LinuxSecurity.com: Git could be made to run programs as your login if it recursivelyopened a malicious git repository.
LinuxSecurity.com: An update for spamassassin is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: Magnus Klaaborg Stubman discovered a NULL pointer dereference bug in net-snmp, a suite of Simple Network Management Protocol applications, allowing a remote, authenticated attacker to crash the snmpd process (causing a denial of service).
LinuxSecurity.com: Several security issues were fixed in Tex Live.
LinuxSecurity.com: An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: dnsruby is a feature-complete DNS(SEC) client for Ruby. It ships the DNS Root Key Signing Key (KSK), used as trust anchor to validate the authenticity of DNS records. This update includes the latest KSK
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: Ben Pfaff discovered that the convert_to_decimal function in the GNU Portability Library contains a heap-based buffer overflow because memory is not allocated for a trailing ‘’ character during %f processing.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2884
LinuxSecurity.com: An update for glusterfs is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: The package patch before version 2.7.6-3 is vulnerable to multiple issues including arbitrary command execution and denial of service.
LinuxSecurity.com: Updates for rh-dotnetcore11-dotnetcore, and rh-dotnetcore10-dotnetcore are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
security update
security update
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2846
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2898
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2892
LinuxSecurity.com: Several security issues were fixed in the kernel.
LinuxSecurity.com: Several vulnerabilities were discovered in tinc, a Virtual Private Network (VPN) daemon. The Common Vulnerabilities and Exposures project identifies the following problems:
LinuxSecurity.com: Several security issues were fixed in libxkbcommon.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2881
LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:
LinuxSecurity.com: Several vulnerabilities were discovered in tinc, a Virtual Private Network (VPN) daemon. The Common Vulnerabilities and Exposures project identifies the following problems:
LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for rh-haproxy18-haproxy is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: Due to multiple vulnerabilities in various coders used by ImageMagick, Gentoo Linux now installs a policy.xml file which will restrict coder usage by default. [More…]
LinuxSecurity.com: A vulnerability in OpenSSH might allow remote attackers to determine valid usernames.
LinuxSecurity.com: Multiple vulnerabilities have been found in SoX, the worst of which may lead to a Denial of Service condition.
LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 20 vulnerabilities is now available.
security update
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.
LinuxSecurity.com: joernchen of Phenoelit discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability via a specially crafted .gitmodules file in a project cloned with –recurse-submodules.
LinuxSecurity.com: joernchen of Phenoelit discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability via a specially crafted .gitmodules file in a project cloned with –recurse-submodules.
LinuxSecurity.com: Security fix for CVE-2018-17336
LinuxSecurity.com: Security fix for CVE-2018-16435
LinuxSecurity.com: Security fix for CVE-2018-10897
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.
LinuxSecurity.com: An update that fixes 10 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: Use a more restrictive blacklist in several policy abstractions.
LinuxSecurity.com: Several security issues were fixed in ImageMagick.
security update
LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: dnsmasq, a DNS forwarder and DHCP server, ships the DNS Root Zone Key Signing Key (KSK), used as the DNSSEC trust anchor. ICANN will rollover the KSK in 11 October 2018, and DNS resolvers will need the new key
LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
LinuxSecurity.com: The package python-django before version 2.1.2-1 is vulnerable to information disclosure.
LinuxSecurity.com: Several security issues were fixed in the Apache HTTP Server.
LinuxSecurity.com: Two security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code inside the sandboxed content process.
LinuxSecurity.com: Several security vulnerabilities were discovered in ImageMagick, an image manipulation program, that allow remote attackers to cause denial of service (application crash, excessive memory allocation, or other
LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Several security issues were fixed in Liblouis.
LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.
LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix a security issue.
LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.
security update
LinuxSecurity.com: – Update to bind-9.11.4-P2 – Add /dev/urandom to chroot (#1631515) – Fix multilib conflicts of devel package – Add support for OpenSSL provided random data
LinuxSecurity.com: This is an update to Mozilla’s CA certificates list version 2.26, which has been published as part of Mozilla NSS 3.39. For additional details, please refer to the NSS 3.39 release notes: https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes
LinuxSecurity.com: Security fix for CVE-2018-17294
LinuxSecurity.com: Add few patches from Kurt Roeckx
LinuxSecurity.com: Update to 1.8.14, which includes fix for CVE-2018-14645.
LinuxSecurity.com: 4.1.5 GA —- 4.1.4 GA Security Fix for CVE-2018-10904 Security Fix for CVE-2018-10907 Security Fix for CVE-2018-10911 Security Fix for CVE-2018-10913 Security Fix for CVE-2018-10914 Security Fix for CVE-2018-10923 Security Fix for CVE-2018-10926 Security Fix for CVE-2018-10927 Security Fix for CVE-2018-10928 Security Fix for CVE-2018-10929 Security Fix for CVE-2018-10930 —- missing
LinuxSecurity.com: An update that solves 5 vulnerabilities and has four fixes is now available.
LinuxSecurity.com: The package lib32-libxml2 before version 2.9.8-4 is vulnerable to denial of service.
LinuxSecurity.com: The package libxml2 before version 2.9.8-5 is vulnerable to denial of service.
LinuxSecurity.com: The package libxml2 before version 2.9.8-5 is vulnerable to denial of service.
LinuxSecurity.com: The package ntp before version 4.2.8.p12-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
