Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

– Fix CVE-2020-28196 (DoS in ASN.1 parsing due to missing recursion depth checks) – fc32 + fc33 only: pull-up to rawhide

Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot.

CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452

USN-4607-1 introduced a regression in OpenJDK.

Li Fei found that libproxy, a library for automatic proxy configuration management, was vulnerable to a buffer overflow vulnerability when receiving a large PAC file from a server without a Content-Length header in the response.

A use-after-free was found in Thunderbird, which could potentially result in the execution of arbitrary code. For Debian 9 stretch, this problem has been fixed in version

Ken Gaillot discovered a vulnerability in the Pacemaker cluster resource manager: If ACLs were configured for users in the “haclient” group, the ACL restrictions could be bypassed via unrestricted IPC communication, resulting in cluster-wide arbitrary code execution with

security update

Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes

Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes

An update that solves 53 vulnerabilities, contains 14 features and has 5 fixes is now available.

Enhancing internet and cloud security with Red Hat’s contribution the Guide to IPsec VPNs

libmaxminddb could be made to crash if it received specially crafted data.

USN-4171-1 introduced a regression in Apport.

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

security update

Several security issues were fixed in Intel Microcode.

raptor2 could be made to crash or run programs as your login if it opened a specially crafted file.

An update that fixes four vulnerabilities is now available.

An update that solves 18 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 18 vulnerabilities is now available.

security update

The ppp de-capsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. The buffer should be big enough to hold the captured data, but it

It was discovered that ZeroMQ, a lightweight messaging kernel library does not properly handle connecting peers before a handshake is completed. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Fabian Vogt discovered a flaw in sddm before 0.19.0. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges (CVE-2020-28049). References:

Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. (CVE-2019-19917) Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. (CVE-2019-19918)

ACL restrictions bypass. (CVE-2020-25654) References: – https://bugs.mageia.org/show_bug.cgi?id=27472 – https://www.openwall.com/lists/oss-security/2020/10/27/1

security update

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

It was discovered that Docker could be made to expose sensitive information when processing URLs in container image manifests. A remote attacker could use this to trick the user and obtain the user’s registry credentials (CVE-2020-15157).

An update that solves 18 vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has 35 fixes is now available.

SFD_GetFontMetaData() insufficient CVE-2020-5395 backport. (CVE-2020-25690) References: – https://bugs.mageia.org/show_bug.cgi?id=27563 – https://access.redhat.com/errata/RHSA-2020:4844

The latest release of mariadb fixes some undisclosed easily exploitable vulnerabilities. (CVE-2020-14765, CVE-2020-14776, CVE-2020-14789 and CVE-2020-14812). Additionally some bugs are fixed:

It was discovered that junit contained a local information disclosure vulnerability. On Unix like systems, the system’s temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system. This vulnerability does not […]

Vaisha Bernard discovered that blueman did not properly sanitize input on the D-Bus interface to blueman-mechanism. A local attacker could possibly use this issue to escalate privileges and run arbitrary code or cause a denial of service (CVE-2020-15238).

The suricata package has been updated to version 4.1.9, which fixes security issues and other bugs. See the upstream announcements for details. References: – https://bugs.mageia.org/show_bug.cgi?id=27475

An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Command field and execute it. Then, after revisiting the Cluster Shell Commands Menu, the XSS Payload will be rendered and executed. (CVE-2020-8820)

security update

In libexif/exif-entry.c, through libexif 0.6.21-2+deb9u4, compiler optimization could remove a buffer overflow check, making a buffer overflow possible with some EXIF tags.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves three vulnerabilities and has 7 fixes is now available.

It was discovered that raptor2, an RDF parser library, is prone to heap-based buffer overflow flaws, which could result in denial of service, or potentially the execution of arbitrary code, if a specially crafted file is processed.

security update

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to run insecure deserialization, embed spam, perform various Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) attacks, escalate privileges, run arbitrary

netqmail could be made to crash if it received specially crafted input.

Update to CVE release 3001.3-1 for Python3 Includes fixes for CVE-2020-16846, CVE-2020-17490, CVE-2020-25592

Fix executable hardening (PIC/PIE)

Update to v2.1.4. Contains security fix for CVE-2020-15238.

Update to Chromium 86. A few big things here: 1. Upstream has made hardware accelerated video support (VAAPI) for Linux possible without patches. One key difference is that the patchset used previously in Fedora enabled it by default and upstream’s approach disables it by default. To enable Hardware accelerated video in chromium, open this link […]

An update that fixes 5 vulnerabilities is now available.

An update that solves three vulnerabilities and has 6 fixes is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

USBGuard improvements in Red Hat Enterprise Linux 8.3

security update

An update that solves three vulnerabilities and has 6 fixes is now available.

WireGuard Brings Speed and Simplicity to VPN Technology>

An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes two vulnerabilities is now available.

An update that fixes 16 vulnerabilities is now available.

python-cryptography could be made to expose sensitive information over the network.

Several security issues were fixed in AccountsService.

GDM could be made to create privileged users.

Vaisha Bernard discovered that Blueman, a graphical bluetooth manager performed insufficient validation on a D-Bus interface, which could result in denial of service or privilege escalation.

There were several vulnerabilites reported against wordpress, as follows: CVE-2020-28032

An update that solves one vulnerability and has two fixes is now available.

Several security issues were fixed in Samba.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

In junit4 the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system’s temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system. Both the SPICE client (spice-gtk) and server are affected by

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that solves 8 vulnerabilities and has 5 fixes is now available.

security update

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that solves 8 vulnerabilities and has 5 fixes is now available.

This update corrects a regression in some Xen virtual machine environments. For reference the original advisory text follows. Several vulnerabilities have been discovered in the Linux kernel that

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

A vulnerability in the handling of normalization with modrdn was discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can use this flaw to cause a denial of service (slapd daemon crash) via a