Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Firefox 89.0.1 Released to Improve WebRender Performance, Fix Scrollbars on GTK Themes>

Several security issues were fixed in Apache HTTP Server.

Several security issues were fixed in Dovecot.

Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613

Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613

Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613

Backport fix for CVE-2021-3589 and a heap buffer overflow.

Backport fix for CVE-2021-3589 and a heap buffer overflow.

security update

security update

It was discovered that the previous upload of the package prosody versioned 0.9.12-2+deb9u3 introduced a regression in the mod_auth_internal_hashed module. Big thanks to Andre Bianchi for the reporting an issue and for testing the update.

Update to 1.6.15 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive.

CVE-2021-3560 mitigation

Backport fix for CVE-2021-33503.

2.0.11 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive. Broker Fix possible crash having just upgraded from 1.6 if per_listener_settings true is set, and a SIGHUP is sent to the broker before a client has […]

This updates nettle to the latest upstream release 3.7.3, which contains security fix for RSA decryption: https://lists.lysator.liu.se/pipermail/nettle- bugs/2021/009545.html

The package connman before version 1.40-1 is vulnerable to arbitrary code execution.

The package grub before version 2:2.06-1 is vulnerable to multiple issues including access restriction bypass and arbitrary code execution.

The package go before version 2:1.16.5-1 is vulnerable to multiple issues including insufficient validation, url request injection and denial of service.

Multiple security vulnerabilities were discovered in Tor, a connection-based low-latency anonymous communication system, which could result in denial of service or spoofing.

Several security issues were fixed in GRUB 2.

An update that solves two vulnerabilities and has one errata is now available.

Several security issues were fixed in libxml2.

The package python-django before version 3.2.4-1 is vulnerable to multiple issues including insufficient validation and directory traversal.

The package radare2 before version 5.3.1-1 is vulnerable to denial of service.

The package thefuck before version 3.31-1 is vulnerable to arbitrary file overwrite.

The package aspnet-runtime-3.1 before version 3.1.16.sdk116-1 is vulnerable to denial of service.

The package aspnet-runtime before version 5.0.7.sdk204-1 is vulnerable to denial of service.

security update

Upstream details at : https://access.redhat.com/errata/RHSA-2018:3140

Upstream details at : https://access.redhat.com/errata/RHSA-2021:1512

Several security issues were fixed in BlueZ.

Several security issues were fixed in BlueZ.

An update for gupnp is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openvswitch2.11 is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362) * kernel: Use after free via PI futex state (CVE-2021-3347) * kernel: use-after-free in n_tty_receive_buf_common function in drivers/tty/n_tty.c (CVE-2020-8648) * kernel: Improper input validation in some Intel(R) Graphics Drivers (CVE-2020-12363) * kernel: Null pointer dereference in some Intel(R) Graphics Drivers (CVE [More…]

An update for ceph, ceph-ansible, ceph-iscsi, python-waitress, and tcmu-runner is now available for Red Hat Ceph Storage 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Open Liberty 21.0.0.6 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in ImageMagick.

gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services (CVE-2021-33516) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 gupnp-1.0.2-6.el7_9.i686.rpm gupnp-1.0.2-6.el7_9.x86_64.rpm gupnp-debuginfo-1.0.2-6.el7_ [More…]

Red Hat OpenShift Container Platform release 4.7.16 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

Openshift Logging Bug Fix Release (5.0.5) This release includes a security update. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for dhcp is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

dhcp: stack-based buffer overflow when parsing statements with colon- separated hex digits in config or lease files in dhcpd and dhclient (CVE-2021-25217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 dhclient-4.2.5-83.el7_9.1.x86_64.rpm dhcp-4.2.5-83.el7_9.1.x86_64.rpm dhcp [More…]

hw: vt-d related privilege escalation (CVE-2020-24489) * hw: improper isolation of shared resources in some Intel Processors (CVE-2020-24511) * hw: observable timing discrepancy in some Intel Processors (CVE-2020-24512) * hw: information disclosure on some Intel Atom processors (CVE-2020-24513) Bug Fix(es) and Enhancement(s): * Update Intel CPU microcode to microcode-20210525 release — [More…]

Several vulnerabilities were discovered in Squid, a proxy caching server. CVE-2021-28651

An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The container suse-sles-15-sp2-chost-byos-v20210610-gen2 was updated. The following patches have been included in this update:

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

Add proposed patches for CVE-2021-29338 and a heap buffer overflow.

security update

The package wireshark-cli before version 3.4.6-1 is vulnerable to denial of service.

The package kube-apiserver before version 1.21.1-1 is vulnerable to insufficient validation.

The package nettle before version 3.7.3-1 is vulnerable to denial of service.

The package isync before version 1.4.2-1 is vulnerable to arbitrary code execution.

The package python-websockets before version 9.1-1 is vulnerable to private key recovery.

The package python-urllib3 before version 1.26.5-1 is vulnerable to denial of service.

security update

security update

An update for servicemesh-operator is now available for OpenShift Service Mesh 2.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

libwebp could be made to crash or run programs as your login if it opened a specially crafted file.

An update for the postgresql:13 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the container-tools:3.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

rxvt, VT102 terminal emulator for the X Window System, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

mrxvt, lightweight multi-tabbed X terminal emulator, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

eterm, an enlightened terminal emulator, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).

Red Hat OpenShift Container Platform release 3.11.452 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 3.11.

An update that fixes three vulnerabilities is now available.

Identity and access in the DevSecOps life cycle

Several security issues were fixed in Intel Microcode.

Memory safety bugs fixed in Firefox 89 and Firefox ESR 78.11 Mozilla developers Gabriele Svelto, Anny Gakhokidze, Alexandru Michis, Christian Holler reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been […]

Fixed format string vulnerability allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file (CVE-2021-30145). References: – https://bugs.mageia.org/show_bug.cgi?id=29058 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QVXB4F67QODLPKYBZX7SBXTE7ESGKGOD/

This update patches the vendored `smallvec` Rust crate in librsvg to fix a security vulnerability: The Iterator implementation mishandles destructors, leading to a double free (CVE-2021-25900). References:

A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability (CVE-2021-20193). References: – https://bugs.mageia.org/show_bug.cgi?id=29049 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XRDSUUE3LUKBDRLPB7GTT5QZRPV5J7O4/

Exponential entity expansion attack bypasses all existing protection mechanisms. (CVE-2021-3541). References: – https://bugs.mageia.org/show_bug.cgi?id=29039 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/NYSYJVWYEQHFG2TBIQJRJ5COUR5LNFJJ/

A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a […]

USN-4937-1 introduced a regression in GNOME Autoar.

USN-4969-1 introduced a regression in DHCP.

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libwebp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

Multiple security issues have been discovered in libwebp CVE-2018-25009

An update that solves 12 vulnerabilities and has 23 fixes is now available.

An update that fixes 21 vulnerabilities is now available.

Several security issues were fixed in the Linux kernel.

security update

New version 3.4.5, Fix for CVE-2021-22207.

Fix for CVE-2021-25217

New version 3.4.5, Fix for CVE-2021-22207.

security update

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. In adddition two security issues were addressed in the OpenPGP support.

An update that fixes one vulnerability is now available.

Apply fix for CVE-2021-3500. —- Apply fix for CVE-2021-32490, CVE-2021-32491, CVE-2021-32492, CVE-2021-32493

Backport fixes for CVE-2021-32617, CVE-2021-29623.