Two heap overflows were fixed in the rsyslog logging daemon. CVE-2019-17041
Out-of-bounds read for an incomplete URI with an IPv6 address containing an embedded IPv4 address has been fixed in uriparser, a library to parse Uniform Resource Identifiers (URIs).
guests may exceed their designated memory limit [XSA-385, CVE-2021-28706] PoD operations on misaligned GFNs [XSA-388, CVE-2021-28704, CVE-2021-28707 CVE-2021-28708] issues with partially successful P2M updates on x86 [XSA-389, CVE-2021-28705, CVE-2021-28709] certain VT-d IOMMUs may not work in shared page table mode [XSA-390, CVE-2021-28710]
An update that fixes 16 vulnerabilities is now available.
Red Hat AMQ Broker 7.9.1 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Red Hat OpenShift Container Platform release 4.8.22 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Andrew Bartlett discovered that Samba, a SMB/CIFS file, print, and login server for Unix, may map domain users to local users in an undesired way. This could allow a user in an AD domain to potentially become root on domain members.
Several security issues were fixed in ImageMagick.
security update
security update
The 5.15.5 stable kernel update contains a number of important fixes across the tree.
The INTERPOL-led operation involved law enforcement from 20 countries and led to the seizure of millions of dollars in illicit gains The post More than 1,000 arrested in global crackdown on online fraud appeared first on WeLiveSecurity
An update for samba is now available for Red Hat Gluster Storage 3.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update is now available for Red Hat OpenShift Container Storage 4.8.5 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for samba is now available for Red Hat Gluster Storage 3.5 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Red Hat OpenShift Container Platform release 4.9.9 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.
Several vulnerabilities were fixed in the OpenSC smart card utilities. CVE-2019-15945
Release of stargz snapshotter v0.10.1. This release contains the mitigation for CVE-2021-41190. Please see the release note for details. https://github.com/containerd/stargz-snapshotter/releases/tag/v0.10.1 —- Update to v0.10.0. See changes at https://github.com/containerd/stargz- snapshotter/releases/tag/v0.10.0
Rongxin Wu discovered a use-after-free vulnerability in the International Components for Unicode (ICU) library which could result in denial of service or potentially the execution of arbitrary code.
An infinite loop when –sparse is used with file shrinkage during read access was fixed in the GNU tar archiving utility. For Debian 9 stretch, this problem has been fixed in version
Update to 7.12.1
This is a security update to address CVE-2021-35063 and other misc bugs.
Update to 7.12.1
An out-of-bounds buffer read on truncated key frames in vp8_decode_frame has been fixed in libvpx, a popular library for the VP8 and VP9 video codecs. For Debian 9 stretch, this problem has been fixed in version
Several vulnerabilities were discovered in BlueZ, the Linux Bluetooth protocol stack. An attacker could cause a denial-of-service (DoS) or leak information.
It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize requests and mail messages. This would allow an attacker to perform Cross-Side Scripting (XSS) or SQL injection attacks.
security update
The 5.15.4 stable kernel rebase contains improved hardware support, new features, and a number of important fixes across the tree.
The 5.15.4 stable kernel rebase contains improved hardware support, new features, and a number of important fixes across the tree.
The 5.15.4 stable kernel rebase contains improved hardware support, new features, and a number of important fixes across the tree.
– Update to 21.08.4. – Closes security issue CVE-2021-43337.
‘Tis the season to avoid getting played by scammers hijacking Twitter accounts and promoting fake offers for PlayStation 5 consoles and other red-hot products The post The triangle of holiday shopping: Scams, social media and supply chain woes appeared first on WeLiveSecurity
The following updated rpms for Oracle Linux 8 have been uploaded to the Unb= reakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unb= reakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
With the holiday shopping bonanza right around the corner, here’s how to make sure your online spending spree is hacker-free The post Avoiding the shopping blues: How to shop online safely this holiday season appeared first on WeLiveSecurity
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685. (CVE-2019-7282)
Integer-overflow in Imf_3_1::bytesPerDeepLineTable. (CVE-2021-3933) Divide-by-zero in Imf_3_1::RGBtoXYZ. (CVE-2021-3941) References: – https://bugs.mageia.org/show_bug.cgi?id=29657
Server processes unencrypted bytes from man-in-the-middle. (CVE-2021-23214) libpq processes unencrypted bytes from man-in-the-middle. (CVE-2021-23222) References:
All FreeRDP clients prior to version 2.4.1 using gateway connections (‘/gt:rpc’) fail to validate input data. A malicious gateway might allow client memory to be written out of bounds. This issue has been resolved in version 2.4.1. If you are unable to update then use `/gt:http` rather than /gt:rdp connections if possible or use a […]
Server-side Request Forgery (SSRF) References: – https://bugs.mageia.org/show_bug.cgi?id=29592 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HMUJA5GZTPQ5WRYUCCK2GEZM4W43N7HH/
Privilege escalation that allows an attacker to add or remove data in any database or make configuration changes. (CVE-2021-38295) References: – https://bugs.mageia.org/show_bug.cgi?id=29548
security update
An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured (CVE-2021-41617) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssh-7.4p1-22.el7_9.x86_64.rpm openssh-askpass-7.4p1-22.el7_9.x86_64.rpm openssh-clients-7.4p1-22.e [More…]
krb5: NULL pointer dereference in process_tgs_req() in kdc/do_tgs_req.c via a FAST inner body that lacks server field (CVE-2021-37750) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 krb5-debuginfo-1.15.1-51.el7_9.i686.rpm krb5-debuginfo-1.15.1-51.el7_9.x86_64.rpm krb5- [More…]
kernel: use-after-free in drivers/infiniband/core/ucma.c ctx use-after- free (CVE-2020-36385) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * scsi: ibmvfc: Avoid link down on FS9100 canister reboot * crash in qla2x00_status_entry() because of corrupt srb * qedf driver: race c […]
