Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Etienne Stalmans discovered that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not validate filenames for traversal outside of the destination directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem

Update to 2.0.1 (fix RHBZ#1998578); fix RHBZ#1932066 (unsafe use of strncpy)

Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)

Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)

Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)

Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)

An XML external entity (XXE) injection in pywps allows an attacker to view files on the application server filesystem by assigning a path to the entity.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

Security release for the 0.4 branch: https://lib.openmpt.org/libopenmpt/2021/08/22/security- updates-0.5.11-0.4.23-0.3.32/

An update that solves 11 vulnerabilities and has 7 fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

The container sles-15-sp3-chost-byos-v20210827 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210827-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20210827-gen2 was updated. The following patches have been included in this update:

security update

Network Controls in the DevSecOps life cycle
Best Linux Backup Solutions to Prevent Data Loss in A Ransomware Attack>

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3338

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3336

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3325

Upstream details at : https://access.redhat.com/errata/RHSA-2020:1021

Upstream details at : https://access.redhat.com/errata/RHSA-2018:3140

An update that solves two vulnerabilities, contains one feature and has one errata is now available.

NTFS-3G could be made to execute arbitrary code if it received a specially crafted image file.

sssd: shell command injection in sssctl (CVE-2021-3621) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Memory leak in the simple access provider * id lookup is failing intermittently * SSSD is NOT able to contact the Global Catalog […]

kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c (CVE-2021-22555) * kernel: race condition for removal of the HCI controller (CVE-2021-32399) * kernel: powerpc: RTAS calls can be used to compromise kernel integrity (CVE-2020-27777) * kernel: Local privilege escalation due to incorrect BPF JIT branch displacement computation (CVE-2021-29154) * kernel: [More…]

bind: Broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly (CVE-2021-25214) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 bind-9.11.4-26.P2.el7_9.7.x86_64.rpm bind-chroot-9.11.4-26.P2.el7_9.7.x86_64.rpm bind-debuginfo-9.11.4-26.P2.el7_9.7.i68 [More…]

libsndfile: Heap buffer overflow via crafted WAV file allows arbitrary code execution (CVE-2021-3246) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 libsndfile-1.0.25-12.el7_9.1.i686.rpm libsndfile-1.0.25-12.el7_9.1.x86_64.rpm libsndfile-debuginfo-1.0.25-12.el7_9.1.i686.rpm li [More…]

hivex: stack overflow due to recursive call of _get_children() (CVE-2021-3622) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 hivex-1.3.10-6.12.el7_9.i686.rpm hivex-1.3.10-6.12.el7_9.x86_64.rpm hivex-debuginfo-1.3.10-6.12.el7_9.i686.rpm hivex-debuginfo-1.3.10-6.12.el7_9.x86_64 [More…]

Where are you on your DevSecOps journey?

security update

APR could be made to expose sensitive information if it received a specially crafted input.

grilo could be made to allow MITM attacks.

An update for libsndfile is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libX11 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several vulnerabilities have been discovered in Exiv2, a C++ library and a command line utility to manage image metadata which could result in denial of service or the execution of arbitrary code if a malformed file is parsed.

An update for libsndfile is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

New upstream stable version 1.24.6; fixes CVE-2021-3716.

New upstream stable version 1.26.5; fixes CVE-2021-3716.

security update

An issue has been found in gthumb, an image viewer and browser. A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c allows attackers to

Michael Catanzaro reported a problem in Grilo, a framework for discovering and browsing media. TLS certificate verification is not enabled on the SoupSessionAsync objects created by Grilo, leaving users vulnerable to network MITM attacks.

– CVE-2021-37750 (explicit NULL deref on KDC)

A security flaw was found on rubygem-addressable that a crafted template may cause DOS. This issue is now assinged as CVE-2021-32740. This new rpm should fix this issue.

A security flaw was found on rubygem-addressable that a crafted template may cause DOS. This issue is now assinged as CVE-2021-32740. This new rpm should fix this issue.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 15 vulnerabilities is now available.

Updated libass packages fix security vulnerability: libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction (CVE-2020-36430).

runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition (CVE-2021-30465).

An update that solves 7 vulnerabilities and has one errata is now available.

An update that solves one vulnerability, contains two features and has 6 fixes is now available.

An update that fixes one vulnerability is now available.

exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE7 — SL7 x86_64 – compat-exiv2-023-0.23-2.el7_9.i686.rpm – compat-exiv2-023-0.23-2.el7_9.x86_64.rpm – compat-exiv2-023-debuginfo-0.23-2.el7_9.i686.rpm – compat- [More…]

exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE7 — SL7 x86_64 – compat-exiv2-026-0.26-3.el7_9.i686.rpm – compat-exiv2-026-0.26-3.el7_9.x86_64.rpm – compat-exiv2-026-debuginfo-0.26-3.el7_9.i686.rpm – compat-e [More…]

libssh could be made to crash or run programs if it received specially crafted network traffic.

An update for servicemesh and servicemesh-proxy is now available for OpenShift Service Mesh 2.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libsndfile is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for python27-babel, python27-python, python27-python-jinja2, and python27-python-pygments is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat’s open approach to vulnerability management
Watch now: 2021 Red Hat Security Symposium on-demand

security update

USN-5037-1 caused a regression in Firefox.

Building a DevSecOps culture and shifting security left

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

security update

security update

Several security issues were fixed in OpenSSL.

Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. CVE-2021-3711

What You Need to Know About Linux Rootkits>

The container suse/sle15 was updated. The following patches have been included in this update:

Several security issues were fixed in the Linux kernel.

update to latest upstream release -fixes CVE-2021-38385

upstream release 1.13.1, including fix for CVE-2021-23358

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that solves two vulnerabilities and has three fixes is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An issue has been found in ircii, an Internet Relay Chat client. A crafted CTCP UTC message could allow an attacker to disconnect the victim from an IRC server due to a segmentation fault and client crash.

Sync with F34 for CVE fixes.

Update to version 2.2.1. Resolves CVE-2021-38512 / RUSTSEC-2021-0081.

An update that fixes four vulnerabilities is now available.