LinuxSecurity.com: Security fix for CVE-2018-20551, CVE-2018-20481, CVE-2018-20650 and CVE-2018-18897.
LinuxSecurity.com: Security fix for CVE-2019-5010 in Python. Anaconda is joined because an unrelated fix was done there that allowed to remove a workaround in Python.
LinuxSecurity.com: – xattr: strip credentials from any URL that is stored (CVE-2018-20483)
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: Multiple vulnerabilities were found in the journald component of systemd which can lead to a crash or code execution. CVE-2018-16864
LinuxSecurity.com: Fix for CVE-2019-5885 Upgrade notes available at https://github.com/matrix- org/synapse/blob/v0.34.0/UPGRADE.rst#upgrading-to-v0340 – Note this continues to use Python 2.
LinuxSecurity.com: Several vulnerabilities have been resolved in libjpeg-turbo, Debian’s default JPEG implemenation. CVE-2016-3616
LinuxSecurity.com: It was discovered that aria2 (the lightweight command-line download utility) can store passed user credentials in a log file when using the –log option. This might allow local users to obtain sensitive information by reading this file.
security update
LinuxSecurity.com: admin: Prevent access if any authentication agent isn’t available
LinuxSecurity.com: Fix for use after free in affile_dw_reap
LinuxSecurity.com: libssh versions 0.6 and above have an authentication bypass vulnerability in the server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS message in place of the SSH2_MSG_USERAUTH_REQUEST message which the server would expect to initiate authentication, the attacker could successfully authentciate
LinuxSecurity.com: Security fix for CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 through rebase to 3.2.0
LinuxSecurity.com: **PHP version 7.2.14** (10 Jan 2019) **Core:** * Fixed bug php#77369 (memcpy with negative length via crafted DNS response). (Stas) * Fixed bug php#71041 (zend_signal_startup() needs ZEND_API). (Valentin V. Bartenev) * Fixed bug php#76046 (PHP generates “FE_FREE” opcode on the wrong line). (Nikita) **Date:** * Fixed bug php#77097 (DateTime::diff gives wrong diff when the
security update
LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.
LinuxSecurity.com: Several security issues were fixed in libcaca.
LinuxSecurity.com: This update fixes CVE-2018-20685 (the first “variant”) and backports several fixes to unbreak ECDSA authentication from PKCS#11, certificate authentication and so on.
LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).
LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).
LinuxSecurity.com: Patch for CVE-2016-10091
LinuxSecurity.com: It was observed that URL’s which gets downloaded via “–log=” attribute stores sensitive information. This update fixes that. References: – https://bugs.mageia.org/show_bug.cgi?id=24112
LinuxSecurity.com: A heap use-after-free vulnerability in the server code of the file transfer extension, which can result in remote code execution. This attack appears to be exploitable via network connectivity (CVE-2018-6307).
LinuxSecurity.com: Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys (CVE-2018-0495). References:
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
security update
security update
LinuxSecurity.com: Several issues in wireshark, a tool that captures and analyzes packets off the wire, have been found by different people. These are basically issues with length checks or invalid memory access in
LinuxSecurity.com: libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) SL7 x86_64 libvncserver-0.9.9-13.el7_6.i686.rpm libvncserver-0.9.9-13.el7_6.x86_64.rpm libvncserver-debuginfo-0.9.9-13.el7_6.i686.rpm libvncserver-debuginfo-0.9.9-13.el7_6.x86_64.rpm libvncserver-devel-0.9.9-13.el7_6.i686.rpm [More…]
LinuxSecurity.com: Several security issues were fixed in libcaca.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0049
LinuxSecurity.com: An update for libvncserver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: The v4.19.14 stable update contains important fixes across the tree.
security update
LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: New zsh packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.
LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in systemd-journald. Two memory corruption flaws, via attacker-controlled alloca()s (CVE-2018-16864, CVE-2018-16865) and an out-of-bounds read flaw leading to an information leak (CVE-2018-16866), could allow an attacker to
LinuxSecurity.com: The package python2-django before version 1.11.18-1 is vulnerable to content spoofing.
LinuxSecurity.com: The package python-django before version 2.1.5-1 is vulnerable to content spoofing.
security update
LinuxSecurity.com: Due to kernel issue there is a way to reuse start_time of a process. This allows to duplicate process authorized by polkit. This update mitigates polkit issue #75 (slowfork): https://gitlab.freedesktop.org/polkit/polkit/issues/75
LinuxSecurity.com: An integer underflow was discovered in the CAF demuxer of the VLC media player. For the stable distribution (stretch), this problem has been fixed in
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: Resolves CVE-2018-16869
LinuxSecurity.com: Resolves CVE-2018-16869
LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
security update
LinuxSecurity.com: The package wireshark-cli before version 2.6.6-1 is vulnerable to multiple issues including information disclosure and denial of service.
LinuxSecurity.com: The package systemd before version 240.0-3 is vulnerable to multiple issues including arbitrary file overwrite and information disclosure.
LinuxSecurity.com: read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header (CVE-2017-14502).
LinuxSecurity.com: Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe “cat README.md” command when e}pn is used. A popmedia control sequence can allow the malicious execution of executable file formats registered in the X desktop share MIME types (/usr/share/applications). The control sequence defers
LinuxSecurity.com: fix CVE-2019-3498 python-django: Content spoofing via URL path in
LinuxSecurity.com: backport anti-phishing fixes
LinuxSecurity.com: **Horde_Image 2.5.4** * [mjr] SECURITY: Fix potential RCE in the text method when using the Imagemagick backend. * [mjr] SECURITY: Sanitize image type parameter (PR: 2, Fariskhi Vidyan). * [mjr] Fix issues with escaping single and double quote characters in the text method when using the Imagemagick backend.
LinuxSecurity.com: A bug in the server implementation of RTSP-over-HTTP in live could allow a denial-of-service attack. A bug in the server implementation of RTSP-over-HTTP could allow a buffer overflow, which could result in the execution of arbitrary code
LinuxSecurity.com: An authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request (CVE-2018-20217). References:
LinuxSecurity.com: A vulnerability was found in mbedTLS which allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites (CVE-2018-19608). References:
LinuxSecurity.com: Security fix for CVE-2018-1000532, new non-root permissions and a few smaller fixes. Fix a directory traversal issue introduced with the fix for CVE-2018-1000532, and refuses to run as setuid root or via sudo to avoid any more priviledge escalation issue. —- Security fix for CVE-2018-1000532 and a few smaller fixes
LinuxSecurity.com: libgxps 0.3.1 release. – Fix font scaling when converting xps to pdf – Handle errors returned by archive_read_data in GXPSArchive – Ensure gxps_archive_read_entry() fills the GError in case of failure – Make the pdf generated by xpstopdf to be 96 dpi – Fix OUTPUT FILE description in man pages – Clear the GError before […]
LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
LinuxSecurity.com: Several vulnerabilities were discovered in libcaca, a graphics library that outputs text: integer overflows, floating point exceptions or invalid memory reads may lead to a denial-of-service (application crash) if a malformed image file is processed.
LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.
LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.
