Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that solves one vulnerability and has one errata is now available.

Drupal 7 has an Open Redirect vulnerability. For example, a user could be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves 55 vulnerabilities and has 93 fixes is now available.

security update

security update

An update is now available for Red Hat build of Eclipse Vert.x. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

NSS could be made to expose sensitive information over the network.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 6 vulnerabilities is now available.

LinuxSecurity Celebrates 24 Years of Serving as the Linux CommunityĆ¢€™s Central Security Resource >

The package intel-ucode before version 20200609-1 is vulnerable to information disclosure.

The package dbus before version 1.12.18-1 is vulnerable to denial of service.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

This is a security update for JBoss EAP Continuous Delivery 12.0. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

This is a security update for JBoss EAP Continuous Delivery 13.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

This is a security update for JBoss EAP Continuous Delivery 18.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

This is a security update for JBoss EAP Continuous Delivery 16.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

This is a security update for JBoss EAP Continuous Delivery 14.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An error in Cyrus IMAP Server allows mailboxes to be created with administrative privileges.

Update to upstream 3.6.14 release, and security fix for CVE-2020-13777.

Fixes CVE-2020-10995, CVE-2020-12244 and CVE-2020-10030

Update to upstream 3.6.14 release, and security fix for CVE-2020-13777. —- – Fix certificate chain validation involving the expired “AddTrust External Root”. – Disable RSA blinding during FIPS self-tests to avoid hanging if there is not enough entropy for `getrandom()` – Add `–waitresumption` option to `gnutls-cli` to force the client to wait for resumption data […]

Fixes CVE-2019-20479

– Update to 1.20.12 release – ifcfg-rh: handle “802-1x.{,phase2-}ca-path” (rh #1841395, CVE-2020-10754)

Update to upstream 3.6.14 release, and security fix for CVE-2020-13777.

security update

security update

security update

An update that fixes three vulnerabilities is now available.

An update that fixes 10 vulnerabilities is now available.

An update that solves 25 vulnerabilities and has 132 fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update for net-snmp is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Multiple security issues have been found in Thunderbird which could result in the setup of a non-encrypted IMAP connection, denial of service or potentially the execution of arbitrary code.

An update that fixes one vulnerability is now available.

Three vulnerabilities have been found in the MySQL Connector/J JDBC driver. For the oldstable distribution (stretch), these problems have been fixed

Multiple security issues have been found in Thunderbird which could result in the setup of a non-encrypted IMAP connection, denial of service or potentially the execution of arbitrary code.

Network traffic control for containers in Red Hat OpenShift

It was discovered that there was an escaping issue in libphp-phpmailer, an email generation utility class for the PHP programming language.

This update ships updated CPU microcode for some types of Intel CPUs and provides mitigations for the Special Register Buffer Data Sampling (CVE-2020-0543), Vector Register Sampling (CVE-2020-0548) and L1D Eviction Sampling (CVE-2020-0549) hardware vulnerabilities.

An update that solves four vulnerabilities and has one errata is now available.

security update

security update

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update for expat is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2432

hw: Special Register Buffer Data Sampling (SRBDS) (CVE-2020-0543) * hw: L1D Cache Eviction Sampling (CVE-2020-0549) * hw: Vector Register Data Sampling (CVE-2020-0548) SL6 x86_64 microcode_ctl-1.17-33.26.el6_10.x86_64.rpm microcode_ctl-debuginfo-1.17-33.26.el6_10.x86_64.rpm i386 microcode_ctl-1.17-33.26.el6_10.i686.rpm microcode_ctl-debuginfo-1.17-33.26.el6_10.i686.rpm [More…]

kernel: NULL pointer dereference due to KEYCTL_READ on negative key (CVE-2017-12192) SL6 x86_64 kernel-2.6.32-754.30.2.el6.x86_64.rpm kernel-debug-2.6.32-754.30.2.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-754.30.2.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.30.2.el6.x86_64.rpm kernel-debug-devel-2.6.32-754.30.2.el6.i686.rpm kernel-debug-devel-2.6.32-754.30.2.el [More…]

Linux Malware: The Truth About This Growing Threat [Updated]>

The package chromium before version 83.0.4103.97-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution and content spoofing.

The package firefox before version 77.0-1 is vulnerable to multiple issues including arbitrary code execution, denial of service, private key recovery and content spoofing.

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2414

An information disclosure vulnerability in GnuTLS allow remote attackers to obtain sensitive information.

security update

An update that fixes three vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes one vulnerability is now available.

The following CVE(s) were reported against src:cups. CVE-2019-8842

A vulnerability was discovered in graphicsmagick, a collection of image processing tools, that results in a heap buffer overwrite when magnifying MNG images.

GnuTLS could be made to expose sensitive information.

A flaw was reported in the TLS session ticket key construction in GnuTLS, a library implementing the TLS and SSL protocols. The flaw caused the TLS server to not securely construct a session ticket encryption key considering the application supplied secret, allowing a

Two vulnerabilities were discovered in Node.js, which could result in denial of service and potentially the execution of arbitrary code. For the stable distribution (buster), these problems have been fixed in

security update

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

– Updated to latest upstream (77.0.1) —- – New upstream version (77.0) —- – Updated VA-API patches for Wayland backend – Use dmabuf WebGL backend by default on Wayland

– Update to 1.2.12 Release notes: https://www.cacti.net/release_notes.php?version=1.2.12

– Update to 1.2.12 Release notes: https://www.cacti.net/release_notes.php?version=1.2.12

– Update to 2.16.6 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.16.6-and-2.7.15-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2020-04

security update

There were several CVE bugs reported against src:netqmail. CVE-2005-1513

An update that fixes one vulnerability is now available.

An update that solves 7 vulnerabilities and has one errata is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2383

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2378

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2381

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has 18 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.