This update addresses possible evasion cases in some archive formats and stability issues in portions of the bytecode engine.

3 Security issues were fixed in rails 2.3 core components. 2 NULL query issues where fixed in the actionpack gem. 1 SQL injection was fixed in the activerecord gem.

- docs-xml: fix default name resolve order; . - s3-aio-fork: Fix a segfault in vfs_aio_fork; . - docs: remove whitespace in example samba.ldif; . - s3-smbd: move print_backend_init behind init_system_info; . - s3-docs: Prepend "/" to filename argument; . - Restrict self granting privileges where security=ads for Samba post-3.3.16; CVE-2012-2111; .

A stack-based buffer overflow in the glyph handling of libqt4"s harfbuzz has been fixed. CVE-2011-3922 has been assigned to this issue.

Adobe Flash Player was updated to, fixing lots of bugs and critical security issues. We also disabled inclusion of mms.cfg again, as it caused trouble on hardware accelerated systems.

This version upgrade of horde3-dimp to 4.3.11 fixes several issues and adds new features.

Fixing CVE-2012-2122: authentication bypass due to incorrect type casting

Acrobat Reader was updated to version 9.4.7 to fix security issues

Specially crafted ogg files could cause a heap-based buffer overflow in the vorbis audio compression library that could potentially be exploited by attackers to cause a crash or execute arbitrary code .

