Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that fixes three vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

The update issued as DLA-1835-1 caused a regression in the http.client library in Python 3.4 which was broken by the patch intended to fix CVE-2019-9740 and CVE-2019-9947.

A security improvement has been made to policykit-desktop-privileges.

A system hardening measure could be bypassed.

Several security issues were fixed in Ceph.

Several security issues were fixed in ImageMagick.

Several security vulnerabilities were discovered in the rdesktop RDP client, which could result in buffer overflows and execution of arbitrary code.

An update that fixes one vulnerability is now available.

Multiple security issues have been found in Thunderbird which may lead to the execution of arbitrary code if malformed email messages are read. For Debian 8 “Jessie”, these problems have been fixed in version

security update

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

A sandbox escape was discovered in Firefox.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1587

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves two vulnerabilities and has four fixes is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

security update

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Two vulnerabilities were discovered in Libvirt, a virtualisation abstraction library, allowing an API client with read-only permissions to execute arbitrary commands via the virConnectGetDomainCapabilities API, or read or execute arbitrary files via the

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Update to 1.1.33 and fix CVE-2019-11068

An update that solves three vulnerabilities and has one errata is now available.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

security update

An update that fixes one vulnerability is now available.

security update

security update

An update that solves one vulnerability and has three fixes is now available.

The package firefox before version 67.0.3-1 is vulnerable to arbitrary code execution.

The package python before version 3.7.3-1 is vulnerable to information disclosure.

The package dbus before version 1.12.16-1 is vulnerable to access restriction bypass.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that solves 6 vulnerabilities and has 7 fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

security update

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1481

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1488

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1492

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that solves 9 vulnerabilities and has 9 fixes is now available.

An update that solves 16 vulnerabilities and has two fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves 16 vulnerabilities and has two fixes is now available.

The package linux-zen before version 5.1.11.zen1-1 is vulnerable to denial of service.

The package linux-lts before version 4.19.52-1 is vulnerable to denial of service.

The package linux before version 5.1.11.arch1-1 is vulnerable to denial of service.

An update for gvfs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

security update

Multiple security issues have been found in Thunderbird which may lead to the execution of arbitrary code if malformed email messages are read. For the stable distribution (stretch), these problems have been fixed in

It was discovered that there was a code injection issue in PyXDG, a library used to locate “FreeDesktop.org” configuration/cache/etc. directories.

security update

An update that fixes 13 vulnerabilities is now available.

An update that fixes 13 vulnerabilities is now available.

An update that fixes 13 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Two vulnerabilities were discovered in the ZNC IRC bouncer which could result in remote code execution (CVE-2019-12816) or denial of service via invalid encoding (CVE-2019-9917).

do not install /usr/libexec/crio – conflicts with crio —- Resolves: #1715668 – CVE-2019-10152

Resolves: #1715758 – CVE-2019-9946

https://lists.wikimedia.org/pipermail/mediawiki-announce/2019-June/000230.html

security update

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

The package chromium before version 75.0.3770.90-1 is vulnerable to arbitrary code execution.

The package thunderbird before version 60.7.1-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Joe Vennix discovered an authentication bypass vulnerability in dbus, an asynchronous inter-process communication system. The implementation of the DBUS_COOKIE_SHA1 authentication mechanism was susceptible to a symbolic link attack. A local attacker could take advantage of this flaw

Update to [3.3.8](https://github.com/vakata/jstree/compare/3.3.5…3.3.8).

Upstream announcement: Welcome to **phpMyAdmin 4.9.0.1**, a bugfix release that includes important security fixes. This release fixes two security vulnerabilities: * PMASA-2019-3 is an SQL injection flaw in the Designer feature * PMASA-2019-4 is a CSRF attack that’s possible through the ‘cookie’ login form Upgrading is highly recommended for all users. Using the ‘http’