Vincent Tondellier reported that the qemu update issued as DSA 4454-1 did not correctly backport the support to define the md-clear bit to allow mitigation of the MDS vulnerabilities. Updated qemu packages are now available to correct this issue.
Several vulnerabilities have been found in the poppler PDF rendering library, which could result in denial of service or possibly other unspecified impact when processing malformed or maliciously crafted files.
Risk Level: Very Low. Type: Trojan.
The Qualys Research Labs reported a flaw in Exim, a mail transport agent. Improper validation of the recipient address in the deliver_message() function may result in the execution of arbitrary commands.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
How a Montreal-made “social search engine” application has managed to become a widely-spread adware, while escaping consequences The post Wajam: From start-up to massively-spread adware appeared first on WeLiveSecurity
It was discovered that there was a cross-site scripting (XSS) vulnerability in the Django web development framework. For Debian 8 “Jessie”, this issue has been fixed in python-django version
security update
It is the second major breach that the Australian National University suffered in 2018 The post Hackers steal 19 years’ worth of data from Australia’s top university appeared first on WeLiveSecurity
An update for systemd is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
The package python-django before version 2.2.2-1 is vulnerable to cross-site scripting.
The package python2-django before version 1.11.21-1 is vulnerable to cross-site scripting.
An update that contains security fixes can now be installed.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
An update that solves 5 vulnerabilities and has 6 fixes is now available.
An update that fixes four vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes 8 vulnerabilities is now available.
An update that solves 5 vulnerabilities and has 6 fixes is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes 16 vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
– https://www.drupal.org/project/module_filter/releases/7.x-2.2 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-042](https://www.drupal.org/sa-contrib-2019-042)
– https://www.drupal.org/project/views/releases/7.x-3.23 – https://www.drupal.org/project/views/releases/7.x-3.22 – https://www.drupal.org/project/views/releases/7.x-3.21 – [Less critical – Cross site scripting – SA-CONTRIB-2019-036](https://www.drupal.org/sa- contrib-2019-036) – [Moderately critical – Information disclosure – SA-
Update to 4.6.6 Various bugfixes on the 4.6 branch
– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)
– https://www.drupal.org/project/uuid/releases/7.x-1.2 – https://www.drupal.org/project/uuid/releases/7.x-1.1 – [Moderately critical – Arbitrary file upload – SA-CONTRIB-2018-045](https://www.drupal.org/sa- contrib-2018-045)
– https://www.drupal.org/project/xmlsitemap/releases/7.x-2.6 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.5 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.4 – [Moderately critical – Information Disclosure – SA- CONTRIB-2018-053](https://www.drupal.org/sa-contrib-2018-053) –
– https://www.drupal.org/project/context/releases/7.x-3.10 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-028](https://www.drupal.org/sa-contrib-2019-028) – https://www.drupal.org/project/context/releases/7.x-3.9 – https://www.drupal.org/project/context/releases/7.x-3.8
– https://www.drupal.org/project/path_breadcrumbs/releases/7.x-3.4 – [Less critical – Cross site scripting – SA- CONTRIB-2019-027](https://www.drupal.org/sa-contrib-2019-027)
– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)
An update that fixes one vulnerability is now available.
An update that fixes 6 vulnerabilities is now available.
