Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Due to a data race in the crossbeam-deque in the crossbeam crate, one or more tasks in the worker queue could have been be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this could have caused a double free and a memory leak (CVE-2021-32810).

New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Several security issues were fixed in MySQL.

Rebase to libssh-0.9.6 Fix CVE-2021-3634

3 focus areas for DevSecOps success

Updated container images that fix various bugs are now available for Red Hat OpenShift Container Storage 3.11 Update 8 in the Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact

Updated packages that provide Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9, and fix an important security issue, are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9 zip release for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact

Bottle could be made to cache malicious requests if it received a specially crafted input.

The updated packages fix a security vulnerabilities: While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Red Hat JBoss Web Server 5.5.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated Red Hat JBoss Web Server 5.5.1 packages are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

security update

security update

Update to 8.6.0.

Squid could be made to crash or expose sensitive information over the network.

DevSecOps tools, culture and misconceptions: Advice from Red Hatters

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated samba packages that fix several bugs with added enhancement are now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated samba packages that fix several bugs with added enhancement are now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Update to 8.6.0.

Imlib2 could be made to denial of service and possibly execute arbitrary code.

Leveraging the “Power of the Crowd” to Fight Cybercrime with a Unique, Collaborative Intrusion Prevention System>

An update that fixes 9 vulnerabilities is now available.

Python could allow unintended access to network services.

Multiple security vulnerabilities have been discovered in fig2dev, utilities for converting XFig figure files. Buffer overflows, out-of-bounds reads and NULL pointer dereferences could lead to a denial-of-service or other unspecified impact.

– Update cranelift crates to version 0.77.0. – Update the wast crate to version 38.0.0. – Update the wat crate to version 1.0.40. – Update the wasmparser crate to version 0.80.1. – Update wasmtime crates to version 0.30.0. – Update the backtrace crate to version 0.3.61. – Update the addr2line crate to version 0.16.0. – […]

– Update cranelift crates to version 0.77.0. – Update the wast crate to version 38.0.0. – Update the wat crate to version 1.0.40. – Update the wasmparser crate to version 0.80.1. – Update wasmtime crates to version 0.30.0. – Update the backtrace crate to version 0.3.61. – Update the addr2line crate to version 0.16.0. – […]

An update that contains security fixes can now be installed.

Update to 94.0.4606.61. Fixes a big pile of security issues: CVE-2021-30542 CVE-2021-30543 CVE-2021-30558 CVE-2021-30625 CVE-2021-30626 CVE-2021-30627 CVE-2021-30628 CVE-2021-30629 CVE-2021-30630 CVE-2021-30631 CVE-2021-30632 CVE-2021-30633 CVE-2021-37972 CVE-2021-37956 CVE-2021-37957 CVE-2021-37958 CVE-2021-37959 CVE-2021-37960 CVE-2021-37961 CVE-2021-37962 CVE-2021-37963

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

Security fix for [PUT CVEs HERE]

One security issue has been discovered in plib. Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

Security fix for [PUT CVEs HERE]

– CVE-2021-22947 – STARTTLS protocol injection via MITM – CVE-2021-22946 – protocol downgrade required TLS bypassed – CVE-2021-22945 – use-after-free and double-free in MQTT sending

An issue has been found in openssl1.0, a Secure Sockets Layer library. The issue is related to read buffer overruns while processing ASN.1 strings.

Two issues have been found in curl, a command line tool and an easy-to-use client-side library for transferring data with URL syntax.

Runtime Analysis in the Red Hat DevSecOps framework

Fix for CVE-2021-20208 Update to 6.13 cifs.upcall: fix regression in kerberos mount mount.cifs: fix crash when mount point does not exist —- Fix for CVE-2021-20208: cifs.upcall kerberos auth leak in container

Fix for CVE-2021-20208 Update to 6.13 cifs.upcall: fix regression in kerberos mount mount.cifs: fix crash when mount point does not exist —- Fix for CVE-2021-20208: cifs.upcall kerberos auth leak in container

Several problems were corrected in TagLib, a library for reading and editing audio meta data. CVE-2017-12678

Several vulnerabilities were fixed in MIT Kerberos, a system for authenticating users and services on a network. CVE-2018-5729

An update for the virt:av and virt-devel:av modules is now available for Red Hat Enterprise Linux Advanced Virtualization 8.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several vulnerabilities were fixed in the chat client WeeChat. CVE-2020-8955

Red Hat AMQ Broker 7.9.0 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

The container sles-15-sp3-chost-byos-v20210927 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210927-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210927-gen2 was updated. The following patches have been included in this update:

An update that fixes one vulnerability is now available.

The Migration Toolkit for Containers (MTC) 1.6.0 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat OpenShift Container Platform release 4.7.32 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

Red Hat OpenShift Container Platform release 4.6.46 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

USN-5090-1 introduced a regression in Apache HTTP Server.

All You Need To Know About IT Security Audits and Its Importance>

Several security issues were fixed in Vim.

USN-5090-1 introduced a regression in Apache HTTP Server.

An update for fwupd, shim, shim-unsigned-aarch64, and shim-unsigned-x64 is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 5 vulnerabilities is now available.

Several security issues were fixed in Apache HTTP Server.

Several security issues were fixed in Apache HTTP Server.

Apache Santuario, XML Security for Java, is vulnerable to an issue where the “secureValidation” property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3438

An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An issue has been found in openssl, a Secure Sockets Layer toolkit. Ingo Schwarze reported a buffer overrun flaw when processing ASN.1 strings, which can result in denial of service.

An update that fixes 19 vulnerabilities is now available.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

Update to latest in git.

update for sharpziplib 1.3.3 which contains a security fix

update for sharpziplib 1.3.3 which contains a security fix

Update to v1.41.1 Fix CVE-2021-39163, CVE-2021-39164

Cumulative bug-fix release from upstream.

– fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)

Rebuild for CVE-2021-3672 in c-ares library

Update to 1.1.1l version

Update to 2.0.1; fix RHBZ#1932066 (unsafe use of strncpy), fix RHBZ#1932066

security update

An update that solves 20 vulnerabilities and has 106 fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Rebase with Security fix for CVE-2021-3781

Update to 1.93, fixes CVE-2020-19752

Fix issue with incorrect obsoletes.

Multiple issues have been discovered in mupdf. CVE-2016-10246

Red Hat Advanced Cluster Management for Kubernetes 2.1.11 General Availability release images, which provide a security fix and update the container images. Red Hat Product Security has rated this update as having a security impact

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.