Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

New expat packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Pulling Back the Curtain: About LinuxSecurity.com>

An update that fixes 24 vulnerabilities is now available.

Several security issues were fixed in Pillow.

An update for httpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Update to 1.12.3 Fixes these two security issues: * CVE-2021-43860 or https://github.com/flatpak/flatpak/security/advisories/GHSA-qpjc-vq3c-572j * CVE-2022-21682 or https://github.com/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx Full release notes: https://github.com/flatpak/flatpak/releases/tag/1.12.3

It was discovered that sphinxsearch, a fast standalone full-text SQL search engine, could allow arbitrary files to be read by abusing a configuration option.

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 9 stretch, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, denial of service or spoofing.

security update

security update

Security fix for CVE-2021-4122

– kombu 5.2.3: https://github.com/celery/kombu/blob/master/Changelog.rst#523 – celery 5.2.3: https://github.com/celery/celery/blob/master/Changelog.rst#523

– kombu 5.2.3: https://github.com/celery/kombu/blob/master/Changelog.rst#523 – celery 5.2.3: https://github.com/celery/celery/blob/master/Changelog.rst#523

Update to 0.9.6, see https://github.com/uriparser/uriparser/blob/uriparser-0.9.6/ChangeLog for details.

Network Intrusion Detection Using Snort>

CPAN 2.28 allows Signature Verification Bypass. (CVE-2020-16156) References: – https://bugs.mageia.org/show_bug.cgi?id=29878 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SZ32AJIV4RHJMLWLU5QULGKMMIHYOMDC/

This update provides Mbed TLS 2.16.12, with a number of bug fixes and a security fix. Mbed TLS has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. (CVE-2021-44732)

A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp. (CVE-2021-3997) References:

CWE-122 Heap-based Buffer Overflow (CVE-2021-4136) CWE-125 Out-of-bounds Read (CVE-2021-4166) CWE-416 Use After Free (CVE-2021-4173) CWE-416 Use After Free (CVE-2021-4187)

Buffer overflow vulnerability in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp. (CVE-2021-40985) References:

security update

The 5.15.14 stable kernel update contains a number of important fixes across the tree.

kernel: perf_event_parse_addr_filter memory (CVE-2020-25704) * kernel: fuse: fuse_do_getattr() calls make_bad_inode() in inappropriate situations (CVE-2020-36322) * kernel: Heap buffer overflow in firedtv driver (CVE-2021-42739) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * [More…]

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for samba is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for ansible-runner for Red Hat Ansible Automation Platform 2.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security fix for CVE-2021-46059, CVE-2022-0158, CVE-2022-0156

security update

security update

Security fix for CVE-2021-41500. Upstream notes for version 1.2.7 read: “Bug fixes, Python 3.10 compatibility”.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

This update upgrades Thunderbird to version 91.5.0. * Mozilla: Iframe sandbox bypass with XSLT (CVE-2021-4140) * Mozilla: Race condition when playing audio files (CVE-2022-22737) * Mozilla: Heap-buffer-overflow in blendGaussianBlur (CVE-2022-22738) * Mozilla: Use-after-free of ChannelEventQueue::mOwner (CVE-2022-22740) * Mozilla: Browser window spoof using fullscreen mode (CVE-2022-22741) [More…]

This update upgrades Firefox to version 91.5.0 ESR. * Mozilla: Iframe sandbox bypass with XSLT (CVE-2021-4140) * Mozilla: Race condition when playing audio files (CVE-2022-22737) * Mozilla: Heap-buffer-overflow in blendGaussianBlur (CVE-2022-22738) * Mozilla: Use-after-free of ChannelEventQueue::mOwner (CVE-2022-22740) * Mozilla: Browser window spoof using fullscreen mode (CVE-2022-22741) [More…]

Several security issues were fixed in Pillow.

Several security issues were fixed in Ghostscript.

Apache Log4j 1.2 could be made to crash or run programs if it received specially crafted input.

security update

security update

It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize HTML messages. This would allow an attacker to perform Cross-Site Scripting (XSS) attacks.

An update that fixes two vulnerabilities is now available.

lxml could be made to execute arbitrary code if it received a specially crafted XML or HTML file.

Several security issues were fixed in Ghostscript.

Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed.

openssl: Read buffer overruns processing ASN.1 strings (CVE-2021-3712) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssl-1.0.2k-23.el7_9.x86_64.rpm openssl-debuginfo-1.0.2k-23.el7_9.i686.rpm openssl-debuginfo-1.0.2k-23.el7_9.x86_64.rpm openssl-libs-1.0.2k-23.e [More…]

An update that solves two vulnerabilities, contains one feature and has 13 fixes is now available.

An update that fixes one vulnerability is now available.

Introduced regression Exiv2.

An update that solves one vulnerability and has two fixes is now available.

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, run unchecked SQL queries, bypass hardening, or perform Cross-Site Scripting (XSS) attacks.

Use-after-free in sampled_data_sample (called from sampled_data_continue and interp). (CVE-2021-45944) Heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp). (CVE-2021-45949)

security update

Version 0.102 of ClamAV, an anti-virus toolkit, is end-of-life. ClamAV has been updated to version 0.103 to be able to receive virus signature updates.

The container suse/sles/15.3/virt-operator was updated. The following patches have been included in this update:

The container suse/sles/15.3/libguestfs-tools was updated. The following patches have been included in this update:

The container suse/sles/15.3/virt-handler was updated. The following patches have been included in this update:

The container suse/sles/15.3/virt-controller was updated. The following patches have been included in this update:

The container suse/sles/15.3/virt-api was updated. The following patches have been included in this update:

Multiple security issues were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which could result in denial of service and potentially the execution of arbitrary code if malformed document files are processed.

It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not properly sanitize HTML messages. This would allow an attacker to perform Cross-Side Scripting (XSS) attacks.

security update

security update

Security fix for CVE-2021-45463

https://www.mediawiki.org/wiki/Release_notes/1.36#MediaWiki_1.36.3

These updated packages fix a buffer overflow in the faces reader.

An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

It was discovered that sphinxsearch, a fast standalone full-text SQL search engine, could allow arbitrary files to be read by abusing a configuration option.

Security fix for CVE-2021-4136, CVE-2021-4166, CVE-2021-4173, CVE-2021-4186

Add wayland detection and pass flags to improve experience when wayland is used. —- Update to 96.0.4664.110. You know the drill, lots of security bugs fixed, update if you like security, hit that like and subscribe button. CVE-2021-4052 CVE-2021-4053 CVE-2021-4054 CVE-2021-4055 CVE-2021-4056 CVE-2021-4057 CVE-2021-4058 CVE-2021-4059 CVE-2021-4061 CVE-2021-4062 CVE-2021-4063

Several security issues were fixed in WebKitGTK.

Several security issues were fixed in Apache HTTP Server.

Several security issues were fixed in the kernel.

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/minimal was updated. The following patches have been included in this update:

security update

The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

What You Need to Know About the Predator-OS 20.04 LTS Release>

Several security issues were fixed in Django.

The container sles-15-sp3-chost-byos-v20220103 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220103-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220103-gen2 was updated. The following patches have been included in this update:

Two vulnerabilities have been discovered in the Apache HTTP server: CVE-2021-44224

An update for the idm:DL1 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for samba is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for telnet is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat Enterprise Linux 7.6 Telco Extended Update Support, and Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions.

xorg-x11-server: SProcRenderCompositeGlyphs out-of-bounds access (CVE-2021-4008) * xorg-x11-server: SProcXFixesCreatePointerBarrier out-of-bounds access (CVE-2021-4009) * xorg-x11-server: SProcScreenSaverSuspend out-of-bounds access (CVE-2021-4010) * xorg-x11-server: SwapCreateRegister out-of-bounds access (CVE-2021-4011) For more details about the security issue(s), including the impact, [More…]

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code, spoofing, information disclosure, downgrade attacks on SMTP STARTTLS connections or misleading display of OpenPGP/MIME signatures.

security update

An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for grafana is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for grafana is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Fix missing TLS certificate verification. (CVE-2021-39359) References: – https://bugs.mageia.org/show_bug.cgi?id=29834 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HRPPP47WRCAPAEJGRMEKYYJZBQCYXTLQ/

Several wireshark vulnerabilities have been fixed. See the release notes for details. References: – https://bugs.mageia.org/show_bug.cgi?id=29832

Fix shell expansion via crafted pathname in the ImageMagick convert fallback References: – https://bugs.mageia.org/show_bug.cgi?id=29829

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code, spoofing, information disclosure, downgrade attacks on SMTP STARTTLS connections or misleading display of OpenPGP/MIME signatures.

Security fix for CVE-2021-4008, CVE-2021-4009, CVE-2021-4010, CVE-2021-4011

The 5..15..12 stable kernel update contains a number of important fixes across the tree.