Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Two issues have been found in golang-1.7, a Go programming language compiler version 1.7

A heap-based buffer overflow flaw was discovered in MuPDF, a lightweight PDF viewer, which may result in denial of service or the execution of arbitrary code if malformed documents are opened.

security update

An update that fixes three vulnerabilities is now available.

An update that fixes 16 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has 12 fixes is now available.

A guide to security technologies in Red Hat Enterprise Linux

An update that fixes three vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

security update

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability, contains one feature and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

How security and compliance automation can help achieve a more secure hybrid cloud

security update

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

You call that DevSecOps? Why your DevSecOps practice may be falling short

Release of OpenShift Serverless 1.11.0 2. Description: Red Hat OpenShift Serverless 1.11.0 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update that fixes 29 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Kerberos could be made to consume unlimited resources if it received specially crafted ASN.1.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the virt:8.2 and virt-devel:8.2 modules is now available for Advanced Virtualization for RHEL 8.2.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Apache Ant uses various insecure temporary files possibly allowing local code execution.

A vulnerability in MIT Kerberos 5 could lead to a Denial of Service condition.

A vulnerability in libmaxminddb could lead to a Denial of Service condition.

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation. (CVE-2020-0452)

The Kleopatra component before 20.07.80 for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary library. (CVE-2020-24972).

A flaw was found in Go standard library packages. Both the net/http/cgi and net/http/fcgi packages use a default Content-Type response header value of “text/html”, rather than “text/plain”. An attacker could exploit this in applications using these packages by uploading crafted files, allowing for a cross-site scripting attack (XSS) (CVE-2020-24553).

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick was too tolerant against an invalid Transfer-Encoding header. This may lead to inconsistent interpretation between WEBrick and some HTTP proxy servers, which may allow the attacker to ”smuggle” a request (CVE-2020-25613).

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-8694) Observable discrepancy in the RAPL interface for some Intel(R) Processors may

Update to latest upstream version.

security update

– Fix CVE-2020-28196 (DoS in ASN.1 parsing due to missing recursion depth checks) – fc32 + fc33 only: pull-up to rawhide

Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot.

CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452

USN-4607-1 introduced a regression in OpenJDK.

Li Fei found that libproxy, a library for automatic proxy configuration management, was vulnerable to a buffer overflow vulnerability when receiving a large PAC file from a server without a Content-Length header in the response.

A use-after-free was found in Thunderbird, which could potentially result in the execution of arbitrary code. For Debian 9 stretch, this problem has been fixed in version

Ken Gaillot discovered a vulnerability in the Pacemaker cluster resource manager: If ACLs were configured for users in the “haclient” group, the ACL restrictions could be bypassed via unrestricted IPC communication, resulting in cluster-wide arbitrary code execution with

security update

Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes

Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes

An update that solves 53 vulnerabilities, contains 14 features and has 5 fixes is now available.

Enhancing internet and cloud security with Red Hat’s contribution the Guide to IPsec VPNs

libmaxminddb could be made to crash if it received specially crafted data.

USN-4171-1 introduced a regression in Apport.

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

security update

Several security issues were fixed in Intel Microcode.

raptor2 could be made to crash or run programs as your login if it opened a specially crafted file.

An update that fixes four vulnerabilities is now available.

An update that solves 18 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 18 vulnerabilities is now available.

security update

The ppp de-capsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. The buffer should be big enough to hold the captured data, but it

It was discovered that ZeroMQ, a lightweight messaging kernel library does not properly handle connecting peers before a handshake is completed. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Fabian Vogt discovered a flaw in sddm before 0.19.0. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges (CVE-2020-28049). References:

Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. (CVE-2019-19917) Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. (CVE-2019-19918)

ACL restrictions bypass. (CVE-2020-25654) References: – https://bugs.mageia.org/show_bug.cgi?id=27472 – https://www.openwall.com/lists/oss-security/2020/10/27/1

security update

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

It was discovered that Docker could be made to expose sensitive information when processing URLs in container image manifests. A remote attacker could use this to trick the user and obtain the user’s registry credentials (CVE-2020-15157).

An update that solves 18 vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has 35 fixes is now available.

SFD_GetFontMetaData() insufficient CVE-2020-5395 backport. (CVE-2020-25690) References: – https://bugs.mageia.org/show_bug.cgi?id=27563 – https://access.redhat.com/errata/RHSA-2020:4844

The latest release of mariadb fixes some undisclosed easily exploitable vulnerabilities. (CVE-2020-14765, CVE-2020-14776, CVE-2020-14789 and CVE-2020-14812). Additionally some bugs are fixed:

It was discovered that junit contained a local information disclosure vulnerability. On Unix like systems, the system’s temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system. This vulnerability does not […]

Vaisha Bernard discovered that blueman did not properly sanitize input on the D-Bus interface to blueman-mechanism. A local attacker could possibly use this issue to escalate privileges and run arbitrary code or cause a denial of service (CVE-2020-15238).

The suricata package has been updated to version 4.1.9, which fixes security issues and other bugs. See the upstream announcements for details. References: – https://bugs.mageia.org/show_bug.cgi?id=27475

An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Command field and execute it. Then, after revisiting the Cluster Shell Commands Menu, the XSS Payload will be rendered and executed. (CVE-2020-8820)

security update

In libexif/exif-entry.c, through libexif 0.6.21-2+deb9u4, compiler optimization could remove a buffer overflow check, making a buffer overflow possible with some EXIF tags.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves three vulnerabilities and has 7 fixes is now available.

It was discovered that raptor2, an RDF parser library, is prone to heap-based buffer overflow flaws, which could result in denial of service, or potentially the execution of arbitrary code, if a specially crafted file is processed.

security update

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to run insecure deserialization, embed spam, perform various Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) attacks, escalate privileges, run arbitrary