Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

What You Need to Know About Open-Source Software Security

Several integer overflows have been discovered in TurboJPEG, a JPEG image library, which can lead to a denial of service (application crash) if someone attempts to compress or decompress gigapixel images with the TurboJPEG API.

– Update to 1.1.2. Fixes rhbz#2085287. – Mitigate CVE-2022-29162 / GHSA-f3fp- gc8g-vw66.

Update to pcre2-10.40, see https://github.com/PCRE2Project/pcre2/blob/pcre2-10.40/NEWS for details.

Several security issues were fixed in CUPS.

Red Hat Compliance service and the Red Hat Insights API
A Complete Guide to Torrenting Safely in 2022

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

security update

security update

A malicious source package could write files outside the unpack directory.

An update for the maven:3.5 module is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Extended Update Support, and Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for rsyslog is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for rsyslog is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

An update that fixes 10 vulnerabilities is now available.

Peter Agten discovered that several modules for TCP syslog reception in rsyslog, a system and kernel logging daemon, have buffer overflow flaws when octet-counted framing is used, which could result in denial of service or potentially the execution of arbitrary code.

Smarty3 is a template engine for PHP. It was found that template authors could inject PHP code by choosing a malicious {block} name or {include} file name. For Debian 9 stretch, this problem has been fixed in version

A flaw was found in the check_chunk_name() function of pngcheck, a tool to verify the integrity of PNG, JNG and MNG files. This flaw allows an attacker who can pass a malicious file to be processed by pngcheck to cause a temporary denial of service.

Several security vulnerabilities have been discovered in smarty3, the compiling PHP template engine. Template authors are able to run restricted static php methods or even arbitrary PHP code by crafting a malicious math string or by choosing an invalid {block} or {include} file name. If a math string was passed

security update

This kernel-linus update is based on upstream 5.15.43 and fixes at least the following security issues: A race condition in the perf subsystem allows for a local privilege escalation. NOTE: Mageia kernels by default has disabled the perf usage

This kernel update is based on upstream 5.15.43 and fixes at least the following security issues: A race condition in the perf subsystem allows for a local privilege escalation. NOTE: Mageia kernels by default has disabled the perf usage

The chromium-browser-stable package has been updated to the 102.0.5005.61 version, fixing many bugs and 32 CVE. Some of them are listed below: CVE-2022-1853: Use after free in Indexed DB. CVE-2022-1854: Use after free in ANGLE. CVE-2022-1855: Use after free in Messaging.

The syscall.Faccessat function checks whether the calling process can access a file. Faccessat contains a bug where it checks a file’s group permission bits if the process’s user is a member of the process’s group rather than a member of the file’s group. (CVE-2022-29526)

ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a. (CVE-2018-25033) References:

MITM vulnerability when DNSSEC wasn’t used (CVE-2022-26491) References: – https://bugs.mageia.org/show_bug.cgi?id=30438 – https://lists.suse.com/pipermail/sle-security-updates/2022-May/011017.html

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

security update

security update

It was discovered that the previous upload to neutron to Debian 9 “Stretch” (ie. version 2:9.1.1-3+deb9u2) was incomplete and did not actually apply the fix for CVE-2021-40085.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Several security issues were fixed in OpenSSL.

Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious ‘fzsftp’ binary in the user’s home directory.

Several security issues were fixed in subversion.

security update

security update

Max Justicz reported a directory traversal vulnerability in Dpkg::Source::Archive in dpkg, the Debian package management system. This affects extracting untrusted source packages in the v2 and v3 source package formats that include a debian.tar.

Max Justicz reported a directory traversal vulnerability in Dpkg::Source::Archive in dpkg, the Debian package management system. This affects extracting untrusted source packages in the v2 and v3 source package formats that include a debian.tar.

An update that fixes one vulnerability is now available.

An update that fixes 15 vulnerabilities is now available.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

This update upgrades Firefox to version 91.9.1 ESR. * Mozilla: Untrusted input used in JavaScript object indexing, leading to prototype pollution (CVE-2022-1529) * Mozilla: Prototype pollution in Top-Level Await implementation (CVE-2022-1802) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 [More…]

Multiple security vulnerabilities were discovered in Puma, a HTTP server for Ruby/Rack applications, which could result in HTTP request smuggling or information disclosure.

Multiple vulnerabilities have been discovered in the lrzip compression program which could result in denial of service or potentially the execution of arbitrary code.

Automating firewall configuration with RHEL System Roles

An update that solves one vulnerability, contains one feature and has two fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

security update

security update

security update

Complete Guide to Keylogging in Linux: Part 1>

Several security issues were fixed in libpng.

Several security issues were fixed in Thunderbird.

Firefox could be made to execute JavaScript in a privileged context if it opened a malicious website.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

The updated postgresql packages fix a security vulnerability: Autovacuum, REINDEX, and others omit “security restricted operation” sandbox (CVE-2022-1552).

Manfred Paul discovered two security issues in the Mozilla Firefox web browser, which could result in the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed

Nokogiri did not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a ‘String’ by calling ‘#to_s’ or equivalent.

This update provides ffmpeg version 4.3.4, which fixes several security vulnerabilities and other bugs which were corrected upstream. References: – https://bugs.mageia.org/show_bug.cgi?id=30444

Updated nvidia-current packages fix security vulnerabilities: NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead

Updated nvidia390 packages fix security vulnerabilities: NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead

This kernel-linus update is based on upstream 5.15.41 and fixes at least the following security issues: A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel BPF subsystem

This kernel update is based on upstream 5.15.41 and fixes at least the following security issues: A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel BPF subsystem

Updated microcodes for Intel processors, fixing various functional issues, and at least the following security issues: Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to

A bug was found in runc where runc exec –cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

security update

security update

Fabian Vogt and Dominik Penner discovered that the Ark archive manager did not sanitize extraction paths, which could result in maliciously crafted archives with symlinks writing outside the extraction directory.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has one errata is now available.

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

OpenLDAP could be made to perform arbitrary modifications to the database.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2022:4642

security update

security update

security update

What You Need to Know about the Sysrv-K Cryptomining Botnet in Less than a Minute>