Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

snapd could be made to run programs as an administrator.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

The container trento/trento-web was updated. The following patches have been included in this update:

The container trento/trento-web was updated. The following patches have been included in this update:

The container trento/trento-runner was updated. The following patches have been included in this update:

The container trento/trento-runner was updated. The following patches have been included in this update:

security update

USN-5745-1 introduced a regression in shadow.

Sysstat could be made to crash or run programs if it processed specially crafted data.

Sysstat could be made to crash or run programs if it processed specially crafted data.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

security update

An Enterprises Guide To Strengthening Linux Cloud Security

It was discovered that twisted, a framework for internet applications written in Python, was prone to an HTML injection when displaying the HTTP Host header in an error page.

It was discovered that twisted, a framework for internet applications written in Python, was prone to an HTML injection when displaying the HTTP Host header in an error page.

An update that fixes 8 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

security update

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Several security vulnerabilities were discovered in inetutils, a collection of common network programs. CVE-2019-0053

Several security vulnerabilities were discovered in inetutils, a collection of common network programs. CVE-2019-0053

It was discovered that a buffer overflow in GraphicsMagick, a collection of image processing tools, could potentially result in the execution of arbitrary code when processing a malformed MIFF image.

It was discovered that a buffer overflow in GraphicsMagick, a collection of image processing tools, could potentially result in the execution of arbitrary code when processing a malformed MIFF image.

Red Hat OpenShift: How to create and integrate a private registry with stronger security capabilities

JBIG-KIT could be made to crash if it opened a specially crafted file.

Exim could be made to crash or run programs if it processed specially crafted regular expressions.

Exim could be made to crash or run programs if it processed specially crafted regular expressions.

Several security issues were fixed in ImageMagick.

Several security issues were fixed in ImageMagick.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

security update

Several security issues were fixed in MariaDB.

Expat could be made to crash or execute arbitrary code.

Expat could be made to crash or execute arbitrary code.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

Understanding open source software supply chain risks

An update that fixes one vulnerability is now available.

Several security issues were fixed in FreeRDP.

Several security issues were fixed in FreeRDP.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 10 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Keeping Your Private Files Private: An Introduction to GNU Privacy Guard

An update that fixes two vulnerabilities is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

security update

security update

security update

Red Hat Enterprise Linux and Microsoft security update of November 2022

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

security update

It was discovered that php-phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v2), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

Expat could be made to crash or execute arbitrary code.

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

security update

security update

security update