Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

The updated packages fix a security vulnerability: In Sudo before 1.8.31, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however,

Security researchers from Snyk discovered that the fix for CVE-2019-9658 was incomplete. Checkstyle, a development tool to help programmers write Java code that adheres to a coding standard, was still vulnerable to XML External Entity (XXE) injection.

an out-of-bounds write vulnerability due to an integer overflow was reported in libexif, a library to parse exif files. This flaw might be leveraged by remote attackers to cause denial of service, or potentially execute arbitrary code via crafted image files.

Several security issues were fixed in libxml2.

Several security issues were fixed in Qt.

Add patch for CVE-2020-6750 and related issues.

An update that fixes 38 vulnerabilities is now available.

Update to Node.js 12.15.0

Update to Node.js 12.15.0

Update to Node.js 12.15.0

libasr-1.0.4, opensmtpd-6.6.2p1 update

libasr-1.0.4, opensmtpd-6.6.2p1 update

Resolve buffer overflow in TexOpen() function, CVE-2019-19601

Resolves: #1796107, #1796109 – Security fix for CVE-2019-19921

Update to upstream 2.0.1 release for CVE-2019-10747

Update to upstream 1.3.2 release for CVE-2019-10746

MinGW cross compiled SDL 2.0.10, fixing a number of CVE issues.

Update to 2.40.0. —- MinGW cross compiled gdk-pixbuf 2.36.12 release, fixing various CVE’s.

security update

security update

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in Pillow.

An update that solves two vulnerabilities and has one errata is now available.

Several security issues were fixed in systemd.

An update that fixes one vulnerability is now available.

OpenSMTPD could be made to run programs as root if it received specially crafted input over the network.

ipa: Denial of service in IPA server due to wrong use of ber_scanf() (CVE-2019-14867) * ipa: Batch API logging user passwords to /var/log/httpd/error_log (CVE-2019-10195) SL7 x86_64 ipa-client-4.6.5-11.el7_7.4.x86_64.rpm ipa-debuginfo-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-trust-ad-4.6.5-11.el7_7.4.x86_64.rpm noarch ipa-client-co [More…]

hw: TSX Transaction Asynchronous Abort (TAA) (CVE-2019-11135) * QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) SL7 x86_64 qemu-img-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-common-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-debuginfo-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-tools-1.5.3-167.el7_7.4.x86_64.rpm – Scien [More…]

security update

Open-Source Security Projects: Choosing a Brandable .com Domain>

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in SpamAssassin.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

security update

An update that solves 10 vulnerabilities and has 11 fixes is now available.

Sudo could allow unintended access to the administrator account.

git: arbitrary code execution via .gitmodules (CVE-2018-17456) SL6 x86_64 git-1.7.1-10.el6_10.x86_64.rpm git-daemon-1.7.1-10.el6_10.x86_64.rpm git-debuginfo-1.7.1-10.el6_10.x86_64.rpm i386 git-1.7.1-10.el6_10.i686.rpm git-daemon-1.7.1-10.el6_10.i686.rpm git-debuginfo-1.7.1-10.el6_10.i686.rpm noarch emacs-git-1.7.1-10.el6_10.noarch.rpm emacs-git-el-1.7.1- [More…]

Several security issues were fixed in the kernel.

An update for git is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

Fixes **CVE-2017-18189**.

This update fixes CVE-2020-6851.

This update fixes CVE-2020-6851.

Fix a potential out of bounds write when checking a maliciously corrupted file system. This is probably not exploitable on 64-bit platforms, but may be exploitable on 32-bit binaries depending on how the compiler lays out the stack variables. (Addresses CVE-2019-5188) A maliciously corrupted file systems can trigger buffer overruns in the quota code used […]

security update

January 2020 CPU security update. See http://mail.openjdk.java.net/pipermail/jdk8u-dev/2020-January/010979.html https://openjdk.java.net/groups/vulnerability/advisories/2020-01-14

Update to Samba 4.11.6 —- Update to Samba 4.11.5 – Security fixes for CVE-2019-14902, CVE-2019-14907 and CVE-2019-19344

A stack-based buffer overflow vulnerability in sudo, a program designed to provide limited super user privileges to specific users, triggerable when configured with the pwfeedback option enabled. An unprivileged user

Joe Vennix discovered a stack-based buffer overflow vulnerability in sudo, a program designed to provide limited super user privileges to specific users, triggerable when configured with the “pwfeedback” option enabled. An unprivileged user can take advantage of this flaw to obtain

A heap-based buffer overflow vulnerability was discovered in the idn2_to_ascii_4i() function in libidn2, the GNU library for Internationalized Domain Names (IDNs), which could result in denial of service, or the execution of arbitrary code when processing a long

An issue was found in the IonMonkey JIT compiler of the Mozilla Firefox web browser which could lead to arbitrary code execution. For Debian 8 “Jessie”, this problem has been fixed in version

security update

security update

In Qt5’s plugin loader code as found in qtbase-opensource-src, it was possible to (side-)load plugins from “the” local folder in addition to a system-widely defined library path.

* Fix issues while trying to play a video on NextCloud. * Make sure the GL video sink uses a valid WebKit shared GL context. * Fix vertical alignment of text containing arabic diacritics. * Fix build with icu 65.1. * Fix page loading errors with websites using HSTS. * Fix web process crash when […]

Several vulnerabilities were fixed in libjackson-json-java. CVE-2017-7525

An update that solves one vulnerability and has three fixes is now available.

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanag es memory, as demonstrated by IRC DCC commands in EMU_IRC.

* Fix issues while trying to play a video on NextCloud. * Make sure the GL video sink uses a valid WebKit shared GL context. * Fix vertical alignment of text containing arabic diacritics. * Fix build with icu 65.1. * Fix page loading errors with websites using HSTS. * Fix web process crash when […]

Update to 79.0.3945.130. Fixes the following security issues: * CVE-2020-6378 * CVE-2020-6379 * CVE-2020-6380

This is January 2020 OpenJDK security update for java-latest-openjdk packages. The sources are updated to the 13.0.2+8 tag.

Update to bugfix release 2.9.3. See https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst

security update

security update

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code.

Two vulnerabilities have recently been discovered in the stream-tcp code of the intrusion detection and prevention tool Suricata.

An update that solves one vulnerability and has four fixes is now available.

Several vulnerabilities have been discovered in the otrs2 package that may lead to unauthorized access, remote code execution and spoofing.

Apache Solr could be made to run programs if it received specially crafted network traffic.

Time to celebrate Data Privacy Day!

The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2019-8835

It was discovered that there were a large number of NULL pointer dereferences due to unchecked return values from malloc and friends in hiredis, a minimalistic C client library.

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Libgcrypt could be made to expose sensitive information.

OpenJPEG had a heap-based buffer overflow in opj_t1_clbl_decode_processor in libopenjp2.so.

An update that fixes three vulnerabilities is now available.

An update for openjpeg2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in tcpdump.

Several security issues were fixed in Tomcat.

Several security issues were fixed in MySQL.

An update for nss is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,