Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Update to 2.53.3 The database format of the stored passwords and certificates in the user profile are now changed. SeaMonkey should perform the changes hiddenly at the first run, just asking for the master password (if used). To avoid a hypothetical data loss, it is recommended to backup user profile before the update, or even […]

This update applies a proposed fix for CVE-2018-12983.

This update applies a proposed fix for CVE-2018-12983.

Backport patches for CVE-2020-15306, CVE-2020-15305, CVE-2020-15304

Security fix

This update applies a proposed fix for CVE-2018-12983.

This update applies a proposed fix for CVE-2018-12983.

Updated mbedtls packages fix security vulnerabilities Fix a side channel vulnerability in modular exponentiation that could reveal an RSA private key used in a secure enclave.

Updated mediawiki packages fix security vulnerability: In MediaWiki before 1.31.8, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This

Advisory text to describe the update. Wrap lines at ~75 chars. A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool.

Updated ffmpeg packages fix security vulnerabilities: This update provides ffmpeg version 4.1.6, which fixes several security vulnerabilities and other bugs which were corrected upstream.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

security update

security update

Several security issues were fixed in OpenSSL.

FIx CVE-2019-20454

This is a security fix release that includes fixes for the following local buffer overflow vulnerability. – CVE-2022-4044: Local users can perform a buffer overflow attack against the xrdp-sesman service and then impersonate it This update is recommended for all xrdp users.

Remmina 1.4.7 and FreeRDP 2.1.2 to fix many bugs and CVEs

Remmina 1.4.7 and FreeRDP 2.1.2 to fix many bugs and CVEs

Security update for CVE-2020-12695 (CallStranger)

security update

Several security issues were fixed in Thunderbird.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2824

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2827

Several vulnerabilities have been discovered in the interpreter for the Ruby language. CVE-2020-10663

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

security update

Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) SL6 x86_64 firefox-68.10.0-1.el6_10.x86_64.rpm [More…]

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Mozilla: Memory corruption due to missing sign-extension for ValueTags on ARM64 (CVE-2020-12417) * Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate tr [More…]

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has one errata is now available.

security update

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves 13 vulnerabilities and has one errata is now available.

An update for jaeger-all-in-one-rhel7-container and jaeger-query-rhel7-container is now available for Jaeger-1.17. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Security fix for CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag

An update that fixes one vulnerability is now available.

Updated docker packages fix security vulnerability: A flaw was found in Docker when it creates network bridges that accept IPv6 router advertisements by default. This flaw allows an attacker who can execute code in a container to possibly spoof rogue IPv6 router

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in information disclosure, denial of service or potentially the execution of arbitrary code.

Updated tcpreplay package fixes security vulnerability: tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c (CVE-2020-12740).

Updated tomcat packages fix security vulnerability: When using Apache Tomcat versions 9.0.0.M1 to 9.0.34, if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a

Updated mailman package fixes security vulnerability: Up to mailman 2.1.29 when sending a file without a file extension (or an unknown file extension) then the file is stored in the list archive with the file extension .obj. Most web servers will try to assign a mime type

security update

Update to Samba 4.12.5

Update to Samba 4.12.5

This update fixes CVE-2020-10177, CVE-2020-10994, CVE-2020-10379, CVE-2020-11538 and CVE-2020-10378.

# Python 3.6.11 Python 3.6.11 is the latest security fix release of Python 3.6. – bpo-39073: Disallow CR or LF in email.headerregistry.Address arguments to guard against header injection attacks. – bpo-38576: Disallow control characters in hostnames in http.client, addressing CVE-2019-18348. Such potentially malicious header injection URLs now cause a InvalidURL to be raised. –

3.48.1

Security update for CVE-2020-12695 (CallStranger)

security update

security update

An update that fixes 19 vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that solves three vulnerabilities and has three fixes is now available.

2.23 fixes CVE-2020-14929 (#1850048,#1850047) and new version (#1848786)

Update to latest upstream version

Fix CVE-2020-12695 (UPnP SUBSCRIBE misbehavior in hostapd WPS AP)

security update

security update

An update for rh-nginx116-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that solves one vulnerability and has 9 fixes is now available.

Several security issues were fixed in Samba.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

A security update is now available for Red Hat Single Sign-On 7.4.1 adapters for Red Hat JBoss Enterprise Application Platform 6 Red Hat Product Security has rated this update as having a security impact of

A security update is now available for Red Hat Single Sign-On 7.4.1 adapters for Red Hat JBoss Enterprise Application Platform 7.3 Red Hat Product Security has rated this update as having a security impact of

security update

An update for ose-machine-config-operator-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for containernetworking-plugins is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openshift is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.2.36 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for python-psutil is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for httpd24-nghttp2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

7 Best Linux Distros for Security and Privacy in 2020>

An update that fixes two vulnerabilities is now available.

An update for the virt:rhel module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the virt:rhel module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Several vulnerabilities were discovered in coturn, a TURN and STUN server for VoIP. CVE-2020-4067

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Mailman could be made to inject arbitrary content in the login page if it received a specially crafted input.

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

An update that solves four vulnerabilities and has four fixes is now available.

It was discovered that there was a “roster push attack” in mcabber, a console-based Jabber (XMPP) client. This is identical to CVE-2015-8688 for gajim.

It was discovered that there was a command injection vulnerability in picocom, a minimal dumb-terminal emulation program.

Several issues have been fixed in zziplib, a library providing read access on ZIP-archives. They are basically all related to invalid memory access and resulting crash or memory leak.

It was found that pngquant, a PNG (Portable Network Graphics) image optimising utility, is susceptible to a buffer overflow write issue triggered by a maliciously crafted png image, which could lead into

It was discovered that libtiprc, a transport-independent RPC library, could be used for a denial of service or possibly unspecified other impact by a stack-based buffer overflow due to a flood of crafted ICMP and UDP

An update that fixes one vulnerability is now available.