the update includes fixes for the following issues:\n\n    * #904372 - Arbitrary file existence disclosure in sprockets gem\n      (CVE-2014-7819)\n    * #904375 - Arbitrary file existence disclosure in Action Pack gem\n      (CVE-2014-7818)\n    * #918203 - Arbitrary file existence disclosure in Studio Onsite\n      (CVE-2014-7829)\n    * #852794 - SLES 11-SP3 templates fail to build x86_64 EC2 images\n    * #914765 - Change of appliance name is not displayed in appliance's\n      change log\n    * #887893 - Change log not accessible via API\n    * #918239 - Failure to create new appliances after upgrade to Studio\n      Onsite 1.3.9\n    * #918395 - Remove 32bit as target for building EC2 appliances\n    * #912512 - Studio doesn't allow duplicated repositories\n    * #880078 - Studio packages contain files that get modified (by Studio)\n      after installation.\n    * #919037 - Can't open appliance on Gallery: undefined\n      restructure_unsupportable_packages method.\n\nSecurity Issues:\n\n    * CVE-2014-7819\n      <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7819>\n    * CVE-2014-7818\n      <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7818>\n    * CVE-2014-7829\n      <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7829>\n\n","id":"SUSE-SU-2015:0863-1","modified":"2015-05-05T23:49:58Z","published":"2015-05-05T23:49:58Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150863-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/852794"},{"type":"REPORT","url":"https://bugzilla.suse.com/876313"},{"type":"REPORT","url":"https://bugzilla.suse.com/880078"},{"type":"REPORT","url":"https://bugzilla.suse.com/887893"},{"type":"REPORT","url":"https://bugzilla.suse.com/904372"},{"type":"REPORT","url":"https://bugzilla.suse.com/904375"},{"type":"REPORT","url":"https://bugzilla.suse.com/912512"},{"type":"REPORT","url":"https://bugzilla.suse.com/914765"},{"type":"REPORT","url":"https://bugzilla.suse.com/918203"},{"type":"REPORT","url":"https://bugzilla.suse.com/918239"},{"type":"REPORT","url":"https://bugzilla.suse.com/918395"},{"type":"REPORT","url":"https://bugzilla.suse.com/919037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-7818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-7819"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-7829"}],"related":["CVE-2014-7818","CVE-2014-7819","CVE-2014-7829"],"summary":"Security update for SUSE Studio","upstream":["CVE-2014-7818","CVE-2014-7819","CVE-2014-7829"]}