Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

security update

libXdmcp could be made to expose sensitive information.

Perl could be made to by pass signature verification.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

This update upgrades Firefox to version 102.3.0 ESR. * expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 firefox-102.3.0-7.el7_9.x86_64.rpm firefox-debuginfo-102.3.0-7.el7_9.x86_64.rpm firefox [More…]

This update upgrades Thunderbird to version 102.3.0. * expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 thunderbird-102.3.0-4.el7_9.x86_64.rpm thunderbird-debuginfo-102.3.0-4.el7_9.x86_64.rpm – [More…]

security update

security update

It was found that the Node XML DOM library was vulnerable to prototype pollution. For Debian 10 buster, this problem has been fixed in version

Several security issues were fixed in FRR.

An update that solves 26 vulnerabilities, contains two features and has 89 fixes is now available.

An update for nodejs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

This update fixes a wide range of vulnerabilities. A significant portion affects character set conversion. CVE-2016-10228

Choosing the Right Remote Access Solution for Your Linux Environment

An update that fixes 6 vulnerabilities is now available.

An update for .NET 6.0 is available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

security update

Multiple vulnerabilities have been discovered in Rust, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in Tcpreplay, the worst of which could result in denial of service.

A vulnerability has been found in Deluge which could result in XSS.

Multiple vulnerabilities have been discovered in libvirt, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in virglrenderer, the worst of which could result in remote code execution.

Multiple vulnerabilities have been discovered in Wireshark, the worst of which could result in denial of service.

Several security issues were fixed in the Linux kernel.

Multiple security issues were found in Django, a Python web development framework, which could result in denial of service, SQL injection or cross-site scripting.

The package linux-zen before version 6.0.1.zen2-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

The package linux-lts before version 5.15.73-3 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

The package linux before version 6.0.1.arch2-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

The package linux-hardened before version 5.19.15.hardened2-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

security update

Several security issues were fixed in gThumb.

An update that solves 8 vulnerabilities and has 12 fixes is now available.

An update that solves 8 vulnerabilities and has 11 fixes is now available.

An update that solves 5 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves 9 vulnerabilities, contains 12 features and has 38 fixes is now available.

security update

Several security issues were fixed in unzip.

XML Security Library could be made to crash if it opened a specially crafted file.

An update that fixes two vulnerabilities is now available.

An update is now available for the Red Hat build of Quarkus Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each

An update that fixes one vulnerability is now available.

Red Hat OpenShift Container Platform release 4.8.51 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.8.

It was discovered that insufficient validation of “vnd.libreoffice.command” URI schemes could result in the execution of arbitrary macro commands.

Several security issues were fixed in AdvanceCOMP.

A command injection vulnerability was found in Rexical, a lexical scanner generator for the Ruby programming language. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user

Multiple vulnerabilities were discovered in Nokogiri, an HTML/XML/SAX/Reader parser for the Ruby programming language, leading to command injection, XML external entity injection (XXE), and denial-of-service (DoS).

Red Hat AMQ Broker 7.10.1 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for expat is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

The Most Important Things you Can do to Quickly Secure Ubuntu Linux

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Evgeny Vereshchagin discovered multiple vulnerabilities in D-Bus, a simple interprocess messaging system, which may result in denial of service by an authenticated user.

Several security vulnerabilities were discovered in WordPress, a popular content management framework. Server Side Request Forgery and cross-site scripting (XSS) attacks may facilitate the bypass of access controls or the injection of client-side scripts.

A security issue was fixed in nginx’s lua module.

Security fix for CVE-2022-38784

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the ‘err_msg’ of ‘sqlite3_exec’ is not releasing after use, while libxml2 emphasizes that the caller needs to release it. (CVE-2021-42523)

A syntactically invalid type signature with incorrectly nested parentheses and curly brackets would cause an assertion failure in debug builds. Similar messages could potentially result in a crash or incorrect message processing in a production build, although we are not aware of a practical example. (CVE-2022-42010)

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. (CVE-2022-41322)

libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). (CVE-2020-29260) References: – https://bugs.mageia.org/show_bug.cgi?id=30917

Core Fixed bug GH-9323 (Crash in ZEND_RETURN/GC/zend_call_function) Fixed bug GH-9361 (Segmentation fault on script exit #9379). Fixed bug GH-9407 (LSP error in eval’d code refers to wrong class for static type).

Non-Responsive Delegation Attack. (CVE-2022-3204) Improves performance when under load, by cutting promiscuous queries for nameserver discovery and limiting the number of times a delegation point can look in the cache for missing records.

Update to the September 2022 update release of .NET Core 3.1 Release Notes: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.29/3.1.29.md This includes a fix for CVE-2022-38013

Security fix for CVE-2022-21797

Update to the September 2022 update release of .NET Core 3.1 Release Notes: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.29/3.1.29.md This includes a fix for CVE-2022-38013

Open source incident response solutions
What is the Confidential Containers project?

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

security update

security update

Security fix for CVE-2022-38784

Some stability fixes. —- Update to 2.53.14 Note that besides the ordinary builds for the current Fedora and EPEL branches, there is an additional distro- independed build available at https://buc.fedorapeople.org/seamonkey . So if you have friends who use other Linux distro, but that distro does not provide SeaMonkey yet, you can recommend it for them.

Rebase to 2.4.9

**Version 3.4.3** (2022-09-28) * Fix a security issue on filesystem loader (possibility to load a template outside a configured directory)

**Version 2.15.3** (2022-09-28) * Fix a security issue on filesystem loader (possibility to load a template outside a configured directory)

Updated to version 0.10.2 with CVE fix.

expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 expat-2.1.0-15.el7_9.i686.rpm expat-2.1.0-15.el7_9.x86_64.rpm expat-debuginfo-2.1.0-15.el7_9.i686.rpm expat-debuginfo-2.1.0-15.el7_9.x86_ [More…]

squid: buffer-over-read in SSPI and SMB authentication (CVE-2022-41318) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 squid-3.5.20-17.el7_9.8.x86_64.rpm squid-debuginfo-3.5.20-17.el7_9.8.x86_64.rpm squid-migration-script-3.5.20-17.el7_9.8.x86_64.rpm squid-sysvinit [More…]

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

security update

security update

security update

Several security issues were fixed in DHCP.