Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that fixes one vulnerability is now available.

Several security issues were fixed in curl.

An update for rh-dotnet21-dotnet and rh-dotnet22-dotnet is now available for .NET Core on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for dotnet is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves three vulnerabilities and has 9 fixes is now available.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the pki-deps:10.6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for poppler is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for libwmf is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

USN 4115-1 introduced a regression in the Linux kernel.

An update for the openshift and atomic-enterprise-service-catalog packages is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

security update

security update

security update

An update that fixes 24 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in Python.

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for polkit is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

It was discovered that the code fixes for LibreOffice to address CVE-2019-9852 were not complete. Additional information can be found at https://www.libreoffice.org/about-us/security/advisories/CVE-2019-9854/

An update that fixes 8 vulnerabilities is now available.

Memcached could be made to expose sensitive information if it received a specially crafted UNIX socket.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update for go-toolset-1.11 and go-toolset-1.11-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update to 2.0.16

Update to 2.0.16

Chromium update to 76.0.3809.132.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An authentication bypass was discovered in D-Bus.

Multiple vulnerabilities have been found in Simple DirectMedia Layer, the worst of which could result in the arbitrary execution of code.

Updated dovecot packages fix security vulnerability: IMAP protocol parser does not properly handle NUL byte when scanning data in quoted strings, leading to out of bounds heap memory writes.

Updated tomcat packages fix security vulnerabilities: The HTTP/2 implementation accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for

This release fixes a heap buffer over-read in BlitNtoN() function when processing an invalid BMP image. It also updates a URL in the RPM metadata.

**Version 1.3.10** – Managesieve: Fix so “Create filter” option does not show up when Filters menu is disabled (#6723) – Enigma: Fix bug where revoked users/keys were not greyed out in key info – Enigma: Fix error message when trying to encrypt with a revoked key (#6607) – Enigma: Fix “decryption oracle” bug [CVE-2019-10740] (#6638) […]

Security fix for CVE-2019-15043

Resolves: rhbz#1609774 nsd-4.2.2 is available

Fixes for CVE-2019-6472, CVE-2019-6473 and CVE-2019-6474

This release fixes a heap buffer over-read in BlitNtoN() function when processing an invalid BMP image. It also updates a URL in the RPM metadata.

Security fix for CVE-2019-15043

An update that fixes one vulnerability is now available.

It was discovered that various procedures in Ghostscript, the GPL PostScript/PDF interpreter, do not properly restrict privileged calls, which could result in bypass of file system restrictions of the dSAFER sandbox.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

It was discovered that there was a stack-based buffer over-read in memcached, the in-memory object caching system. For Debian 8 “Jessie”, this issue has been fixed in memcached version

Multiple vulnerabilities have been found in Exim, the worst of which allows remote attackers to execute arbitrary code.

security update

An update that fixes one vulnerability is now available.

Exim could be made to run programs as an administrator if it received specially crafted network traffic.

Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Apache, the worst of which could result in a Denial of Service condition.

A buffer overflow in Pango might allow an attacker to execute arbitrary code.

Multiple vulnerabilities have been found in VLC, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Perl, the worst of which could result in the arbitrary execution of code.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

It was discovered that there was a heap-based buffer overread vulnerability in expat, an XML parsing library. A specially-crafted XML input could fool the parser into changing

* Security fix for CVE-2019-14267 * Security fix for CVE-2019-14934

Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling.

Update LXC to version 3.0.4. The release announcement can be found [here](https://discuss.linuxcontainers.org/t/lxc-3-0-4-has-been-released/5080).

security update

security update

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has 19 fixes is now available.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, bypass of the same-origin policy, sandbox escape, information disclosure or denial of service.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 12 vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

npm/fstream could be made to overwrite files.

An update that solves 12 vulnerabilities and has 19 fixes is now available.

security update

The package jenkins before version 2.192-1 is vulnerable to multiple issues including cross-site request forgery and cross-site scripting.

The package grafana before version 6.3.4-1 is vulnerable to denial of service.

An update that solves three vulnerabilities and has two fixes is now available.

Several newly-referenced issues have been fixed in the FreeType 2 font engine.

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update for openstack-nova is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Alf-Andre Walla discovered a remotely triggerable assert in the Varnish web accelerator; sending a malformed HTTP request could result in denial of service.

The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]

The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]

The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]