Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Multiple vulnerabilities have been found in xymon, the network monitoring application. Remote attackers might leverage these vulnerabilities in the CGI parsing code (including buffer overflows and XSS) to cause denial of service, or any other unspecified impact.

Update to v1.15.2 + carry upstream #81330

Even Rouault found an issue in tiff, a library providing support for the Tag Image File Format. Wrong handling off integer overflow checks, that are based on undefined

Addresses CVE-2019-14462 and CVE-2019-14463

Addresses CVE-2019-14462 and CVE-2019-14463

Update to Node.js 10.6.13

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has two fixes is now available.

An update that solves three vulnerabilities and has two fixes is now available.

It was discovered that there was a remote arbitrary code vulnerability in commons-beanutils, a set of utilities for manipulating JavaBeans code.

The package nginx before version 1.16.1-1 is vulnerable to denial of service.

The package nginx-mainline before version 1.17.3-1 is vulnerable to denial of service.

The package firefox before version 68.0.2-1 is vulnerable to information disclosure.

The package subversion before version 1.12.2-1 is vulnerable to denial of service.

The package libreoffice-still before version 6.2.6-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure.

An update that fixes one vulnerability is now available.

Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP server, which could result in denial of service. For the stable distribution (buster), these problems have been fixed in

Several vulnerabilities were discovered in Squid, a fully featured web proxy cache. The flaws in the HTTP Digest Authentication processing, the HTTP Basic Authentication processing and in the cachemgr.cgi allowed remote attackers to perform denial of service and cross-site scripting

Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, the execution of arbitrary code or bypass of ACLs.

security update

2019-08-14 – Fix compile issues – Fix output buffer size for lzo1x_decompress_safe() 2019-08-07 – Fix VerifyExtensionMap #179 2019-08-06 – Fix compile errors 2019-08-05 – Fix nfdump.1 man page. #175 – Fix off by 1 array. #173 – Fix use after free in ModifyCompressFile – Add bound checks in AddExporterStat #174 – Add bound checks in […]

security update

Three vulnerabilities were discovered in the HTTP/2 code of Nginx, a high-performance web and reverse proxy server, which could result in denial of service.

An update that fixes one vulnerability is now available.

This update includes the latest release of the Apache HTTP Server, version `2.4.41`, fixing various security issues. Several major enhancements are also included in this update: * `mod_md` is now packaged from upstream *github* releases, adding support for ACMEv2. * `mod_cgid` stderr handling has been improved See http://www.apache.org/dist/httpd/CHANGES_2.4.41 for a full list of

This update includes the latest release of the Apache HTTP Server, version `2.4.41`, fixing various security issues. Several major enhancements are also included in this update: * `mod_md` is now packaged from upstream *github* releases, adding support for ACMEv2. * `mod_cgid` stderr handling has been improved See http://www.apache.org/dist/httpd/CHANGES_2.4.41 for a full list of

– update to the latest upstream release (fixes CVE-2019-9511 and CVE-2019-9513)

– Security fix for CVE-2019-13636 – Security fix for CVE-2019-13638

The latest security update of openjdk-7 caused a regression when applications relied on elliptic curve algorithms to establish SSL connections. Several duplicate classes were removed from rt.jar by the upstream developers of OpenJDK because they were also present in

Two issues have been found in cups, the Common UNIX Printing System(tm). Basically both CVEs (CVE-2019-8675 and CVE-2019-8696) are about

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has 7 fixes is now available.

An update that contains security fixes can now be installed.

Security flaws caused by compiler optimizations

An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for atomic-openshift-web-console is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Fixes CVE-2019-9511, CVE-2019-9513, CVE-2019-9516

security update

Multiple security issues were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed file/stream is processed.

An update that solves one vulnerability and has one errata is now available.

Several security issues were fixed in OpenJPEG.

An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Zstandard could be made to execute arbitrary code if it received specially crafted input.

An update that fixes 30 vulnerabilities is now available.

An update is now available for Red Hat Ceph Storage 3.3 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

A security update for Red Hat 3scale API Management Platform is now available from the Red Hat Container Catalog. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

– Fix for CVE-2019-10216 added

updated to 1.4 branch snapshot containing several security fixes

Security fix for CVE-2019-1010238

– Fix for CVE-2019-10216 added

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Several security issues were fixed in GIFLIB.

Flask, a micro web framework for Python contains a CWE-20: Improper Input Validation vulnerability that can result in Large amount of memory usage possibly leading to denial of service. This attack appear

NLTK could be made to overwrite files.

Several security issues were fixed in CUPS.

security update

Nova could be made to expose sensitive information.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that contains security fixes can now be installed.

Docker could be made to crash or run programs as your login.

docker-credential-helpers could be made to crash or run programs as your login

Several security issues were fixed in OpenLDAP.

Several security issues were fixed in LibreOffice.

KConfig and KDE libraries could be made to crash or run programs if it opened a specially crafted file.

An update for rh-php71-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** – `kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to […]

Security fix for CVE-2019-1010189

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has 11 fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that solves three vulnerabilities and has 41 fixes is now available.

This update fixes 2 security issues. A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure (CVE-2019-10192).

Updated postgresql packages fix security vulnerabilities: Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function

Updated mariadb packages fix security vulnerabilities: An easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise mariadb server. Successful attacks of this vulnerability can result in unauthorized

This update provides and update to mythtv 30, and updates the bundled ffmpeg to 3.2. It also fixes atleast the following issue: The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 4.0.2 does not check for an empty audio packet, leading to an assertion

It was discovered that elfutils incorrectly handled certain malformed files. If a user or automated system were tricked into processing a specially crafted file, elfutils could be made to crash or consume resources, resulting in a denial of service (CVE-2017-7607, CVE-2017-7608, CVE-2017-7609, CVE-2017-7610, CVE-2017-7611, CVE-2017-7612, CVE-2017-7613,

A vulnerability in hostapd and wpa_supplicant could lead to a Denial of Service condition.

Multiple vulnerabilities have been found in MariaDB and MySQL, the worst of which could result in privilege escalation.

Multiple vulnerabilities have been found in VLC, the worst of which could result in the arbitrary execution of code.

security update

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2473

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2471

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

security update

An update that fixes 10 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.