Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

The container trento/trento-db was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

This is a maintenance release of OpenVPN 2.5 with a security fix when used in server mode ([CVE-2022-0547](https://community.openvpn.net/openvpn/wiki/CVE-2022-0547)). The other changes are available in [Changes.rst](https://github.com/OpenVPN/openvpn/blob/release/2.5/Changes.rst).

Update to 91.7.0

Update to version 1.5.5. This includes a fix for a denial-of-service vulnerability ([RUSTSEC-2022-0013](https://rustsec.org/advisories/RUSTSEC-2022-0013.html) / [CVE-2022-24713](https://cve.mitre.org/cgi- bin/cvename.cgi?name=CVE-2022-24713)).

Fix potential DoS in pesign daemon

An update that fixes one vulnerability, contains one feature is now available.

An update that fixes one vulnerability, contains one feature is now available.

security update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Update to 3.24: fix CVE-2022-26495, CVE-2022-26496

Update to 3.24: fix CVE-2022-26495, CVE-2022-26496

An update that contains security fixes and contains one feature can now be installed.

An update that solves 13 vulnerabilities and has three fixes is now available.

An update that contains security fixes and contains one feature can now be installed.

OpenSSL could be made to stop responding if it opened a specially crafted certificate.

Tavis Ormandy discovered that the BN_mod_sqrt() function of OpenSSL could be tricked into an infinite loop. This could result in denial of service via malformed certificates.

rsh would allow unintended modification of target directory permissions.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

10 Common Security Mistakes Sysadmins Make & How To Avoid These Pitfalls>

security update

security update

security update

Command injection in ruby bundler. (CVE-2021-43809) References: – https://bugs.mageia.org/show_bug.cgi?id=30162 – https://blog.sonarsource.com/securing-developer-tools-package-managers

This kernel-linus update is based on upstream 5.15.28 and fixes at least the following security issues: Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially

This kernel update is based on upstream 5.15.28 and fixes at least the following security issues: Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially

The chromium-browser-stable package has been updated to the 99.0.4844.51 version that fixes multiples security vulnerabilities. References: – https://bugs.mageia.org/show_bug.cgi?id=29988

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

A flaw was discovered in the way HAProxy, a fast and reliable load balancing reverse proxy, processes HTTP responses containing the “Set-Cookie2” header, which can result in an unbounded loop, causing a denial of service.

The update for expat released as DSA 5085-1 introduced regressions for applications using URI characters (‘:’ in particular) for a namespace separator (while the HTML API docs of function XML_ParserCreateNS have been advising against their use). Updated expat packages are now

Emmet Leahy reported that libphp-adodb, a PHP database abstraction layer library, allows to inject values into a PostgreSQL connection string. Depending on how the library is used this flaw can result in authentication bypass, reveal a server IP address or have other

Improve your hybrid cloud security with these 3 tips

Two vulnerabilities were discovered in the server for the Network Block Device (NBD), which could result in the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed

The container sles-15-sp3-chost-byos-v20220310 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220310-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220310-gen2 was updated. The following patches have been included in this update:

Null pointer dereference in MD_UPDATE. (CVE-2021-4209) References: – https://bugs.mageia.org/show_bug.cgi?id=30112 – https://lists.suse.com/pipermail/sle-security-updates/2022-March/010333.html

security update

security update

Multiple security vulnerabilities have been discovered in vim, an enhanced vi editor. Buffer overflows, out-of-bounds reads and Null pointer dereferences may lead to a denial of service (application crash) or other unspecified impact.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

– New upstream update (98.0)

Update Chromium to 99.0.4844.51. Fixes, well, a LOT of security bugs. Sorry about that. CVE-2021-22570 CVE-2022-0096 CVE-2022-0097 CVE-2022-0098 CVE-2022-0099 CVE-2022-0100 CVE-2022-0101 CVE-2022-0102 CVE-2022-0103 CVE-2022-0104 CVE-2022-0105 CVE-2022-0106 CVE-2022-0107 CVE-2022-0108 CVE-2022-0109 CVE-2022-0110 CVE-2022-0111 CVE-2022-0112 CVE-2022-0113

Bugfix release. fixes CVE-2022-0518 2055256, 2055130 – https://github.com/radare org/radare2/commit/9650e3c352f675687bf6c6f65ff2c4a3d0e288fa fixes CVE-2022-0519 2055103, 2055104 – https://github.com/radareorg/radare2/commit/6c4428f018d385fc8 0a33ecddcb37becea685dd5 fixes CVE-2022-0520 2055145, 2055146 – https://github.co m/radareorg/radare2/commit/8525ad0b9fd596f4b251bb3d7b114e6dc7ce1ee8 fixes

security update

security update

security update

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, spoofing or sandbox bypass.

An update that solves one vulnerability and has two fixes is now available.

An update that solves two vulnerabilities and has 11 fixes is now available.

Several security issues and a regression were fixed in Expat.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, spoofing or sandbox bypass.

New mozilla-thunderbird packages are available for Slackware 15.0, and -current to fix security issues.

security update

security update

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities, contains one feature is now available.

security update

security update

security update

security update

It was discovered that SPIP, a website engine for publishing, would allow a malicious user to execute arbitrary code. For the oldstable distribution (buster), this problem has been fixed

Redis could be made to run programs if it received specially crafted network traffic from an authenticated user.

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

Nmap Firewall Evasion Techniques>

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in OpenJDK.

Several security issues were fixed in GNU C Library.

Several vulnerabilities have been discovered in Expat, an XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code, if a malformed XML file is processed.

Several security issues were fixed in PHP.

A command injection vulnerability was found in FreeCAD, a parametric 3D modeler, when importing DWF files with crafted filenames. For Debian 9 stretch, this problem has been fixed in version

Several issues have been found in tiff, a library and tools to manipulate and convert files in the Tag Image File Format (TIFF). CVE-2022-22844

It was discovered that the SQL plugin in cyrus-sasl2, a library implementing the Simple Authentication and Security Layer, is prone to a SQL injection attack. An authenticated remote attacker can take advantage

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free (CVE-2022-26485). An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape (CVE-2022-26486).

A bug was found in containerd where containers launched through containerd’s CRI implementation with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive

Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. (CVE-2022-0561)

An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity. (CVE-2021-36370)

An update that fixes one vulnerability is now available.

An update that fixes 15 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

An update that solves two vulnerabilities, contains two features and has two fixes is now available.

An update that fixes two vulnerabilities is now available.