LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for libnettle fixes the following issues: Security issues fixed:
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. Description: Description: This update for tiff fixes the following issues: Security issues fixed:
LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for git fixes the following issues: Security issue fixed:
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for bluez fixes the following issues: Security issues fixed:
LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available. Description: Description: This new package for go1.11 fixes the following issues: Security issues fixed: – CVE-2018-16873: Fixed a remote code execution in go get, when executed [More…] with the -u flag (bsc#1118897) with the -u flag (bsc#1118897) [More…] – CVE-2018-16874: Fixed […]
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3834
LinuxSecurity.com: Update to 2.7.5 bugfix release. Fix for CVE-2018-16876
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in wmi_set_ie. […]
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in […]
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:
LinuxSecurity.com: Updated packages are now available for Red Hat Gluster Storage 3.4 Web Administration on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: – Update to 2.14.1 – CVE-2018-19608 (#1656784) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-03 —- – Update to 2.14.0 Release notes:
LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644
LinuxSecurity.com: New upstream version 1.8.2. Fix low priority security issue with TLS: https://www.redhat.com/archives/libguestfs/2018-December/msg00047.html —- New upstream version 1.8.1. —- Rebase to new stable version 1.8.0. —- nbdkit metapackage should depend on versioned -server subpackage etc. —- New upstream version 1.6.3.
LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.
LinuxSecurity.com: – Buffer overflow using computed size of canvas element. (CVE-2018-12359) – Use-after-free when using focus(). (CVE-2018-12360) – Integer overflow in SwizzleData. (CVE-2018-12361)
LinuxSecurity.com: It was discovered there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack (CVE-2018-19208). References:
LinuxSecurity.com: Cache side-channel variant of the Bleichenbacher attack.(CVE-2018-12404) References: – https://bugs.mageia.org/show_bug.cgi?id=23972 – https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.6_release_notes
LinuxSecurity.com: A buffer overflow and out-of-bounds read can occur in TextureStorage11 within the ANGLE graphics library, used for WebGL content. This results in a potentially exploitable crash (CVE-2018-17466). A use-after-free vulnerability can occur after deleting a selection
LinuxSecurity.com: A vulnerability in Scala could result in privilege escalation.
LinuxSecurity.com: Multiple vulnerabilities have been found in SpamAssassin, the worst of which may lead to remote code execution.
LinuxSecurity.com: Multiple vulnerabilities have been found in CouchDB, the worst of which could lead to the remote execution of code.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:
LinuxSecurity.com: This update fixes libstdc++ std::future support on armel, which is necessary to get firefox-esr and thunderbird updates built on that architecture.
security update
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: The package firefox before version 64.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass and access restriction bypass.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
LinuxSecurity.com:
LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.
LinuxSecurity.com: USN-3837-1 introduced a regression in poppler.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.
security update
LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.
LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.
LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package lib32-openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package lib32-openssl before version 1:1.1.1.a-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package openssl before version 1.1.1.a-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package texlive-bin before version 2018.48691-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package wireshark-cli before version 2.6.5-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: The package chromium before version 71.0.3578.80-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and insufficient validation.
LinuxSecurity.com: CUPS could be made to expose sensitive information.
LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.
LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.
LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.6 Telco Update Service (TUS). This notification applies only to those customers subscribed to the Telco Update Service (TUS) channel for Red Hat Enterprise Linux 6.6.
LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 7.3 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.3.
LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.
LinuxSecurity.com: Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF module was susceptible to denial of service/information disclosure when parsing malformed images, the Apache module allowed cross-site-scripting via the body of a
LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: It was discovered that there was a XSS injection vulnerability in the LXML HTML/XSS manipulation library for Python. LXML did not remove “javascript:” URLs that used escaping such as
LinuxSecurity.com: An update for rh-git218-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service (CVE-2018-1336). The defaults settings for the CORS filter are insecure and enable
LinuxSecurity.com: An update that fixes 27 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
security update
LinuxSecurity.com: Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983)
LinuxSecurity.com: The HTML thumbnailer was incorrectly accessing some content of remote URLs listed in HTML files. This meant that the owners of the servers referred in HTML files in your system could have seen in their access logs your IP address every time the thumbnailer tried to create the thumbnail (CVE-2018-19120).
