Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that solves two vulnerabilities and has one errata is now available.

An update that solves 8 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 8 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

It was discovered that the code fixes to address CVE-2018-16858 and CVE-2019-9848 were not complete. For the oldstable distribution (stretch), these problems have been fixed

**MariaDB 10.3.17** Release notes: https://mariadb.com/kb/en/mariadb-10317-release-notes/ **MariaDB Connector/C 3.1.3** Release notes: https://mariadb.com/kb/en/mariadb- connector-c-313-release-notes/ **MariaDB Connector/ODBC 3.1.2** Release notes: https://mariadb.com/kb/en/mariadb-connector-odbc-312-release-notes/ —–

nginx could be made to crash if it received specially crafted network traffic.

fixes for CVE-2019-14232 to 14235

Multiple vulnerabilities have been found in imagemagick, an image processing toolkit. CVE-2019-12974

Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, information disclosure or the execution of arbitrary code.

A buffer over-read in the t1-parser of freetype, a font engine, has been found and fixed by checking limits more sensible.

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mysql:8.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]

A vulnerability in ZeroMQ might allow an attacker to execute arbitrary code.

A vulnerability in ProFTPD could result in the arbitrary execution of code.

A vulnerability in ZNC allows users to escalate privileges.

Multiple vulnerabilities have been found in polkit, the worst of which could result in privilege escalation.

Multiple vulnerabilities have been found in LibreOffice, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in libarchive, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Oracles JDK and JRE software suites.

Multiple vulnerabilities have been found in SQLite, the worst of which could result in the arbitrary execution of code.

security update

security update

An update that fixes two vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Several security issues have been fixed in otrs2, a well known trouble ticket system.

An update that fixes 7 vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

wpa_supplicant and hostapd could be made to expose sensitive information over the network.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes four vulnerabilities is now available.

security update

An update that solves four vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has three fixes is now available.

An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that fixes one vulnerability is now available.

An update that fixes 16 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

security update

security update

The package postgresql before version 11.5-1 is vulnerable to multiple issues including access restriction bypass and information disclosure.

The package postgresql-libs before version 11.5-1 is vulnerable to multiple issues including access restriction bypass and information disclosure.

The package chromium before version 76.0.3809.100-1 is vulnerable to arbitrary code execution.

An update that fixes one vulnerability is now available.

poppler could be made to crash if it received specially crafted PDF.

An update for cockpit-ovirt is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several vulnerabilities were discovered in python-django, a web development framework. They could lead to remote denial-of-service or SQL injection,

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

Security fix for CVE-2018-19800 CVE-2018-19801 CVE-2018-19802

Security fix for CVE-2018-19800 CVE-2018-19801 CVE-2018-19802

Benno Fuenfstueck discovered that Pango, a library for layout and rendering of text with an emphasis on internationalization, is prone to a heap-based buffer overflow flaw in the pango_log2vis_get_embedding_levels function. An attacker can take advantage of this flaw for denial of

The 5.2.7 stable kernel update contains a number of important fixes across the tree. —- The 5.2.6 kernel rebase contains new hardware support, features, and a number of important bug fixes across the tree. —- Update to v5.1.12

The 5.2.7 stable kernel update contains a number of important fixes across the tree. —- The 5.2.6 kernel rebase contains new hardware support, features, and a number of important bug fixes across the tree. —- Update to v5.1.12

The 5.2.7 stable kernel update contains a number of important fixes across the tree. —- The 5.2.6 kernel rebase contains new hardware support, features, and a number of important bug fixes across the tree. —- Update to v5.1.12

Patches for CVE-2019-14295, CVE-2019-14296

July CPU update. See: http://openjdk.java.net/groups/vulnerability/advisories/2019-07-16 and http://mail.openjdk.java.net/pipermail/jdk8u-dev/2019-July/009840.html

fixed CVEs 2019-10181, 2019-10182, 2019-10185 —- Updated to fres upstream release: https://mail.openjdk.java.net/pipermail/distro-pkg- dev/2019-March/041320.html New in release 1.8 (2019-03-12): * added support for javafx-desc and so allwong run of pure-javafx only applications * –nosecurity enhanced for possibility to skip invalid signatures * enhanced to allow

The 5.2.7 stable update contains a number of important fixes across the tree.

The 5.2.7 stable update contains a number of important fixes across the tree.

The 5.2.7 stable update contains a number of important fixes across the tree.

Security fix for CVE-2019-14378

Patches for CVE-2019-14295, CVE-2019-14296

security update

Multiple vulnerabilities have been found in LibVNCServer, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been found in Redis, the worst of which may allow execution of arbitrary code.

Multiple vulnerabilities have been found in JasPer, the worst of which could result in a Denial of Service condition.

Updated cyrus-imapd package fixes security vulnerability: It was discovered that cyrus-imapd had a buffer overflow in CalDAV request handling triggered by a long iCalendar property name (CVE-2019-11356).

Updated php packages fixes atleast the following security issues: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with

security update

security update

An update that fixes 7 vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Dominik Penner discovered that KConfig, the KDE configuration settings framework, supported a feature to define shell command execution in .desktop files. If a user is provided with a malformed .desktop file (e.g. if it’s embedded into a downloaded archive and it gets opened in

Transport Layer Security version 1.3 in Red Hat Enterprise Linux 8

An update that fixes two vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

* CVE-2019-10208: `TYPE` in `pg_temp` executes arbitrary SQL during `SECURITY DEFINER` execution Versions Affected: 9.4 – 11