Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

security update

Several security issues were fixed in MariaDB.

Expat could be made to crash or execute arbitrary code.

Expat could be made to crash or execute arbitrary code.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

Understanding open source software supply chain risks

An update that fixes one vulnerability is now available.

Several security issues were fixed in FreeRDP.

Several security issues were fixed in FreeRDP.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 10 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Keeping Your Private Files Private: An Introduction to GNU Privacy Guard

An update that fixes two vulnerabilities is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

security update

security update

security update

Red Hat Enterprise Linux and Microsoft security update of November 2022

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

security update

It was discovered that php-phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v2), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

Expat could be made to crash or execute arbitrary code.

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

security update

security update

security update

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 xorg-x11-server-Xephyr-1.20.4-19.el7_9.x86_64.rpm xorg- [More…]

xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 xorg-x11-server-Xephyr-1.20.4-19.el7_9.x86_64.rpm xorg- [More…]

An update that fixes one vulnerability is now available.

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, create open redirects, bypass authorization access, or perform Cross-Site Request Forgery (CSRF) or Cross-Site Scripting (XSS) attacks.

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, create open redirects, bypass authorization access, or perform Cross-Site Request Forgery (CSRF) or Cross-Site Scripting (XSS) attacks.

Several bugs were discovered in PostgreSQL, a relational database server system. This new LTS minor version update fixes over 25 bugs that were reported in the last several months. The complete and detailed list of issues could be found at: https://www.postgresql.org/docs/release/11.18.

Several bugs were discovered in PostgreSQL, a relational database server system. This new LTS minor version update fixes over 25 bugs that were reported in the last several months. The complete and detailed list of issues could be found at: https://www.postgresql.org/docs/release/11.18.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

security update

security update

Complete Guide to Ethical Hacking on Linux

An update that fixes 6 vulnerabilities is now available.

An update for libksba is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for device-mapper-multipath is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An issue was discovered in Dropbear, a relatively small SSH server and client. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it was possible for an SSH server to change the login process in its favor. This attack can bypass

There were a couple of secuity issues found in sysstat, system performance tools for Linux, which are as follows: CVE-2019-16167

Update to 4.19.0, fixes CVE-2021-46848.

libiberty: Heap/stack buffer overflow in the dlang_lname function in d-demangle.c (CVE-2021-3826) binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcopy.c via a crafted file (CVE-2022-38533)

libiberty: Heap/stack buffer overflow in the dlang_lname function in d-demangle.c (CVE-2021-3826) binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcopy.c via a crafted file (CVE-2022-38533)

LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-3599) LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in

LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-3599) LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in

In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y. (CVE-2022-44638) References:

In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y. (CVE-2022-44638) References:

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Maddie Stone reported a heap-based buffer overflow flaw in pixman, a pixel-manipulation library for X and cairo, which could result in denial of service or potentially the execution of arbitrary code.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

security update

security update

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

A vulnerability has been found in lesspipe which could result in arbitrary code execution.

A vulnerability has been found in lesspipe which could result in arbitrary code execution.

This is the October 2022 monthly update for .NET 6. It updates the SDK to 6.0.110 and the Runtime to 6.0.10. This update includes a fix for CVE 2022-41032

This is the October 2022 monthly update for .NET 6. It updates the SDK to 6.0.110 and the Runtime to 6.0.10. This update includes a fix for CVE 2022-41032