Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the redis:6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The security update of smarty3, the compiling PHP template engine, issued as DLA 2618-1 introduced a regression in the smarty_security class when secure directories are evaluated. Updated smarty3 packages are now available to correct this issue.

An update for the redis:5 module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

Update to upstream stable release 2.9.4, includes a fix for CVE-2021-3802 (#2003650, #2003649)

Several security issues were fixed in strongSwan.

An update for the redis:5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat Quay 3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in strongSwan.

The container suse/sle15 was updated. The following patches have been included in this update:

Red Hat OpenShift Container Platform release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

Ardour could be made to crash or possibly arbitrary code execute if it received a specially crafted XML file.

A security issue was fixed in nginx.

DLA-2743-1 was issued for CVE-2017-5715, affecting amd64-microcode, processor microcode firmware for AMD CPUs. However, the binaries for the resulting upload weren’t built and published, thereby preventing the users to upgrade to a fixed version.

security update

https://lib.openmpt.org/libopenmpt/2021/10/04/security- updates-0.5.12-0.4.24-0.3.33/

The newest upstream commit Security fix for CVE-2021-3796 Security fix for CVE-2021-3778

https://lib.openmpt.org/libopenmpt/2021/10/04/security- updates-0.5.12-0.4.24-0.3.33/

Two security issues have been discovered in LibreOffice’s support for digital signatures in ODF documents, which could result in incorrect signature indicators/timestamps being presented.

Two security issue have been discovered in nghttp2: server, proxy and client implementing HTTP/2. CVE-2018-1000168

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 20 vulnerabilities is now available.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

security update

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Richard Weinberger reported that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not check for duplicate filenames within a directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem if a malformed

An update that solves 6 vulnerabilities and has 44 fixes is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

security update

USN-5091-1 introduced a regression in the Linux kernel for Microsoft Azure cloud systems.

security update

Red Hat Advanced Cluster Management for Kubernetes 2.2.9 General Availability release images, which provide security updates, one or more container updates, and bug fixes. Red Hat Product Security has rated this update as having a security impact

Fix CVE-2021-29063 regular expression denial of service References: – https://bugs.mageia.org/show_bug.cgi?id=29537 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3M5O55E7VUDMXCPQR6MQTOIFDKHP36AA/

Security fix for CVE-2021-41617

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform Cross-Site Scripting (XSS) attacks or impersonate other users.

An update for httpd is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Red Hat 3scale API Management 2.11.0 Release – Container Images A security update for Red Hat 3scale API Management is now available from the Red Hat Container Catalog. Red Hat Product Security has rated this update as having a security impact

Squashfs-Tools could be made to overwrite files.

The container suse/sle15 was updated. The following patches have been included in this update:

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes 25 vulnerabilities is now available.

An update for libxml2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

An update that fixes 21 vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

– New upstream update (93.0) – Fixed NSS package dependency (NSS 3.70) —- – New upstream release (93.0)

Two security issues were found in TIFF, a widely used format for storing image data, as follows: CVE-2020-19131

Update to f13cbcf (dr_wav 0.13.2) Fix a possible buffer overflow. —- Update to 8900af1 with dr_mp3 0.6.31 Fix a bug in dr_mp3 when loading from memory.

Upgrade Grafana to upstream version 7.5.10 —- rebuild to resolve CVE-2021-34558

Update to f13cbcf (dr_wav 0.13.2) Fixes a possible buffer overflow. —- Update to 8900af1 with dr_mp3 0.6.31 Fix a bug in dr_mp3 when loading from memory.

An update that solves three vulnerabilities and has one errata is now available.

The container caasp/v4/kured was updated. The following patches have been included in this update:

The container caasp/v4/kucero was updated. The following patches have been included in this update:

The container caasp/v4/kubernetes-client was updated. The following patches have been included in this update:

The container caasp/v4/hyperkube was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

Due to a data race in the crossbeam-deque in the crossbeam crate, one or more tasks in the worker queue could have been be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this could have caused a double free and a memory leak (CVE-2021-32810).

New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Several security issues were fixed in MySQL.

Rebase to libssh-0.9.6 Fix CVE-2021-3634

3 focus areas for DevSecOps success

Updated container images that fix various bugs are now available for Red Hat OpenShift Container Storage 3.11 Update 8 in the Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact

Updated packages that provide Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9, and fix an important security issue, are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9 zip release for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact

Bottle could be made to cache malicious requests if it received a specially crafted input.

The updated packages fix a security vulnerabilities: While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Red Hat JBoss Web Server 5.5.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated Red Hat JBoss Web Server 5.5.1 packages are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

security update

security update

Update to 8.6.0.

Squid could be made to crash or expose sensitive information over the network.

DevSecOps tools, culture and misconceptions: Advice from Red Hatters

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,