Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

The container bci/python was updated. The following patches have been included in this update:

The container bci/php-apache was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container suse/registry was updated. The following patches have been included in this update:

security update

LuaTeX (TeX Live) could be made to run programs as your login if it compiled a specially crafted TeX file.

Email Phishing Using Kali Linux

hawk could be made to crash if it opened a specially crafted file.

nth-check could be made to crash if it opened a specially crafted file.

Jhead could be made to crash if it opened a specially crafted file.

The container bci/openjdk-devel was updated. The following patches have been included in this update:

Multiple vulnerabilities have been found in Apache Tomcat, the worst of which could result in denial of service.

security update

Multiple vulnerabilities were found in sssd, a set of daemons to manage access to remote directories and authentication mechanisms, which could lead to privilege escalation.

Several security issues were fixed in Sudo.

Jhead could be made to crash if it opened a specially crafted file.

Linux PTP could be made to crash, run arbitrary code, or expose sensitive information if it received specially crafted input.

Update bottles to 51.6 and release final dependency vkbasalt-cli

Update bottles to 51.6 and release final dependency vkbasalt-cli

security update

security update

An update that fixes 43 vulnerabilities is now available.

Update to 1.19.1. Fixes CVE-2023-32067, CVE-2023-31130, CVE-2023-31147, CVE-2023-31124

Update to 0.10.5 (CVE-2023-1667 CVE-2023-2283)

Cross-site scripting (XSS) vulnerabilities were found in rainloop, a web-based email client, which could lead to information disclosure including passphrase leak.

security update

security update

Several vulnerabilities were discovered in libraw, a library for reading RAW files obtained from digital photo cameras, which may result in denial of service or the execution of arbitrary code if specially crafted files are processed.

It was discovered that sysstat, a system performance tools for Linux, incompletely fixed CVE-2022-39377 (as published in DLA-3188-1), which could lead to crashes and possibly remote code execution.

Jose Gomez discovered that the Catalog API endpoint in the Docker registry implementation did not sufficiently enforce limits, which could result in denial of service.

Buffer Overflow vulnerabilities were found in libraw, a raw image decoder library, which could lead to application crash or privilege escalation.

– Update the sequoia-openpgp crate to version 1.16.0. – Update the nettle crate to version 7.3.0. – Update the nettle-sys crate to version 2.2.0. – Update the buffered-reader crate to version 1.2.0. Version 1.16.0 of the sequoia-openpgp crate fixes some issues in parsing code, which could lead to attempted out-of- bounds accesses that result in […]

– Update the sequoia-openpgp crate to version 1.16.0. – Update the nettle crate to version 7.3.0. – Update the nettle-sys crate to version 2.2.0. – Update the buffered-reader crate to version 1.2.0. Version 1.16.0 of the sequoia-openpgp crate fixes some issues in parsing code, which could lead to attempted out-of- bounds accesses that result in […]

– Update the sequoia-openpgp crate to version 1.16.0. – Update the nettle crate to version 7.3.0. – Update the nettle-sys crate to version 2.2.0. – Update the buffered-reader crate to version 1.2.0. Version 1.16.0 of the sequoia-openpgp crate fixes some issues in parsing code, which could lead to attempted out-of- bounds accesses that result in […]

An issue has been found in sniproxy, a transparent TLS and HTTP layer 4 proxy with SNI support. Due to bad handling of wildcard backend hosts, a crafted HTTP or TLS packet might lead to remote arbitrary code execution.

Improving supply chain resiliency with Red Hat Trusted Software Supply Chain

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux Cloud Native Environment 1.6 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Confidential Containers on Azure with OpenShift: A technical deep dive

security update

An update for sudo is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

An update for devtoolset-12-binutils is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

JSON Schema could be made to crash or run programs if it opened specially crafted input.

USN-6074-2 caused some minor regressions in Firefox.

Several security issues were fixed in GNU binutils.

Several security issues were fixed in xmldom.

security update

Go applications could be made to hang or crash if they received specially crafted input.

USN-6073-4 introduced a regression in os-brick.

USN-6073-3 introduced a regression in Nova.

USN-6073-2 introduced a regression in Glance_store.

USN-6073-1 introduced a regression in Cinder.

Several security issues were fixed in ncurses.

security update

security update

tar could be made to crash or expose sensitive information if it received a specially crafted file.

Two vulnerabilities have been fixed in sqlite (V2) which which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact.

An update for git is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for git is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for git is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for git is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

It was discovered that missing input sanitising in cups-filters, when using the Backend Error Handler (beh) backend to create an accessible network printer, may result in the execution of arbitrary commands.

Potential NULL dereference during rekeying with algorithm guessing. (CVE-2023-1667) Authorization bypass in pki_verify_data_signature. (CVE-2023-2283 References:

ReDoS (Regular Expression Denial of Service) (CVE-2023-30608) References: – https://bugs.mageia.org/show_bug.cgi?id=31913 – https://ubuntu.com/security/notices/USN-6064-1

An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c. (CVE-2023-2004) References: – https://bugs.mageia.org/show_bug.cgi?id=31887

cmark incorrectly handled certain inputs. Fixes quadratic complexity in handle_close_bracket “![[]()” which may lead to a denial of service (CVE-2023-22486). Noting that this also fixes a quadratic parsing issue with repeated

Dmidecode allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. (CVE-2023-30630) References:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Max Chernoff discovered that improperly secured shell-escape in LuaTeX may result in arbitrary shell command execution, even with shell escape disabled, if specially crafted tex files are processed.

The newest upstream commit Security fix for CVE-2023-2426

security update

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Confidential computing use cases

This kernel-linus update is based on upstream 5.15.110 and fixes atleast the following security issues: A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.

fix clone-in-kitty + security fix rhbz#2196803

Upgrade to 1.2.11

Backport fix for CVE-2023-1729.

– Update yubibomb to version 0.2.12. – Update ybaas to version 0.0.16.

– Update yubibomb to version 0.2.12. – Update ybaas to version 0.0.16.

security update

It was discovered that missing input sanitising in the implementation of the OIDCStripCookie option in mod_auth_openidc could result in denial of service.

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Red Hat AMQ Streams 2.4.0 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in Ruby.

minimatch could be made to crash if it opened a specially crafted input file.

security update

EventSource could leak sensitive information if it opened a specially crafted input file.

The container bci/openjdk was updated. The following patches have been included in this update: