Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the ‘Cache-Digest’ header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via “H2Push off” will mitigate this vulnerability for unpatched servers (CVE-2020-9490).

An access flaw was found in targetcli, where the /etc/target and underneath backup directory/files were world-readable. This flaw allows a local attacker to access potentially sensitive information such as authentication credentials from the /etc/target/saveconfig.json and backup files. The highest threat from this vulnerability is to confidentiality (CVE-2020-13867).

Servers where the Handler concurrently reads the request body and writes a response can encounter a data race and crash. The httputil.ReverseProxy Handler is affected (CVE-2020-15586). Certain invalid inputs to ReadUvarint or ReadVarint could cause those functions

An update that solves 7 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Software Properties could be made to manipulate the display.

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that solves two vulnerabilities and has 6 fixes is now available.

Several vulnerabilities were fixed in JRuby, a 100% pure-Java implementation of Ruby. CVE-2017-17742

Updated webkit2 packages fix security vulnerabilities: The webkit2 package has been updated to version 2.28.3, fixing several security issues and other bugs.

The znc package has been updated to version 1.8.1, containing several bugfixes and enhancements. See the upstream change logs for details. References: – https://bugs.mageia.org/show_bug.cgi?id=26886

In libEtPan, a mail library, a STARTTLS response injection was discovered that affects IMAP, SMTP, and POP3. For Debian 9 stretch, this problem has been fixed in version

Updated mumble package fixes security vulnerability: OCB2 is known to be broken under certain conditions: https://eprint.iacr.org/2019/311

An update that fixes 14 vulnerabilities is now available.

In HtmlUnit, a GUI-Less browser for Java programs, malicious JavaScript code was able to execute arbitrary Java code on the application. For Debian 9 stretch, this problem has been fixed in version

Several vulnerabilities were discovered in net-snmp, a suite of Simple Network Management Protocol applications, which could lead to privilege escalation.

security update

Update to latest upstream stable version.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Several security issues were fixed in Salt.

An update that solves one vulnerability and has four fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Patch for CVE-2020-17353

Security fix for CVE-2019-20907, CVE-2020-14422. Provide a versioned pathfix3.7.py command.

security update

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has three fixes is now available.

An update that solves two vulnerabilities and has 6 fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Several security issues were fixed in Apache HTTP Server.

An update that fixes 6 vulnerabilities is now available.

An update that solves two vulnerabilities and has 6 fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has one errata is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

security update

security update

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

“To be, or not to be,” vulnerable… How customers and partners can understand and track Red Hat security vulnerabilities

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes four vulnerabilities is now available.

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Samba could be made to crash if it received specially crafted network traffic.

An update for libvncserver is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

xrdp-sesman service in xrdp can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them

ruby-kramdown processes the template option inside Kramdown documents by default, which allows unintended read access (such as template=”/etc/passwd”) or unintended embedded Ruby code execution (such as a string that begins with template=”string://

An update that fixes 26 vulnerabilities is now available.

Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt

# rpki-client 6.7p1 * Security fix: Incorrect use of `EVP_PKEY_cmp` allowed an authentication bypass

The following CVE(s) have been reported against src:wpa. CVE-2019-10064

An update that fixes 7 vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

A use-after-free was found in iproute2, possibly allowing a Denial of Service condition.

A buffer overflow in gThumb might allow remote attacker(s) to execute arbitrary code.

Multiple vulnerabilities have been found in Apache, the worst of which could result in the arbitrary execution of code.

security update

An update that contains security fixes can now be installed.

An update that fixes 12 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3253

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3344

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3233

security update

Yunus ‘ad±rc± found an issue in the SUBSCRIBE method of UPnP, a network protocol for devices to automatically discover and communicate with each other. Insuficient checks on this method allowed attackers to use vulnerable UPnP services for DoS attacks or possibly to bypass

An update that solves one vulnerability and has two fixes is now available.

An update that fixes 10 vulnerabilities is now available.

An update that solves 19 vulnerabilities and has 92 fixes is now available.

ppp could be made to load arbitrary kernel modules and possibly run programs.

An update that solves one vulnerability and has one errata is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes 26 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Red Hat Ansible Tower 3.7.2-1 – RHEL7 Container 2. Description: * Updated Named URLs to allow for testing the presence or absence of objects (CVE-2020-14337)

Red Hat Ansible Tower 3.6.5-1 – RHEL7 Container 2. Description: * Removed reports option for Satellite inventory script * Fixed Tower Server Side Request Forgery on Credentials (CVE-2020-14327)

USN-4441-1 introduced a regression in MySQL

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

libssh could be made to crash if it received a specially crafted request.

postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) SL6 noarch postgresql-jdbc-8.4.704-4.el6_10.noarch.rpm – Scientific Linux Development Team

Updated ovirt-engine packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) SL7 noarch postgresql-jdbc-9.2.1002-8.el7_8.noarch.rpm postgresql-jdbc-javadoc-9.2.1002-8.el7_8.noarch.rpm – Scientific Linux Development Team

security update

An update that fixes one vulnerability is now available.

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for postgresql-jdbc is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,