Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that fixes three vulnerabilities is now available.

An update that contains security fixes can now be installed.

DjVuLibre could be made to crash or execute arbitrary code if it opened a specially crafted file.

* CVE-2021-29157: Dovecot does not correctly escape kid and azp fields in JWT tokens. This may be used to supply attacker controlled keys to validate tokens, if attacker has local access. * CVE-2021-33515: On-path attacker could have injected plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the

* CVE-2021-29157: Dovecot does not correctly escape kid and azp fields in JWT tokens. This may be used to supply attacker controlled keys to validate tokens, if attacker has local access. * CVE-2021-33515: On-path attacker could have injected plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the

The ieee-data package, which provides the OUI and IAB listings of identifiers assigned by IEEE Standards Association, ships a script (update-ieee-data) which queries ieee.org to download the most recent dataset and save it to /var/lib/ieee-data/.

Updated live packages fix security vulnerabilities: Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska

Updated PHP packages fix security vulnerabilities: – Fixed bug #81122: SSRF bypass in FILTER_VALIDATE_URL. (CVE-2021-21705) PDO_Firebird: – Fixed bug #76448: Stack buffer overflow in firebird_info_cb.

Updated file-roller package fixes security vulnerability: A path traversal vulnerability was found in file-roller due to an incomplete fix for CVE-2020-11736. It may still be possible to extract files outside of the intended directory in case of malicious archives

Updated busybox packages fix security vulnerability: decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data (CVE-2021-28831).

A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability. (CVE-2021-20297)

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves four vulnerabilities and has one errata is now available.

The container ses/7/cephcsi/cephcsi was updated. The following patches have been included in this update:

Upgrade to 2.9.23. Fixes CVE-2021-3583

Update to 2.53.8 Some improvements for performance and stability. Following the upstream and Firefox behaviour, no more use system colors (some backgrounds etc.) by default. You can change it in Appearance–>Colors as usual.

Upgrade to 2.9.23. Fixes CVE-2021-3583

Red Hat OpenShift Container Platform release 4.5.41 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of [[Important]]. A Common Vulnerability Scoring System (CVSS) base score,

An update for go-toolset-1.15 and go-toolset-1.15-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 14 vulnerabilities is now available.

An update that fixes 14 vulnerabilities is now available.

An update that solves 12 vulnerabilities and has 42 fixes is now available.

An update that fixes one vulnerability is now available.

A buffer overflow was discovered in HTMLDOC, a HTML processor that generates indexed HTML, PS, and PDF, which could potentially result in the execution of arbitrary code. In addition a number of crashes were addressed.

X.Org X Server could be made to crash or run programs if it received specially crafted input.

An update that fixes three vulnerabilities is now available.

An update that solves four vulnerabilities and has 98 fixes is now available.

An update is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes three vulnerabilities is now available.

An update that solves three vulnerabilities and has three fixes is now available.

An update for lz4 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for fwupd is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for libxml2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for rpm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Open Source Utilization in Email Security Demystified>

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The XML parsers used by XMLBeans did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include the possibility for XML Entity Expansion attacks which could lead to a denial-of-service. This update implements sensible defaults for the XML parsers to prevent these kind

An update that fixes two vulnerabilities is now available.

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Two vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code if malformed image files are processed.

An update that fixes three vulnerabilities is now available.

An update that contains security fixes can now be installed.

Two issues have been found in bluez, a package with Bluetooth tools and daemons. One issue is about a man-in-the-middle attack during secure pairing, the other is about information disclosure due to improper access

An update that fixes two vulnerabilities is now available.

This update ships updated CPU microcode for some types of Intel CPUs and provides mitigations for security vulnerabilities which could result in privilege escalation in combination with VT-d and various side channel attacks.

Add fix to CVE-2021-28041

**Version 6.5.0** (June 16th, 2021) * **SECURITY** Fixes **CVE-2021-34551**, a complex RCE affecting Windows hosts. See SECURITY.md for details. * The fix for this issue changes the way that language files are loaded. While they remain in the same PHP-like format, they are processed as plain text, and any code in them will not be […]

**Version 6.5.0** (June 16th, 2021) * **SECURITY** Fixes **CVE-2021-34551**, a complex RCE affecting Windows hosts. See SECURITY.md for details. * The fix for this issue changes the way that language files are loaded. While they remain in the same PHP-like format, they are processed as plain text, and any code in them will not be […]

An update that solves three vulnerabilities and has three fixes is now available.

A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability (CVE-2020-27840).

Updated graphicsmagick packages fix security vulnerabilities: The graphicsmagick package has been updated to version 1.3.36, fixing several security issues and other bugs. See the upstream NEWS file for details.

A memory leak was discovered in Mat_VarCalloc in mat.c in matio 1.5.17 because SafeMulDims does not consider the rank==0 case (CVE-2019-20052). References: – https://bugs.mageia.org/show_bug.cgi?id=27969

Several security issues were fixed in Thunderbird.

Application analysis in the DevSecOps life cycle

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

The package pigeonhole before version 0.5.15-1 is vulnerable to denial of service.

The package dovecot before version 2.3.15-1 is vulnerable to information disclosure.

The package tpm2-tools before version 5.1.1-1 is vulnerable to man-in- the-middle.

The package exiv2 before version 0.27.4-1 is vulnerable to multiple issues including arbitrary code execution, denial of service and information disclosure.

The package keycloak before version 14.0.0-1 is vulnerable to certificate verification bypass.

The package helm before version 3.6.1-1 is vulnerable to information disclosure.

An update is now available for Red Hat OpenShift Jaeger 1.17. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for qemu-kvm-rhev is now available for Red Hat Virtualization for Red Hat Virtualization Host 7. Red Hat Product Security has rated this update as having a security impact of

The components for Windows Container Support for Red Hat OpenShift 2.0.1 are now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in the Linux kernel.

The system could be made to run programs as an administrator.

Several security issues were fixed in the Linux kernel.

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

An update for the virt:8.2 and virt-devel:8.2 modules is now available for Advanced Virtualization for RHEL 8.2.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in OpenEXR.

Several security issues were fixed in OpenEXR.

Several security issues were fixed in Apache HTTP Server.

Secure Linux Hosting for Businesses>
What Is Threat Intelligence?>
RHEL and CentOS 7 Users Get New Kernel Security Update to Fix Intel Graphics Flaws>
Firefox 89.0.1 Released to Improve WebRender Performance, Fix Scrollbars on GTK Themes>

Several security issues were fixed in Apache HTTP Server.

Several security issues were fixed in Dovecot.

Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613

Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613

Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613

Backport fix for CVE-2021-3589 and a heap buffer overflow.

Backport fix for CVE-2021-3589 and a heap buffer overflow.

security update

security update

It was discovered that the previous upload of the package prosody versioned 0.9.12-2+deb9u3 introduced a regression in the mod_auth_internal_hashed module. Big thanks to Andre Bianchi for the reporting an issue and for testing the update.

Update to 1.6.15 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive.

CVE-2021-3560 mitigation

Backport fix for CVE-2021-33503.

2.0.11 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive. Broker Fix possible crash having just upgraded from 1.6 if per_listener_settings true is set, and a SIGHUP is sent to the broker before a client has […]

This updates nettle to the latest upstream release 3.7.3, which contains security fix for RSA decryption: https://lists.lysator.liu.se/pipermail/nettle- bugs/2021/009545.html

The package connman before version 1.40-1 is vulnerable to arbitrary code execution.

The package grub before version 2:2.06-1 is vulnerable to multiple issues including access restriction bypass and arbitrary code execution.