Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Exponential entity expansion attack bypasses all existing protection mechanisms. (CVE-2021-3541). References: – https://bugs.mageia.org/show_bug.cgi?id=29039 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/NYSYJVWYEQHFG2TBIQJRJ5COUR5LNFJJ/

A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a […]

USN-4937-1 introduced a regression in GNOME Autoar.

USN-4969-1 introduced a regression in DHCP.

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libwebp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

Multiple security issues have been discovered in libwebp CVE-2018-25009

An update that solves 12 vulnerabilities and has 23 fixes is now available.

An update that fixes 21 vulnerabilities is now available.

Several security issues were fixed in the Linux kernel.

security update

New version 3.4.5, Fix for CVE-2021-22207.

Fix for CVE-2021-25217

New version 3.4.5, Fix for CVE-2021-22207.

security update

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. In adddition two security issues were addressed in the OpenPGP support.

An update that fixes one vulnerability is now available.

Apply fix for CVE-2021-3500. —- Apply fix for CVE-2021-32490, CVE-2021-32491, CVE-2021-32492, CVE-2021-32493

Backport fixes for CVE-2021-32617, CVE-2021-29623.

Upgrade to upstream security release 3.7.4

Apply fix for CVE-2021-3500. —- Apply fix for CVE-2021-32490, CVE-2021-32491, CVE-2021-32492, CVE-2021-32493

Backport fixes for CVE-2021-32617, CVE-2021-29623.

security update

Kubernetes architecture and what it means for security

security update

An update for glib2 is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openvswitch is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This advisory resolves CVE issues filed against XP1 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP1 code base. NOTE: This advisory is informational only. There are no code changes

Dnsmasq could be exposed to cache poisoning.

Several security issues were fixed in Django.

Network-Bound Disk Encryption improvements in RHEL 8

Applications using Lasso could be made to allow unintended access.

An update for rh-python36-python-jinja2 is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

Amir Sarabadani and Kunal Mehta discovered that the import functionality of Hyperkitty, the web user interface to access Mailman 3 archives, did not restrict the visibility of private archives during the import, i.e. that during the import of a private Mailman 2 archive the archive was

security update

8u292 update

8u292 update

Security fix for CVE-2021-30465

**Version 4.4.24** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) * bug #41230 [FrameworkBundle][Validator] Fix deprecations from Doctrine Annotations+Cache (derrabus) * bug #41240 Fixed deprecation warnings about passing null as parameter (derrabus) * bug #41241 [Finder] Fix gitignore regex

**Version 3.4.49** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) —- **Version 3.4.48** (2021-05-12) * security **CVE-2021-21424** [Security][Guard] Prevent user enumeration (chalasr)

Luis Merino, Markus Vervier and Eric Sesterhenn discovered an off-by-one in Nginx, a high-performance web and reverse proxy server, which could result in denial of service and potentially the execution of arbitrary code.

The container caasp/v4.5/velero-restic-restore-helper was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-microsoft-azure was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-gcp was updated. The following patches have been included in this update:

The container caasp/v4.5/velero-plugin-for-aws was updated. The following patches have been included in this update:

The container caasp/v4.5/velero was updated. The following patches have been included in this update:

security update

Security automation for digital transformation

Patch for CVE-2020-24119.

CVE-2021-3480: invalid BIND DN crash

Patch for CVE-2020-24119.

CVE-2021-3480: invalid BIND DN crash

An update that fixes one vulnerability is now available.

Multiple vulnerabilities have been found in Ceph, the worst of which could result in privilege escalation.

nginx could be made to crash or run programs if it received specially crafted network traffic.

A vulnerability in Nextcloud Desktop Client could allow a remote attacker to execute arbitrary commands.

Actionable threat intelligence for publicly known exploits for RHEL

Multiple vulnerabilities have been found in cURL, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to execute arbitrary code.

The package thunderbird before version 78.10.2-1 is vulnerable to multiple issues including content spoofing and information disclosure.

The package hivex before version 1.3.20-1 is vulnerable to denial of service.

An update that fixes one vulnerability is now available.

Red Hat OpenShift Container Platform release 4.7.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

Red Hat OpenShift Container Platform release 4.7.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.7.12.

Red Hat OpenShift Container Platform release 4.7.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.7.12.

Release of OpenShift Serverless Client kn 1.14.1 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

DevSecOps compliance: Make your auditor’s job easier!

An update for openshift-serverless-1-kn-cli-artifacts-rhel8-container, openshift-serverless-1-knative-rhel8-operator-container, and openshift-serverless-1-serverless-operator-bundle-container is now available for Openshift Serveless 1.14.

An update that fixes one vulnerability is now available.

Roman Fiedler found that libX11, the X11 protocol client library, was vulnerable to protocol command injection due to insufficient validation of arguments to some functions.

Roman Fiedler reported that missing length validation in various functions provided by libx11, the X11 client-side library, allow to inject X11 protocol commands on X clients, leading to authentication bypass, denial of service or potentially the

security update

– Update to 20.11.7 – Closes security issue CVE-2021-31215

– Security fix for CVE-2021-28363. – Security fix for *pip incorrectly handled unicode separators in git references*.

LinuxSecurity is in Beta: A Customized User Profile is Just the Beginning! >

security update

security update

security update

security update

**MariaDB 10.5.10** Release notes: https://mariadb.com/kb/en/mariadb-10510-release-notes/

Several vulnerabilities were discovered in jetty, a Java servlet engine and webserver. An attacker may reveal cryptographic credentials such as passwords to a local user, disclose installation paths, hijack user sessions or tamper with collocated webapps.

An update that solves two vulnerabilities and has one errata is now available.

Multiple security issues have been discovered in the PostgreSQL database system, which could result in the execution of arbitrary code or disclosure of memory content.

One security issue has been discovered in libgetdata CVE-2021-20204

Red Hat AMQ Streams 1.6.4 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 20 vulnerabilities is now available.

An update that contains security fixes can now be installed.

– New upstream version (88.0.1) – Fixes CVE-2021-29952 (https://www.mozilla.org/en-US/security/advisories/mfsa2021-20/) —- – Fixed WebRTC indicator (mozbz#1705048). —- – Enable Wayland backend on Plasma/KDE by default (rhbz#1922608)

Update to Chromium 90.0.4430.93. Fixes the following security issues: CVE-2021-21206 CVE-2021-21220 CVE-2021-21201 CVE-2021-21202 CVE-2021-21203 CVE-2021-21204 CVE-2021-21221 CVE-2021-21207 CVE-2021-21208 CVE-2021-21209 CVE-2021-21210 CVE-2021-21211 CVE-2021-21212 CVE-2021-21213 CVE-2021-21214 CVE-2021-21215 CVE-2021-21216 CVE-2021-21217 CVE-2021-21218 CVE-2021-21219

Exiv2 update fixing security issues.

An update that fixes four vulnerabilities is now available.

security update

security update

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for portable Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for Windows. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which