Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

A heap-based buffer overflow was discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of this flaw for local root privilege escalation.

Libzip could be made to crash if it received specially crafted input.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0622

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0623

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes three vulnerabilities is now available.

Update tcpflow to 1.5.2 tag at github, fixing a security issue.

security update

security update

security update

Press Release: Guardian Digital Leverages the Power of Open Source to Combat Evolving Email Security Threats

Proxy Auto-Configuration file can define localhost access to be proxied (CVE-2018-18506). Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6 (CVE-2019-9788).

In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c. (CVE-2019-7397) References: – https://bugs.mageia.org/show_bug.cgi?id=24396

The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837). The fetch module was susceptible to path traversal (CVE-2019-3828).

Several security issues were fixed in Ghostscript.

An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

NTFS-3G could be made to crash or potentially run programs as anadministrator if executed with specially crafted arguments.

An update that fixes three vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes two vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves 9 vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

The package wordpress before version 5.1-1 is vulnerable to directory traversal.

The package libelf before version 0.176-1 is vulnerable to denial of service.

Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to gain unauthorized access.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0597

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

security update

Youve Been Pwned! Best Practices to Prevent Your Email Account from Being Compromised in a Data Breach

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

cloud-init: extra ssh keys added to authorized_keys on the Azure platform (CVE-2019-0816) SL7 x86_64 cloud-init-18.2-1.el7_6.2.x86_64.rpm – Scientific Linux Development Team

An update that fixes 9 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0482

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0485

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0483

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0512

It has been discovered that OTRS (Open source Ticket Request System) is susceptible to code injection vulnerability. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully

An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

The CLI tools in python-rdflib-tools can load python modules found in the current directory. This happens because “python -m” appends the current directory in the python path.

The ikiwiki maintainers discovered that the aggregate plugin did not use LWPx::ParanoidAgent. On sites where the aggregate plugin is enabled, authorized wiki editors could tell ikiwiki to fetch potentially undesired URIs even if LWPx::ParanoidAgent was installed:

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

Two vulnerabilities were discovered in SQLALchemy, a Python SQL Toolkit and Object Relational Mapper.

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has four fixes is now available.

LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

Several security issues were fixed in file.

An update for openstack-octavia is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for ansible is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes 18 vulnerabilities is now available.

Security fix CVE-2019-9210

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that fixes three vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that solves 8 vulnerabilities and has 73 fixes is now available.

Several security issues identified in ikiwiki fixed by updating to version 3.20190228. See references for details References: – https://bugs.mageia.org/show_bug.cgi?id=24453

An update that fixes two vulnerabilities is now available.

An update is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openstack-octavia is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-ceilometer is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for haproxy is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for haproxy is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Multiple vulnerabilities have been found in Oracles JDK and JRE software suites.

Multiple vulnerabilities have been found in BIND, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.

A vulnerability was discovered in XRootD which could lead to the remote execution of code.

Multiple Information Disclosure vulnerabilities in OpenSSL allow attackers to obtain sensitive information.

A vulnerability in the GNU C Library could result in a Denial of Service condition.

security update

security update

Multiple buffer overflow security issues have been found in libsdl2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard.

Multiple buffer overflow security issues have been found in libsdl1.2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard.

cockpit: Crash when parsing invalid base64 headers (CVE-2019-3804) SL7 x86_64 cockpit-173.2-1.el7.x86_64.rpm cockpit-bridge-173.2-1.el7.x86_64.rpm cockpit-debuginfo-173.2-1.el7.i686.rpm cockpit-debuginfo-173.2-1.el7.x86_64.rpm cockpit-ws-173.2-1.el7.i686.rpm cockpit-ws-173.2-1.el7.x86_64.rpm cockpit-doc-173.2-1.el7.x86_64.rpm cockpit-173.2-1.el7.src.rpm noa [More…]

openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) (CVE-2018-5407) Bug Fix(es): * Perform the RSA signature self-tests with SHA-256 SL7 x86_64 openssl-1.0.2k-16.el7_6.1.x86_64.rpm openssl-debuginfo-1.0.2k-16.el7_6.1.i686.rpm openssl-debuginfo-1.0.2k-16.el7_6.1.x86_64.rpm openssl-libs-1.0.2k-16.el7_6.1.i686.rpm openssl-libs-1.0.2k-16.el [More…]

An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Updates for rh-dotnetcore10-dotnetcore, rh-dotnetcore11-dotnetcore, rh-dotnet21-dotnet, and rh-dotnet22-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

It was found that the fix for CVE-2018-19758 was incomplete. That has been addressed in this update. The description for CVE-2018-19758 follows:

An update for cockpit is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Ross Geerlings discovered that the XMLTooling library didn’t correctly handle exceptions on malformed XML declarations, which could result in denial of service against the application using XMLTooling.

Why Your Current Approach to Email Security May Not Be Enough

LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

An update that solves 8 vulnerabilities and has two fixes is now available.

Several security vulnerabilities were discovered in Zabbix, a server/client network monitoring solution. CVE-2016-10742

The package pacman before version 5.1.3-1 is vulnerable to arbitrary code execution.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0462

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update