Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

Security fix for CVE-2019-11459.

Update to 1.1.33 and fix CVE-2019-11068

Upstream announcement: Welcome to **phpMyAdmin 4.9.0.1**, a bugfix release that includes important security fixes. This release fixes two security vulnerabilities: * PMASA-2019-3 is an SQL injection flaw in the Designer feature * PMASA-2019-4 is a CSRF attack that’s possible through the ‘cookie’ login form Upgrading is highly recommended for all users. Using the ‘http’

dovecot updated to 2.3.6, includes several security fixes

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

The package gvim before version 8.1.1467-1 is vulnerable to arbitrary code execution.

The package vim before version 8.1.1467-1 is vulnerable to arbitrary code execution.

The package openssl before version 1.1.1.c-1 is vulnerable to information disclosure.

The package lib32-openssl before version 1:1.1.1.c-1 is vulnerable to information disclosure.

An update that fixes 15 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update for python is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

1717503 – Security issue: patch 8.1.1365: source command doesn’t check for the sandbox

An update that solves one vulnerability and has three fixes is now available.

An update that solves one vulnerability and has one errata is now available.

Consistent PKCS #11 support in Red Hat Enterprise Linux 8

An update that fixes four vulnerabilities is now available.

Update to 2.3.4 upstream release

update to 2.1.9

Resolves: #1715758 – CVE-2019-9946

Update to v1.24.3

security update

security update

security update

An unitialized read was discovered in the XBM support of libgd2, a library for programmatic graphics creation and manipulation. The unitialized read might lead to information disclosure.

An update that fixes one vulnerability is now available.

A security update is now available for Red Hat Single Sign-On 7.3 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

What you need to know about the MDS vulnerability and Red Hat Virtualization

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 16 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

The updated Advanced Virtualization module is now available for Red Hat Enterprise Linux 8.0 Advanced Virtualization. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-haproxy18-haproxy is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for atomic-openshift-web-console is now available for Red Hat Openshift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 17 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

A flaw was discovered in the CalDAV feature in httpd of the Cyrus IMAP server, leading to denial of service or potentially the execution of arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

security update

An update that solves one vulnerability and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that solves two vulnerabilities and has 13 fixes is now available.

An update that fixes four vulnerabilities is now available.

Update to version 3.0.10, which fixes a security issue (a buffer overrun vulnerability in the httpd daemon, CVE-2019-11356).

An update that fixes one vulnerability is now available.

Hanno Bck discovered that Evolution was vulnerable to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security bar with encryption and signature information above the message

security update

Update to version 3.0.10, which fixes a security issue (a buffer overrun vulnerability in the httpd daemon, CVE-2019-11356).

Update to version 2.8 from upstream, Security fix for [CVE-2019-11555]

security update

An update that fixes four vulnerabilities is now available.

An update that solves 24 vulnerabilities and has two fixes is now available.

A vulnerability in Exim could allow a remote attacker to execute arbitrary commands.

An update that fixes one vulnerability is now available.

An update for qpid-proton is now available for Red Hat OpenStack Platform 14 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for qpid-proton is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for qpid-proton is now available for Red Hat OpenStack Platform 14 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Understanding random number generators, and their limitations, in Linux

Vincent Tondellier reported that the qemu update issued as DSA 4454-1 did not correctly backport the support to define the md-clear bit to allow mitigation of the MDS vulnerabilities. Updated qemu packages are now available to correct this issue.

Several vulnerabilities have been found in the poppler PDF rendering library, which could result in denial of service or possibly other unspecified impact when processing malformed or maliciously crafted files.

The Qualys Research Labs reported a flaw in Exim, a mail transport agent. Improper validation of the recipient address in the deliver_message() function may result in the execution of arbitrary commands.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

It was discovered that there was a cross-site scripting (XSS) vulnerability in the Django web development framework. For Debian 8 “Jessie”, this issue has been fixed in python-django version

security update

Guardian Digital Celebrates 20 Years of Revolutionizing Digital Security, Securing Email with Open Source

An update for systemd is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The package python-django before version 2.2.2-1 is vulnerable to cross-site scripting.

The package python2-django before version 1.11.21-1 is vulnerable to cross-site scripting.

An update that contains security fixes can now be installed.

An update that solves 5 vulnerabilities and has 6 fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

An update that solves 5 vulnerabilities and has 6 fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 16 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.