Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

## 1.4.3 (12, Nov 2019) ### Security Improvements: – Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

– https://www.drupal.org/project/ckeditor/releases/7.x-1.19 – https://www.drupal.org/sa-contrib-2020-007

Security fix for CVE-2020-11100)

An update that contains security fixes can now be installed.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has three fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]

A vulnerability in libssh could allow a remote attacker to cause a Denial of Service condition.

An update that fixes two vulnerabilities is now available.

The package libssh before version 0.9.4-1 is vulnerable to denial of service.

The package wireshark-cli before version 3.2.3-1 is vulnerable to arbitrary code execution.

The package chromium before version 81.0.4044.92-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass and insufficient validation.

The package firefox before version 75.0-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and access restriction bypass.

The package haproxy before version 2.1.4-1 is vulnerable to arbitrary code execution.

security update

security update

An update that fixes 5 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

Security fix for CVE-2020-5247, CVE-2020-5249

This update incorporates fixes from the upstream glibc 2.29 stable release branch, including 3 fixes for medium severity security vulnerabilities. (CVE-2020-10029, CVE-2020-1752, CVE-2020-1751)

Updated firefox packages fix security vulnerabilities: When reading from areas partially or fully outside the source resource with WebGL’s copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized,

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed

Be careful when pulling images by short name
Linux Malware: The Truth About This Growing Threat>

The package firefox before version 74.0.1-1 is vulnerable to arbitrary code execution.

telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code (CVE-2020-10188) SL6 x86_64 krb5-appl-clients-1.0.1-10.el6_10.x86_64.rpm krb5-appl-debuginfo-1.0.1-10.el6_10.x86_64.rpm krb5-appl-servers-1.0.1-10.el6_10.x86_64.rpm i386 krb5-appl-clients-1.0.1-10.el6_10.i686.rpm krb5-appl-debuginfo-1.0.1-10.el6_10.i686.rpm krb5-appl-se [More…]

Mozilla: Use-after-free while running the nsDocShell destructor (CVE-2020-6819) * Mozilla: Use-after-free when handling a ReadableStream (CVE-2020-6820) SL6 x86_64 firefox-68.6.1-1.el6_10.x86_64.rpm firefox-debuginfo-68.6.1-1.el6_10.x86_64.rpm firefox-68.6.1-1.el6_10.i686.rpm firefox-debuginfo-68.6.1-1.el6_10.i686.rpm i386 firefox-68.6.1-1.el6_10.i686.rpm firefox- [More…]

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

GnuTLS could expose sensitive information over the network.

An update for ksh is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) SL6 x86_64 ipmitool-1.8.15-3.el6_10.x86_64.rpm ipmitool-debuginfo-1.8.15-3.el6_10.x86_64.rpm i386 ipmitool-1.8.15-3.el6_10.i686.rpm ipmitool-debuginfo-1.8.15-3.el6_10.i686.rpm – Scientific Linux Development Team

An update for ipmitool is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for ksh is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code (CVE-2020-10188) SL6 x86_64 telnet-0.17-49.el6_10.x86_64.rpm telnet-debuginfo-0.17-49.el6_10.x86_64.rpm telnet-server-0.17-49.el6_10.x86_64.rpm i386 telnet-0.17-49.el6_10.i686.rpm telnet-debuginfo-0.17-49.el6_10.i686.rpm telnet-server-0.17-49.el6_10.i686.rpm – Scientif [More…]

An update for telnet is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

This update is based on upstream 5.5.15 and fixes some security related issues related to use after free and null pointer dereferences and also some other bugfixes. Other fixes in this update:

Updated firefox packages fix security vulnerabilities: Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free (CVE-2020-6819).

Updated python-ntlk package fixes security vulnerability: A vulnerability was found in NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ in an NLTK package (ZIP archive) that is mishandled during extraction

The updated packages fix a security vulnerability: In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number

libmtp is a library for communicating with MTP aware devices. The Media Transfer Protocol (commonly referred to as MTP) is a devised set of custom extensions to support the transfer of music files on USB digital audio players

– New upstream version (74.0.1), fixed 0day vulnerability

Two security issues have been found in the Mozilla Firefox web browser, which could result in the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed

An update that fixes one vulnerability is now available.

A flaw was reported in the DTLS protocol implementation in GnuTLS, a library implementing the TLS and SSL protocols. The DTLS client would not contribute any randomness to the DTLS negotiation, breaking the security guarantees of the DTLS protocol.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.

Security fix for CVE-2020-10188

security update

security update

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

A regression in GnuTLS breaks the security guarantees of the DTLS protocol.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for haproxy is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

The krb5 PAM module (pam_krb5.so) had a buffer overflow that might have caused remote code execution in situations involving supplemental prompting by a Kerberos library.

A vulnerability was discovered in python-bleach, a whitelist-based HTML-sanitizing library. Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to a regular expression denial

An update that fixes one vulnerability is now available.

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the idm:DL1 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for nss-softokn is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An issue has been found in apng2gif, a tool for converting APNG images to animated GIF format.

Several issues have been found in gst-plugins-bad0.10, a package containing GStreamer plugins from the “bad” set.

An update that fixes 9 vulnerabilities is now available.

A minor security issue and a severe packaging bug have been fixed in tinyproxy, a lightweight http proxy daemon.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

With Kubernetes Operators comes great responsibility

An update that solves three vulnerabilities and has one errata is now available.

Multiple vulnerabilities have been found in QEMU, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in FFmpeg, the worst of which allows remote attackers to execute arbitrary code.

Multiple vulnerabilities have been found in libxls, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in GNU IDN Library 2, the worst of which could result in the remote execution of arbitrary code.

A buffer overflow in GNU Screen might allow remote attackers to corrupt memory.

An update that solves two vulnerabilities and has one errata is now available.

Fix CVE-2018-19655

Fix CVE-2018-19655

Fix CVE-2018-19655

* New upstream release 5.3.1 (rhbz#1814882) * Fixes CVE-2020-1747 (rhbz#1807367,1809011)

An update that fixes 7 vulnerabilities is now available.