Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Update to WebKitGTK 2.34: * Add support for CSS Scroll Snap. * Add support for date and datetime-local input elements. * Add support for display capture. * Add support for ICC color management. * Add support color-schemes CSS property. * Add multi-track support to MSE media backend. * Add new API to handle web process […]

security update

Two SQL injection vulnerabilities were discovered in SQLAlchemy, a SQL toolkit and Object Relational Mapper for Python, when the order_by or group_by parameters can be controlled by an attacker.

An update that solves two vulnerabilities and has one errata is now available.

DSE measures and improves DevOps

An update that fixes one vulnerability is now available.

An update that fixes 15 vulnerabilities is now available.

The 5.14.16 stable kernel update contains a number of important fixes across the tree.

The 5.14.16 stable kernel update contains a number of important fixes across the tree.

The binary got built with Fedora mandatory compiler flags.

An update that fixes 15 vulnerabilities is now available.

Technically Speaking series decodes DevSecOps

There were a couple of vulnerabilites found in src:python3.5, the Python interpreter v3.5, and are as follows: CVE-2021-3733

This update upgrades Thunderbird to version 91.3.0. * Mozilla: Use-after-free in HTTP2 Session object * Mozilla: Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3 * Mozilla: iframe sandbox rules did not apply to XSLT stylesheets (CVE-2021-38503) * Mozilla: Use-after-free in file picker dialog (CVE-2021-38504) * Mozilla: Firefox could be coaxed into going […]

Stefan Walter found that udisks2, a service to access and manipulate storage devices, could cause denial of service via system crash if a corrupted or specially crafted ext2/3/4 device or image was mounted, which could happen automatically on certain environments.

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Rust 1.56.1 adds a mitigation for CVE-2021-42574, the “trojan source” attack that obfuscates code with BiDi control characters. The compiler will now error on such characters in code comments and string/char literals. For more details, see the upstream [security advisory](https://blog.rust- lang.org/2021/11/01/cve-2021-42574.html).

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This update upgrades Firefox to version 91.3.0 ESR. * Mozilla: Use-after-free in HTTP2 Session object * Mozilla: Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3 * Mozilla: iframe sandbox rules did not apply to XSLT stylesheets (CVE-2021-38503) * Mozilla: Use-after-free in file picker dialog (CVE-2021-38504) * Mozilla: Firefox could be coaxed into […]

The 5.14.15 stable kernel update contains a number of important fixes across the tree.

Top 6 Vulnerability Scanning Tools>

An update that solves two vulnerabilities and has two fixes is now available.

An update is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The container sles-15-sp3-chost-byos-v20211101 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20211101-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20211101-gen2 was updated. The following patches have been included in this update:

security update

security update

An update that fixes 12 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Red Hat OpenShift Virtualization release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that solves two vulnerabilities and has one errata is now available.

Red Hat OpenShift Virtualization release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for flatpak is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in WebKitGTK.

An update for flatpak is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The package bind before version 9.16.22-1 is vulnerable to denial of service.

The package freerdp before version 2:2.4.1-1 is vulnerable to arbitrary code execution.

The package wpewebkit before version 2.34.1-1 is vulnerable to multiple issues including arbitrary code execution and sandbox escape.

The package webkit2gtk before version 2.34.1-1 is vulnerable to multiple issues including arbitrary code execution and sandbox escape.

The package opera before version 80.0.4170.63-1 is vulnerable to multiple issues including arbitrary code execution and sandbox escape.

The package chromium before version 95.0.4638.69-1 is vulnerable to multiple issues including arbitrary code execution and insufficient validation.

security update

security update

Several security vulnerabilities have been discovered in OpenCV, the Open Computer Vision Library. Buffer overflows, NULL pointer dereferences and out-of-bounds write errors may lead to a denial-of-service or other unspecified impact.

An update that fixes 16 vulnerabilities is now available.

security update

An issue has been found in cups, the Common UNIX Printing System. Due to an input validation issue a malicious application might be allowed to read restricted memory.

Update to 2.34.1: * Update user agent browser versions. * Fix a crash with GTK >= 3.24.30. * Fix a crash when loading videos on reddit. * Fix file type detection when application calls g_desktop_app_info_set_as_default_for_extension() passing html. * Security fixes: CVE-2021-42762

Fix for CVE-2021-41990 and CVE-2021-41991

# New in release OpenJDK 11.0.13 (2021-10-19): Live versions of these release notes can be found at: * https://bitly.com/openjdk11013 * https://builds.shipilev.net/backports-monitor/release-notes-11.0.13.txt ## Security fixes – JDK-8163326, CVE-2021-35550: Update the default enabled cipher suites preference – JDK-8254967, CVE-2021-35565:

Could “Unbreakable” Oracle Linux be the Logical Enterprise-Ready CentOS Replacement?>

This update includes the changes in tzdata 2021e for the Perl bindings. For the list of changes, see DLA-2797-1. For Debian 9 stretch, this problem has been fixed in version

This update includes the changes in tzdata 2021e. Notable changes are: – – Fiji suspends DST for the 2021/2022 season.

A security vulnerability was discovered in gpsd, the Global Positioning System daemon. A stack-based buffer overflow may allow remote attackers to execute arbitrary code via traffic on port 2947/TCP or crafted JSON inputs.

The container suse/sle15 was updated. The following patches have been included in this update:

security update

security update

Two issues have been found in jbig2dec, a JBIG2 decoder library. One issue is related to an overflow with a crafted image file. The other is related to a NULL pointer dereference.

The following vulnerabilities have been discovered in the wpewebkit web engine: CVE-2021-30846

Bind could be made to consume resources if it received specially crafted network traffic.

Red Hat OpenShift Container Platform release 3.11.542 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

One security issue has been discovered in mosquitto: MQTT message broker. A null dereference vulnerability was found which could lead to crashes for applications using the library.

An update that fixes two vulnerabilities is now available.

An update that solves two vulnerabilities, contains one feature and has one errata is now available.

An update that fixes 5 vulnerabilities is now available.

Do host firewalls matter in cloud deployments?
Lead Cloud-Native Security Analytics Engineer Shares Top Tips for Securing the Enterprise >

It was discovered that Qt incorrectly handled certain XBM image files. If a user or automated system were tricked into opening a specially crafted PPM file, a remote attacker could cause Qt to crash, resulting in a denial of service. (CVE-2020-17507)

It was discovered that openCryptoki incorrectly handled certain EC keys. An attacker could possibly use this issue to cause a invalid curve attack. References: – https://bugs.mageia.org/show_bug.cgi?id=29328

security update

security update

An update is now available for Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.9.4 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.

An update that fixes 16 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

Several security issues were fixed in libslirp.

Apport could be made to create files as the administrator.

An update for redis is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This kernel-linus update is based on upstream 5.10.75 and fixes atleast the following security issues: A memory leak in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ ccp/ccp-ops.c in the Linux kernel allows malicious users to cause a

This kernel update is based on upstream 5.10.75 and fixes atleast the following security issues: A memory leak in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ ccp/ccp-ops.c in the Linux kernel allows malicious users to cause a

Several security issues were fixed in GNU binutils.

Several security issues were fixed in MySQL.

An update that solves 6 vulnerabilities and has four fixes is now available.

This update provides the upstream 6.1.28 maintenance release that fixes atleast the following security vulnerabilities: Vulnerability in the Oracle VM VirtualBox prior to 6.1.28 contains an easily exploitable vulnerability that allows high privileged attacker with

Several issues have been found in faad2, a freeware Advanced Audio Decoder player. They are related to heap buffer overflows or null pointer dereferences, which both might allow an attacker to execute code by

security update

Do not include params in exception when a call to set_options fails. Additionally, block the exception that is returned from being displayed to stdout. (CVE-2021-3620) References:

Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other host-OS services into treating the Flatpak app as though it was an ordinary, non-sandboxed host-OS process, by manipulating the VFS using recent mount-related syscalls that are not blocked by Flatpak’s denylist seccomp

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. (CVE-2021-30640) Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66

A bug was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky.