Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that fixes 7 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

“To be, or not to be,” vulnerable… How customers and partners can understand and track Red Hat security vulnerabilities

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes four vulnerabilities is now available.

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Samba could be made to crash if it received specially crafted network traffic.

An update for libvncserver is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

xrdp-sesman service in xrdp can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them

ruby-kramdown processes the template option inside Kramdown documents by default, which allows unintended read access (such as template=”/etc/passwd”) or unintended embedded Ruby code execution (such as a string that begins with template=”string://

An update that fixes 26 vulnerabilities is now available.

Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt

# rpki-client 6.7p1 * Security fix: Incorrect use of `EVP_PKEY_cmp` allowed an authentication bypass

The following CVE(s) have been reported against src:wpa. CVE-2019-10064

An update that fixes 7 vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

A use-after-free was found in iproute2, possibly allowing a Denial of Service condition.

A buffer overflow in gThumb might allow remote attacker(s) to execute arbitrary code.

Multiple vulnerabilities have been found in Apache, the worst of which could result in the arbitrary execution of code.

security update

An update that contains security fixes can now be installed.

An update that fixes 12 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3253

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3344

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3233

security update

Yunus ‘ad±rc± found an issue in the SUBSCRIBE method of UPnP, a network protocol for devices to automatically discover and communicate with each other. Insuficient checks on this method allowed attackers to use vulnerable UPnP services for DoS attacks or possibly to bypass

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 10 vulnerabilities is now available.

An update that solves 19 vulnerabilities and has 92 fixes is now available.

ppp could be made to load arbitrary kernel modules and possibly run programs.

An update that solves one vulnerability and has one errata is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes 26 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Red Hat Ansible Tower 3.7.2-1 – RHEL7 Container 2. Description: * Updated Named URLs to allow for testing the presence or absence of objects (CVE-2020-14337)

Red Hat Ansible Tower 3.6.5-1 – RHEL7 Container 2. Description: * Removed reports option for Satellite inventory script * Fixed Tower Server Side Request Forgery on Credentials (CVE-2020-14327)

USN-4441-1 introduced a regression in MySQL

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

libssh could be made to crash if it received a specially crafted request.

postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) SL6 noarch postgresql-jdbc-8.4.704-4.el6_10.noarch.rpm – Scientific Linux Development Team

Updated ovirt-engine packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) SL7 noarch postgresql-jdbc-9.2.1002-8.el7_8.noarch.rpm postgresql-jdbc-javadoc-9.2.1002-8.el7_8.noarch.rpm – Scientific Linux Development Team

security update

An update that fixes one vulnerability is now available.

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

libvncserver: websocket decoding buffer overflow (CVE-2017-18922) SL7 x86_64 libvncserver-0.9.9-14.el7_8.1.i686.rpm libvncserver-0.9.9-14.el7_8.1.x86_64.rpm libvncserver-debuginfo-0.9.9-14.el7_8.1.i686.rpm libvncserver-debuginfo-0.9.9-14.el7_8.1.x86_64.rpm libvncserver-devel-0.9.9-14.el7_8.1.i686.rpm libvncserver-devel-0.9.9-14.el7_8.1.x86_64.rpm – Scientific Linux [More…]

IoT Security Vulnerabilities are Ubiquitous: How To Secure Your Router and Your Linux System Now>

An update that fixes one vulnerability is now available.

Multiple security issues have been found in Thunderbird which could result in denial of service or potentially the execution of arbitrary code.

It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language.

Multiple vulnerabilities have been found in Python, the worst of which could result in a Denial of Service condition.

In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in

Security fix for CVE-2020-15917 (STARTTLS protocol violation).

security update

Fix insufficient output escaping bug in file attachment names (CVE-2020-13625). References: – https://bugs.mageia.org/show_bug.cgi?id=26760

An integer overflow in the getnum function in lua_struct.c CVE-2020-14147 References: – https://bugs.mageia.org/show_bug.cgi?id=26978

Multiple security vulnerabilites in virtualbox allow unauthorized access to critical data or takeover of Oracle VM VirtualBox. See CVE references for details. References:

Updated dnsmasq package fix insecure default configuration potentially making it an open resolver (CVE-2020-14312). In its default configuration, dnsmasq listen and answer query from any address even outside of the local subnet. Thus, it may inadvertently

Bypass of boundary checks in nio.Buffer via concurrent access. (CVE-2020-14583) Incomplete bounds checks in Affine Transformations. (CVE-2020-14593)

The CBC padding operations were not constant time and as a result would leak the length of the plaintext values which were being padded to an attacker running a side channel attack via shared resources such as cache or branch predictor. No information about the contents was leaked, but the length alone might be used […]

An update that fixes 10 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

A flaw in PyCrypto allow remote attackers to obtain sensitive information.

Multiple vulnerabilities have been found in SNMP Trap Translator, the worst of which could allow attackers to execute arbitrary shell code.

Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code.

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

security update

security update

An update that fixes one vulnerability is now available.

Tobias Stoeckmann found an integer overflow issue in JSON-C, a C library to manipulate JSON objects, when reading maliciously crafted large files. The issue could be exploited to cause denial of service or possibly execute arbitrary code.

chromium-browser: Use after free in ANGLE (CVE-2020-6463) * chromium-browser: Inappropriate implementation in WebRTC (CVE-2020-6514) * Mozilla: Potential leak of redirect targets when loading scripts in a worker (CVE-2020-15652) * Mozilla: Memory safety bugs fixed in Firefox 79 and Firefox ESR 68.11 (CVE-2020-15659) SL6 x86_64 firefox-68.11.0-1.el6_10.x86_64.rpm firefox-debuginfo [More…]

The updated packages fix security vulnerabilities: A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via a crafted pdf file. (CVE-2018-12983)

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each

It was discovered that there was an issue where kdepim-runtime would default to using unencrypted POP3 communication despite the UI indicating that encryption was in use.

Several vulnerabilities have been discovered in the GRUB2 bootloader. CVE-2020-10713

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.

An update of the Red Hat OpenShift Container Platform 3.11 and 4.4/4.5 container images is now available for Red Hat AMQ Online. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Top 8 File and Disk Encryption Tools for Linux>

An update that fixes one vulnerability is now available.

The Case Against Full-Disk Encryption>

security update

security update

An update that fixes 5 vulnerabilities is now available.

The Ultimate Guide to Using Data Encryption on Linux>

A minor version update (from 7.6 to 7.7) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

Linux malware could soon be a thing of the past>

Several security issues were fixed in MySQL.

# July 2020 OpenJDK security update for OpenJDK 11 Full release notes: https://bitly.com/openjdk1108 ## Security fixes – JDK-8230613: Better ASCII conversions – JDK-8231800: Better listing of arrays – JDK-8232014: Expand DTD support – JDK-8233234: Better Zip Naming – JDK-8233239, CVE-2020-14562: Enhance TIFF support – JDK-8233255: Better Swing Buttons –