Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

NSS could be made to expose sensitive information if it received a specially crafted input.

An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

security update

An update that fixes one vulnerability is now available.

It was reported that the Lua module for Nginx, a high-performance web and reverse proxy server, is prone to a HTTP request smuggling vulnerability.

Mozilla: Attacker-induced prompt for extension installation (CVE-2020-15664) * Mozilla: Use-After-Free when aborting an operation (CVE-2020-15669) SL6 x86_64 firefox-68.12.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.12.0-1.el6_10.x86_64.rpm firefox-68.12.0-1.el6_10.i686.rpm firefox-debuginfo-68.12.0-1.el6_10.i686.rpm i386 firefox-68.12.0-1.el6_10.i686.rpm firefox-d [More…]

Several security issues were fixed in libmysofa.

An update that fixes three vulnerabilities is now available.

– New upstream version (80.0)

security update

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

security update

An update that fixes 21 vulnerabilities is now available.

Several security issues were fixed in Net-SNMP.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for jenkins and openshift is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Chrony’s method of opening its PID file could allow a compromised chrony user account to overwrite files in certain parts of the filesystem with chrony’s PID, using a symlink attack (CVE-2020-14367). References:

Security fix for CVE-2020-14367

Several vulnerabilities have been discovered in sqlite3, a C library that implements an SQL database engine. CVE-2018-8740

Several memory leaks were discovered in proftpd-dfsg, a versatile, virtual-hosting FTP daemon, when mod_facl or mod_sftp is used which could lead to memory exhaustion and a denial-of-service.

Jason A. Donenfeld found an ansi escape sequence injection into software-properties, a manager for apt repository sources. An attacker could manipulate the screen of a user prompted to install an additional repository (PPA).

Multiple vulnerabilities were discovered in Python2.7, an interactive high-level object-oriented language.

Tim Starling discovered two vulnerabilities in firejail, a sandbox program to restrict the running environment of untrusted applications.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has 22 fixes is now available.

An update that solves one vulnerability and has 19 fixes is now available.

Several security issues were fixed in Bind.

An update that solves 7 vulnerabilities and has 109 fixes is now available.

The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. (CVE-2020-14148) References:

– fix expired pointer dereference via multi API with `CURLOPT_CONNECT_ONLY` option set (CVE-2020-8231)

Multiple vulnerabilities were found in ghostscript, an interpreter for the PostScript language and for PDF, allowing an attacker to escalate privileges and cause denial of service via crafted PS/EPS/PDF files.

An update that solves two vulnerabilities and has 6 fixes is now available.

curl could be made to expose sensitive information over the network.

Rebased to version 3.33.0

Update to v0.3.4 release

A security flaw was found on ruby kramdown which may lead to unintended code execution. This vulnerability is now assigned as CVE-2020-14001 . This new rpm should fix this issue.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in QEMU.

An update that fixes two vulnerabilities is now available.

An update for rh-mysql80-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

CVE-2020-12100: Receiving mail with deeply nested MIME parts leads to resource exhaustion as Dovecot attempts to parse it. CVE-2020-12673: Dovecot’s NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-12674: Dovecot’s RPA mechanism implementation accepts zero-length

In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it’s required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory (CVE-2020-15121).

It was reported that firejail does not respect the end-of-options separator (“–“), allowing an attacker with control over the command line options of the sandboxed application, to write data to a specified file (CVE-2020-17367). It was reported that firejail when redirecting output via –output or

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the ‘Cache-Digest’ header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via “H2Push off” will mitigate this vulnerability for unpatched servers (CVE-2020-9490).

An access flaw was found in targetcli, where the /etc/target and underneath backup directory/files were world-readable. This flaw allows a local attacker to access potentially sensitive information such as authentication credentials from the /etc/target/saveconfig.json and backup files. The highest threat from this vulnerability is to confidentiality (CVE-2020-13867).

Servers where the Handler concurrently reads the request body and writes a response can encounter a data race and crash. The httputil.ReverseProxy Handler is affected (CVE-2020-15586). Certain invalid inputs to ReadUvarint or ReadVarint could cause those functions

An update that solves 7 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Software Properties could be made to manipulate the display.

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that solves two vulnerabilities and has 6 fixes is now available.

Several vulnerabilities were fixed in JRuby, a 100% pure-Java implementation of Ruby. CVE-2017-17742

Updated webkit2 packages fix security vulnerabilities: The webkit2 package has been updated to version 2.28.3, fixing several security issues and other bugs.

The znc package has been updated to version 1.8.1, containing several bugfixes and enhancements. See the upstream change logs for details. References: – https://bugs.mageia.org/show_bug.cgi?id=26886

In libEtPan, a mail library, a STARTTLS response injection was discovered that affects IMAP, SMTP, and POP3. For Debian 9 stretch, this problem has been fixed in version

Updated mumble package fixes security vulnerability: OCB2 is known to be broken under certain conditions: https://eprint.iacr.org/2019/311

An update that fixes 14 vulnerabilities is now available.

In HtmlUnit, a GUI-Less browser for Java programs, malicious JavaScript code was able to execute arbitrary Java code on the application. For Debian 9 stretch, this problem has been fixed in version

Several vulnerabilities were discovered in net-snmp, a suite of Simple Network Management Protocol applications, which could lead to privilege escalation.

security update

Update to latest upstream stable version.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Several security issues were fixed in Salt.

An update that solves one vulnerability and has four fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Patch for CVE-2020-17353

Security fix for CVE-2019-20907, CVE-2020-14422. Provide a versioned pathfix3.7.py command.

security update

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has three fixes is now available.

An update that solves two vulnerabilities and has 6 fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Several security issues were fixed in Apache HTTP Server.

An update that fixes 6 vulnerabilities is now available.

An update that solves two vulnerabilities and has 6 fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has one errata is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

security update

security update

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.