Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that solves 38 vulnerabilities and has 9 fixes is now available.

An update that solves 43 vulnerabilities and has 16 fixes is now available.

It was discovered that there was a potential remote denial of service vulnerability in node-trim-newlines, a Javascript module to strip newlines from the start and/or end of a string.

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

security update

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

security update

Fix buggy patch to CVE-2022-46340

Security fix for CVE-2022-41854

Release notes for xrdp v0.9.21 (2022/12/10) General announcements – Running xrdp and xrdp-sesman on separate hosts is still supported by this release, but is now deprecated. This is not secure. A future v1.0 release will replace the TCP socket used between these processes with a Unix Domain Socket, and then cross-host running will not be […]

Security fixes for CVE-2022-37966, CVE-2022-37967 and CVE-2022-38023

Update to 102.6.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2022-53/ ; https://www.thunderbird.net/en- US/thunderbird/102.6.0/releasenotes/

Security fix for CVE-2022-41854

An update that fixes 7 vulnerabilities is now available.

The container sles-15-sp4-chost-byos-v20221215-arm64 was updated. The following patches have been included in this update:

The container sles-15-sp4-chost-byos-v20221118-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20221215-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20221215-x86_64-gen2 was updated. The following patches have been included in this update:

The container sles-15-sp3-chost-byos-v20221215-x86-64 was updated. The following patches have been included in this update:

Red Hat Government Symposium 2022: Unleashing innovation, powering missions
Lynis: A Linux Security Audit Tool You Should Know About

Multiple vulnerabilities have been discovered in NSS, the worst of which could result in arbitrary code execution.

A vulnerability has been discovered in LibreOffice which could result in arbitrary script execution via crafted links.

Multiple vulnerabilities have been discovered in Unbound, the worst of which could result in denial of service.

Multiple vulnerabilities have been found in curl, the worst of which could result in arbitrary code execution.

Update to version 4.17.4

xwayland 22.1.6 Fixes CVE-2022-46340, CVE-2022-46341, CVE-2022-46342, CVE-2022-46343, CVE-2022-46344, CVE-2022-4283

Automate like an expert with Ansible validated content

An update that fixes 7 vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

advancecomp has been updated to fix a number of bugs and security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=31234 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/KQHLMLFHPV5C7PTBZML6U72QT6VNEOEF/

Update to 102.6.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2022-53/ ; https://www.thunderbird.net/en- US/thunderbird/102.6.0/releasenotes/

security update

security update

An update that fixes 6 vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

New version 4.0.2

New version 3.6.10

– New upstream release (108.0)

CVE fixes for: CVE-2022-4283, CVE-2022-46340, CVE-2022-46341, CVE-2022-46342, CVE-2022-46343, CVE-2022-46344

Update to 2.9.0 (CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319, CVE-2022-39320, CVE-2022-41877 and CVE-2022-39347).

Update to upstream release 3.0.26.

Update to 2.9.0 (CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319, CVE-2022-39320, CVE-2022-41877 and CVE-2022-39347). —- Update to 2.8.1 (CVE-2022-39282, CVE-2022-39283).

An update that fixes 5 vulnerabilities is now available.

Large-Scale Phishing Campaign Floods Open-Source Repositories with 144,000 Packages

security update

Using system tags to enable extended security hardening recommendations
Beyond the STIG: The wider world of cybersecurity

The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

Several security issues were fixed in X.Org X Server.

security update

An update that contains security fixes can now be installed.

An update that solves 12 vulnerabilities, contains one feature and has two fixes is now available.

An update that solves 12 vulnerabilities, contains one feature and has two fixes is now available.

An update that contains security fixes can now be installed.

An update that fixes 12 vulnerabilities, contains one feature is now available.

Several security issues were fixed in containerd.

Timothee Desurmont discovered an information leak vulnerability in node-eventsource, a W3C compliant EventSource client for Node.js: the module was not honoring the same-origin-policy and upon following a redirect would leak cookies to the the target URL.

Deception Technology for Linux: How to Trick Cyber Criminals into Focusing on a Decoy

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Multiple security vulnerabilities have been found in OpenEXR, command-line tools and a library for the OpenEXR image format. Buffer overflows or out-of-bound reads could lead to a denial of service (application crash) if a malformed image file is processed.

security update

An update that fixes one vulnerability is now available.

Security fix for CVE-2022-3500 Proper exception handling in tornado_requests

Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing

Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing

Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing

An update that fixes one vulnerability is now available.

security update

Zhang Boyang reported that the grub2 update released as DLA 3190-1 did not correctly apply fixes for CVE-2022-2601 and CVE-2022-3775. Updated packages are now available to address this issue. For reference the original advisory text follows.

Update the capnp crate to version 0.14.11 to address CVE-2022-46149 / RUSTSEC-2022-0068. This update also includes a rebuild of the only affected application (the Sequoia PGP plugin for Thunderbird).

Update the capnp crate to version 0.14.11 to address CVE-2022-46149 / RUSTSEC-2022-0068. This update also includes a rebuild of the only affected application (the Sequoia PGP plugin for Thunderbird).

Update the capnp crate to version 0.14.11 to address CVE-2022-46149 / RUSTSEC-2022-0068. This update also includes a rebuild of the only affected application (the Sequoia PGP plugin for Thunderbird).

Update the capnp crate to version 0.14.11 to address CVE-2022-46149 / RUSTSEC-2022-0068. This update also includes a rebuild of the only affected application (the Sequoia PGP plugin for Thunderbird).

updates to screenshooter,settings, and places-plugin

The container bci/bci-busybox was updated. The following patches have been included in this update:

Fix a possible double free in `woffEncode()`. – Update License to SPDX – improved summary and description – Add hand-written man pages – Install HTML format description as documentation

Openshift Logging Bug Fix Release (5.3.14) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.