LinuxSecurity.com: Updated openssl packages fix security vulnerabilities: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a
LinuxSecurity.com: Updated java-1.8.0-openjdk packages fixes atleast the following security vulnerability: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (CVE-2018-2952)
LinuxSecurity.com: The updated packages fix security vulnerabilities: gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a
LinuxSecurity.com: Two security issues have been discovered in the Tomcat servlet and JSP engine. CVE-2018-1336
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
security update
security update
LinuxSecurity.com: Two vulnerabilities have been discovered in php5, a server-side, HTML-embedded scripting language. One (CVE-2018-14851) results in a potential denial of service (out-of-bounds read and application crash)
LinuxSecurity.com: A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or,
LinuxSecurity.com: This update provides mercurial version 4.6.2 and fixes the following security issues: Fix the mpatch_apply function in mpatch.c that incorrectly proceeds in cases where the fragment start is past the end of the original data
LinuxSecurity.com: The updated packages fix a security vulnerability: Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial
LinuxSecurity.com: The updated packages fix security vulnerabilities: An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to
LinuxSecurity.com: This update provides libraw 0.18.13 fixing atleast the following security issues: LibRaw versions prior to 0.18.12 are vulnerable to an integer overflow in the internal/dcraw_common.cpp:parse_qt() function. An attacker could
LinuxSecurity.com: Updated mariadb packages fix security vulnerabilities: Vulnerability in the MariaDB Server component of MariaDB (subcomponent: MyISAM). Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MariaDB Server.
LinuxSecurity.com: Updated quazip packages fix security vulnerability: A vulnerability has been found in the way developers have implemented the archive extraction of files. An arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other
LinuxSecurity.com: This update provides the virtualbox 5.1.18 maintenance release that fixes atleast the following security issues: Fixed an easily exploitable vulnerability that allowed unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox
LinuxSecurity.com: OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c (CVE-2018-15473).
LinuxSecurity.com: Updated libxcursor packages fix security vulnerability _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. (CVE-2015-9262)
LinuxSecurity.com: Updated squirrelmail packages fix XSS-security vulnerability: It was discovered that some special tags have not been filtered accordingly which can be used for an XSS-attack.
LinuxSecurity.com: It was discovered that there were a number of Cross Site Scripting (XSS) vulnerabilities in the squirrelmail webmail client. For Debian 8 “Jessie”, these issues has been fixed in squirrelmail
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: CVE-2018-5740 The “deny-answer-aliases” feature in BIND has a flaw which can cause named to exit with an assertion failure.
LinuxSecurity.com: CVE-2018-10871 By default nsslapd-unhashed-pw-switch was set to ‘on’. So a copy of
LinuxSecurity.com: Several security issues were fixed in libx11.
LinuxSecurity.com: Several security issues were fixed in libx11.
LinuxSecurity.com: An update for OpenDaylight is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for ansible is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: poppler could be made to crash if it received specially crafted PDF file.
LinuxSecurity.com: Several issues were discovered in libx11, the client interface to the X Windows System. The functions XGetFontPath, XListExtensions, and XListFonts are vulnerable to an off-by-one override on malicious server responses. A malicious server could also send a reply in which
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2570
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2557
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2571
LinuxSecurity.com: Several issues were discovered in the Tomcat servlet and JSP engine. They could lead to unauthorized access to protected resources, denial-of-service, or information leak.
security update
LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate security issues.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read
LinuxSecurity.com: bind: processing of certain records when “deny-answer-aliases” is in use may trigger an assert leading to a denial of service (CVE-2018-5740) SL6 x86_64 bind-debuginfo-9.8.2-0.68.rc1.el6_10.1.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.1.x86_64.rpm bind-libs-9.8.2-0.68.rc1.el6_10.1.i686.rpm bind-libs-9.8.2-0.68.rc1.el6_10.1.x86_64.rpm bind-utils-9.8.2-0.68.rc1.el6_10.1 [More…]
LinuxSecurity.com: bind: processing of certain records when “deny-answer-aliases” is in use may trigger an assert leading to a denial of service (CVE-2018-5740) SL7 x86_64 bind-debuginfo-9.9.4-61.el7_5.1.i686.rpm bind-debuginfo-9.9.4-61.el7_5.1.x86_64.rpm bind-libs-9.9.4-61.el7_5.1.i686.rpm bind-libs-9.9.4-61.el7_5.1.x86_64.rpm bind-libs-lite-9.9.4-61.el7_5.1.i686.rpm bind-libs-lite-9. [More…]
LinuxSecurity.com: Several security issues were fixed in GD.
LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.
LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.
LinuxSecurity.com: An update that solves one vulnerability and has 10 fixes is now available.
LinuxSecurity.com: Several vulnerabilities were discovered in Ruby 2.1. CVE-2016-2337
LinuxSecurity.com: The Bootstrap framework was found to have cross-site scripting vulnerabilities in the “collapse” plugin. For Debian 8 “Jessie”, this problem has been fixed in version
LinuxSecurity.com: The system could be made to expose sensitive information.
LinuxSecurity.com: An update for rh-postgresql96-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 31 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: CVE-2018-15501 A potential out-of-bounds read when processing a “ng” smart packet might lead to a Denial of Service.
LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: Spice could be made to crash if it received specially crafted network traffic.
LinuxSecurity.com: postgresql: Certain host connection parameters defeat client-side security defenses (CVE-2018-10915) SL7 x86_64 postgresql-debuginfo-9.2.24-1.el7_5.i686.rpm postgresql-debuginfo-9.2.24-1.el7_5.x86_64.rpm postgresql-libs-9.2.24-1.el7_5.i686.rpm postgresql-libs-9.2.24-1.el7_5.x86_64.rpm postgresql-9.2.24-1.el7_5.i686.rpm postgresql-9.2.24-1.el7_5.x86_64.rpm postgre [More…]
LinuxSecurity.com: An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
security update
LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Pango could be made to crash if it opened a specially crafted file.
LinuxSecurity.com: Several security issues were fixed in Spidermonkey.
LinuxSecurity.com: An update that solves two vulnerabilities and has 21 fixes is now available.
