Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Several security issues were fixed in amanda.

Fixes CVE-2023-1393: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability

Update to ldb 2.7.2 and samba 4.18.1 Security fixes for CVE-2023-0225, CVE-2023-0922, CVE-2023-0614

Update to ldb 2.7.2 and samba 4.18.1 Security fixes for CVE-2023-0225, CVE-2023-0922, CVE-2023-0614

Fixes CVE-2023-1393: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability

xwayland 22.1.9 Security fix for CVE-2023-1393

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/bci-busybox was updated. The following patches have been included in this update:

Multiple potential security vulnerabilities in some Intel® Processors have been found which may allow information disclosure or may allow escalation of privilege. Intel is releasing firmware updates to mitigate this potential vulnerabilities.

The container bci/openjdk was updated. The following patches have been included in this update:

An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

go1.19.7 (released 2023-03-07) includes a security fix to the crypto/elliptic package, as well as bug fixes to the linker, the runtime, and the crypto/x509 and syscall packages. See the [Go 1.19.7 milestone on the upstream issue tracker](https://go.dev/doc/devel/release#go1.19.7) for details.

Maintenance release with fix for CVE-2023-28686 and bug fixes.

Several security issues were fixed in the Linux kernel.

Red Hat Shares – Security automation

Multiple vulnerabilities were found in Json-smart library. Json-smart is a performance focused, JSON processor lib written in Java. CVE-2021-31684

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Several out of bounds memory access and buffer overflows were fixed in xrdp, an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP)

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

security update

Jan-Niklas Sohn discovered that a user-after-free flaw in the Composite extension of the X.org X server may result in privilege escalation if the X server is running under the root user.

Several security vulnerabilities have been discovered in unbound, a validating, recursive, caching DNS resolver. CVE-2022-3204

The container bci/rust was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

security update

The container bci/bci-init was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:

The container ses/7.1/ceph/ceph was updated. The following patches have been included in this update:

The container ses/7.1/ceph/grafana was updated. The following patches have been included in this update:

The container ses/7.1/cephcsi/cephcsi was updated. The following patches have been included in this update:

An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, denial of service or information leaks.

3 security issues (#2180425) x86 shadow plus log-dirty mode use-after-free [XSA-427, CVE-2022-42332] x86/HVM pinned cache attributes mis-handling [XSA-428, CVE-2022-42333, CVE-2022-42334] x86: speculative vulnerability in 32bit SYSCALL path [XSA-429, CVE-2022-42331]

3 security issues (#2180425) x86 shadow plus log-dirty mode use-after-free [XSA-427, CVE-2022-42332] x86/HVM pinned cache attributes mis-handling [XSA-428, CVE-2022-42333, CVE-2022-42334] x86: speculative vulnerability in 32bit SYSCALL path [XSA-429, CVE-2022-42331]

Fix for CVE-2022-48303

This update upgrades Thunderbird to version 102.9.0. * Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751) * Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176) * Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752) * Mozilla: Invalid downcast in Worklets (CVE-2023-28162) * Mozilla: URL being dragged fr [More…]

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

update to 111.0.5563.110. Fixes the following security issues: CVE-2023-1528 CVE-2023-1529 CVE-2023-1530 CVE-2023-1531 CVE-2023-1532 CVE-2023-1533 CVE-2023-1534

Rebuild for CVE-20220-{3064,41717,41723}

security update

security update

New tar packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue.

This update includes the changes in tzdata 2023b for the Perl bindings. For the list of changes, see DLA-3366-1. For Debian 10 buster, this problem has been fixed in version

This update includes the changes in tzdata 2023b. Notable changes are: – – Egypt uses DST again, starting on April.

Incorrect code generation during JIT compilation. (CVE-2023-25751) Potential out-of-bounds when accessing throttled streams. (CVE-20223-25752) Invalid downcast in Worklets. (CVE-2023-28162) URL being dragged from a removed cross-origin iframe into the same tab triggered navigation. (CVE-2023-28164)

If a malicious Flatpak app is run on a Linux virtual console such as /dev/tty1, it can copy text from the virtual console and paste it back into the virtual console’s input buffer, from which the command might be run by the user’s shell after the Flatpak app has exited. This is similar to CVE-2017-5226, […]

In the MHD_PostProcessor, malformed inputs can be used to crash the server (for denial-of-service). References: – https://bugs.mageia.org/show_bug.cgi?id=31670

LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-4645) References:

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Several security issues were fixed in amanda.

The container bci/golang was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

ManageEngine Vulnerability Manager Plus: How To Protect Your Enterprise from Security Vulnerabilities
High-Impact DoS, Arbitrary Code Execution, Spoofing Bugs Fixed in Thunderbird 102.9.0
Tails 5.11 Amnesic Incognito Live System Switches to ZRam and Linux Kernel 6.1 LTS
Researcher Creates Polymorphic Blackmamba Malware with ChatGPT

USN-5904-1 caused a minor regression in SoX.

The container bci/nodejs was updated. The following patches have been included in this update:

TigerVNC could be made to expose sensitive information over the network.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in Vim.

Python could be made to bypass blocklisting methods if a specially crafted URL was provided.

One of the security fixes released as DLA 3315 introduced a regression in the processing WAV files with variable bitrate encoding. Updated sox packages are available to correct this issue.

Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing.

The newest upstream commit Security fixes for CVE-2023-1175, CVE-2023-1170, CVE-2023-1264.

Update to 1.15.4 * Fix CVE-2023-28100 and CVE-2023-28101

Update to 102.9.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2023-11/ ; https://www.thunderbird.net/en- US/thunderbird/102.9.0/releasenotes/

Denial of service using crafted input. (CVE-2022-40152) References: – https://bugs.mageia.org/show_bug.cgi?id=31665 – https://lists.suse.com/pipermail/sle-security-updates/2023-March/013995.html