Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

Fixes **CVE-2017-18189**.

This update fixes CVE-2020-6851.

This update fixes CVE-2020-6851.

Fix a potential out of bounds write when checking a maliciously corrupted file system. This is probably not exploitable on 64-bit platforms, but may be exploitable on 32-bit binaries depending on how the compiler lays out the stack variables. (Addresses CVE-2019-5188) A maliciously corrupted file systems can trigger buffer overruns in the quota code used […]

security update

January 2020 CPU security update. See http://mail.openjdk.java.net/pipermail/jdk8u-dev/2020-January/010979.html https://openjdk.java.net/groups/vulnerability/advisories/2020-01-14

Update to Samba 4.11.6 —- Update to Samba 4.11.5 – Security fixes for CVE-2019-14902, CVE-2019-14907 and CVE-2019-19344

A stack-based buffer overflow vulnerability in sudo, a program designed to provide limited super user privileges to specific users, triggerable when configured with the pwfeedback option enabled. An unprivileged user

Joe Vennix discovered a stack-based buffer overflow vulnerability in sudo, a program designed to provide limited super user privileges to specific users, triggerable when configured with the “pwfeedback” option enabled. An unprivileged user can take advantage of this flaw to obtain

A heap-based buffer overflow vulnerability was discovered in the idn2_to_ascii_4i() function in libidn2, the GNU library for Internationalized Domain Names (IDNs), which could result in denial of service, or the execution of arbitrary code when processing a long

An issue was found in the IonMonkey JIT compiler of the Mozilla Firefox web browser which could lead to arbitrary code execution. For Debian 8 “Jessie”, this problem has been fixed in version

security update

security update

In Qt5’s plugin loader code as found in qtbase-opensource-src, it was possible to (side-)load plugins from “the” local folder in addition to a system-widely defined library path.

* Fix issues while trying to play a video on NextCloud. * Make sure the GL video sink uses a valid WebKit shared GL context. * Fix vertical alignment of text containing arabic diacritics. * Fix build with icu 65.1. * Fix page loading errors with websites using HSTS. * Fix web process crash when […]

Several vulnerabilities were fixed in libjackson-json-java. CVE-2017-7525

An update that solves one vulnerability and has three fixes is now available.

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanag es memory, as demonstrated by IRC DCC commands in EMU_IRC.

* Fix issues while trying to play a video on NextCloud. * Make sure the GL video sink uses a valid WebKit shared GL context. * Fix vertical alignment of text containing arabic diacritics. * Fix build with icu 65.1. * Fix page loading errors with websites using HSTS. * Fix web process crash when […]

Update to 79.0.3945.130. Fixes the following security issues: * CVE-2020-6378 * CVE-2020-6379 * CVE-2020-6380

This is January 2020 OpenJDK security update for java-latest-openjdk packages. The sources are updated to the 13.0.2+8 tag.

Update to bugfix release 2.9.3. See https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst

security update

security update

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code.

Two vulnerabilities have recently been discovered in the stream-tcp code of the intrusion detection and prevention tool Suricata.

An update that solves one vulnerability and has four fixes is now available.

Several vulnerabilities have been discovered in the otrs2 package that may lead to unauthorized access, remote code execution and spoofing.

Apache Solr could be made to run programs if it received specially crafted network traffic.

Time to celebrate Data Privacy Day!

The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2019-8835

It was discovered that there were a large number of NULL pointer dereferences due to unchecked return values from malloc and friends in hiredis, a minimalistic C client library.

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Libgcrypt could be made to expose sensitive information.

OpenJPEG had a heap-based buffer overflow in opj_t1_clbl_decode_processor in libopenjp2.so.

An update that fixes three vulnerabilities is now available.

An update for openjpeg2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in tcpdump.

Several security issues were fixed in Tomcat.

Several security issues were fixed in MySQL.

An update for nss is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This update fixes CVE-2019-20093.

This update fixes CVE-2019-20093.

An update that fixes 5 vulnerabilities is now available.

This update fixes CVE-2019-20093.

This update fixes CVE-2019-20093.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

– Security fix for CVE-2019-19746, CVE-2019-19797 – New upstream release 3.2.7b – Add patch fixing CVE-2019-19746 (rhbz#1787040) – Add patch fixing CVE-2019-19797 (rhbz#1786726)

– Security fix for CVE-2019-19746, CVE-2019-19797 – New upstream release 3.2.7b – Add patch fixing CVE-2019-19746 (rhbz#1787040) – Add patch fixing CVE-2019-19797 (rhbz#1786726)

** MySQL 8.0.19 ** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-19.html

Security fix for CVE-2020-5395:out-of-bounds write in sfd.c

security update

An update that fixes 7 vulnerabilities is now available.

update to enigmail 2.1.5 Includes a security fix for “Unsigned MIME parts displayed as signed”

Update to 12.14.1 Add new subpackage `nodejs-full-i18n` to provide non-English locale and Unicode support.

Update to 12.14.1 Add new subpackage `nodejs-full-i18n` to provide non-English locale and Unicode support.

New upstream release with security fixes for CVE-2019-15945, CVE-2019-15946, CVE-2019-19479, CVE-2019-19480, CVE-2019-19481

An update that solves three vulnerabilities and has one errata is now available.

USN-4233-1 marked SHA1 as untrusted in GnuTLS with no workaround.

An update for ansible is now available for Ansible Engine 2 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.9 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.8 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.7 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Several security issues were fixed in python-apt.

security update

An update that fixes three vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086) SL7 noarch apache-commons-beanutils-1.8.3-15.el7_7.noarch.rpm apache-commons-beanutils-javadoc-1.8.3-15.el7_7.noarch.rpm – Scientific Linux Development Team

An update that solves 5 vulnerabilities and has one errata is now available.

python-reportlab: code injection in colors.py allows attacker to execute code (CVE-2019-17626) SL6 x86_64 python-reportlab-2.3-3.el6_10.1.x86_64.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.x86_64.rpm i386 python-reportlab-2.3-3.el6_10.1.i686.rpm python-reportlab-debuginfo-2.3-3.el6_10.1.i686.rpm noarch python-reportlab-docs-2.3-3.el6_10.1.noarch.rpm – Scientific L [More…]

security update

security update

A security update is now available for Open Liberty 20.0.0.1 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openvswitch2.12 is now available for Fast Datapath for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

security update

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

Update to Rack 2.0.8.

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests

Updated wireshark packages fix security vulnerability: BT ATT dissector crash (CVE-2020-7045). References:

Updated suricata packages fix security vulnerabilities: The suricata package has been updated to version 4.1.6, which fixes security issues and other bugs. See the upstream announcements for details.

Updated tigervnc packages fix security vulnerabilities: The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues. These issues affect both the client and server and could theoretically allow an malicious peer to take control over the