Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that solves 10 vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Security fixes for CVE-2020-1472

RavenDB: Pioneering Data Management with an Innovative Open-Source Approach>

An update that fixes 5 vulnerabilities is now available.

An update that contains security fixes can now be installed.

Update to 85.0.4183.121. Why? Because security, that’s why. It fixes these CVEs: CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 It also has a fix for an issue where networking… uh… didn’t. —- Update Chromium to 85.0.4183.102. Fix issue where unpackaged components prevented hardware accelerated rendering from

Mumble 1.3.2. === Client * Fixed: Overlay not starting (#4282) Server * Fixed: keychain-error on macOS for custom certificates (#4345) Known issues * Overlay blocked by BattleEye. A request to whitelist it has been made. * Overlay blocked by CS:GO Trusted Mode

It was found that SNMP Trap Translator does not drop privileges as configured and does not properly escape shell commands in certain functions. A remote attacker, by sending a malicious crafted SNMP trap, could possibly execute arbitrary shell code with the privileges of the

Several security vulnerabilities have been discovered in Squid, a high- performance proxy caching server for web clients. CVE-2020-15049

Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, guest-to-host privilege escalation or information leaks.

An update that solves one vulnerability and has 25 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with jruby) was too tolerant against

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with ruby2.3) was too tolerant against

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes 12 vulnerabilities is now available.

The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Therefore, there was a need to explicitly specify the number

This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format.

Red Hat adopts ROLIE protocol for automated exchange of security compliance assets

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Updated OpenShift Container Storage packages fixing various security issues and other bugs are now available for Red Hat OpenShift Container Storage with 3.11.z Async update. Red Hat Product Security has rated this update as having a security impact

An update that solves four vulnerabilities and has two fixes is now available.

Several security improvements were added to Samba.

Several security issues were fixed in Tomcat.

security update

The package podman before version 2.1.0-1 is vulnerable to information disclosure.

The package firefox before version 81.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, cross-site scripting and denial of service.

The package chromium before version 85.0.4183.121-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, information disclosure and insufficient validation.

The package libvirt before version 6.5.0-2 is vulnerable to privilege escalation.

An update that solves 11 vulnerabilities and has one errata is now available.

An update that solves 10 vulnerabilities and has one errata is now available.

How To Identify Libraries that are Still Vulnerable to Attacks After Updates>

Several security issues were fixed in iTALC.

libuv could be made to crash or execute arbitrary code if it received a specially crafted path.

ImageMagick could be made to crash if it opened a specially crafted file.

Several vulnerabilities were discovered in the Perl5 Database Interface (DBI). An attacker could trigger a denial-of-service (DoS) and possibly execute arbitrary code.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has 6 fixes is now available.

An update that fixes 7 vulnerabilities is now available.

grub2 updates for boothole vulnerabilities in f31/f32.

security update

x86 pv: Crash when handling guest access to MSR_MISC_ENABLE [XSA-333, CVE-2020-25602] (#1881619) Missing unlock in XENMEM_acquire_resource error path [XSA-334, CVE-2020-25598] (#1881616) race when migrating timers between x86 HVM vCPU-s [XSA-336, CVE-2020-25604] (#1881618) PCI passthrough code reading back hardware registers [XSA-337, CVE-2020-25595] (#1881587) once valid event

An update that fixes 7 vulnerabilities is now available.

Two issues have been found in yaws, a high performance HTTP 1.1 webserver written in Erlang.

Two issues have been found in nfdump, a netflow capture daemon. Both issues are related to either a buffer overflow or an integer overflow, which could result in a denial of service or a local code

An issue has been found in curl, a command line tool for transferring data with URL syntax. In rare circumstances, when using the multi API of curl in combination

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

security update

An update that solves one vulnerability and has one errata is now available.

Several security issues were fixed in Gnuplot.

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work: SpecialUserRights could leak whether a user existed or not, multiple code paths lacked HTML sanitisation allowing for cross-site scripting and TOTP validation applied insufficient rate

Sanitize could be made to perform XSS attacks if it received specially crafted input.

Disable pkcs11 related test case running into GnuTLS locking bug

CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. CVE-2020-12673: Dovecot’s NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-10967: lmtp/submission:

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that fixes 14 vulnerabilities is now available.

Several security issues were fixed in SPIP.

An update that fixes 19 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that fixes 19 vulnerabilities is now available.

RDFLib could be made to made to execute arbitrary code if it were running in a directory with a specially crafted file.

– New upstream version (81.0)

Security fixes for CVE-2020-1472

Fix CVE-2020-25219

Fix for #1876738 and #1876689

An update that solves four vulnerabilities and has one errata is now available.

Securing a Linux Web Server: A Primer>
The new BLESA Bluetooth security flaw can keep billions of devices vulnerable>

An update that fixes 19 vulnerabilities is now available.

An update that solves four vulnerabilities and has one errata is now available.

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.

Several security issues were fixed in FreeImage.

TANSTAAFL! The Tragedy of the Commons Meets Open-Source Software>
Announcement of the passing of Jari Fredriksson>

An update that fixes one vulnerability is now available.

pam_tacplus could be made to expose sensitive information.

An update that fixes 14 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes 25 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Two security issues were discovered in the modules of the InspIRCd IRC daemon, which could result in denial of service. CVE-2019-20917

An update that solves one vulnerability and has one errata is now available.

security update

security update

Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789).

Update to the new upstream 3.6.15 release. —- – Fix memory leak when serializing iovec_t (#1845083) – Fix automatic libraries sonames detection (#1845806)

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.