security update
security update
LinuxSecurity.com: – update to 2.56.x
LinuxSecurity.com: – update to 2.56.x
LinuxSecurity.com: rebase to 8.37.0 ———————- – few fixes and enhancements handling journal input – now requires librelp at least 1.2.16, adding support for setting address to bind – various other rsyslog core bugfixes and stability fixes
LinuxSecurity.com: New upstream version 0.7alpha. Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks
LinuxSecurity.com: New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: Two vulnerabilities have been found in the PostgreSQL database system: CVE-2018-10915
LinuxSecurity.com: It was discovered that the PatternSyntaxException class in the Concurrency component of OpenJDK, an implementation of the Oracle Java platform could result in denial of service via excessive memory consumption.
LinuxSecurity.com: Various vulnerabilities leading to denial of service or possible unspecified other impacts were discovered in sam2p, an utility to convert raster images to EPS, PDF, and other formats.
LinuxSecurity.com: Several security issues were fixed in the kernel.
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: Java applications could be made to use excessive memory.
LinuxSecurity.com: Java applications could be made to use excessive memory.
security update
LinuxSecurity.com: The following vulnerability was discovered in wpa_supplicant. CVE-2018-14526: | An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: The package linux-hardened before version 4.17.11.a-1 is vulnerable to denial of service.
LinuxSecurity.com: The package linux-zen before version 4.17.11-1 is vulnerable to denial of service.
LinuxSecurity.com: The package linux before version 4.17.11-1 is vulnerable to denial of service.
LinuxSecurity.com: The package linux-lts before version 4.14.59-1 is vulnerable to denial of service.
LinuxSecurity.com: Henning Westerholt discovered a flaw related to the To header processing in kamailio, a very fast, dynamic and configurable SIP server. Missing input validation in the build_res_buf_from_sip_req function could result in denial of service and potentially the execution of arbitrary code.
LinuxSecurity.com: New upstream version 0.7alpha. Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks
LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: The security update for slurm-llnl introduced a regression in the fix for CVE-2018-10995 which broke accounting. For Debian 8 “Jessie”, this problem has been fixed in version
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves 5 vulnerabilities and has two fixes is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
security update
LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: It was discovered that there were several vulnerabilities in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious .CAB, .CHM or .KWAJ files
LinuxSecurity.com: It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.
LinuxSecurity.com: It was discovered that there was a directory traversal vulnerability in cgit, a web frontend for Git repositories. For Debian 8 “Jessie”, this issue has been fixed in cgit version
LinuxSecurity.com: An update for openslp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update for rhvm-setup-plugins is now available for Red Hat Virtualization Engine 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: The fix for CVE-2018-10886 was incomplete in the previous upload. New changes was implemented upstream which check and resolve symlinks before expanding the archives.
LinuxSecurity.com: It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.
LinuxSecurity.com: Andreas Hug discovered an open redirect in Django, a Python web development framework, which is exploitable if django.middleware.common.CommonMiddleware is used and the APPEND_SLASH setting is enabled.
security update
security update
LinuxSecurity.com: Update to 3.2.1 (CVE-2017-12627)
LinuxSecurity.com: Update to 3.2.1 (CVE-2017-12627)
LinuxSecurity.com: Backport fix for CVE 2017-11548
security update
LinuxSecurity.com: The package python2-django before version 1.11.15-1 is vulnerable to open redirect.
LinuxSecurity.com: The package cgit before version 1.2.1-1 is vulnerable to directory traversal.
LinuxSecurity.com: Jann Horn discovered a directory traversal vulnerability in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of this flaw to retrieve arbitrary files via a specially crafted request, when ‘enable-http-clone=1’ (default) is not turned off.
security update
LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 10 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: The 4.17.11 stable update contains a number of important fixes across the tree. Also of note, starting with this release, kernel-headers is built from a different srpm. The contents should be the same, but there were some benefits to breaking it from the kernel build. —- The 4.17.10 stable kernel update contains a number […]
LinuxSecurity.com: Sync with git (CVE-2017-14160, CVE-2018-10392, CVE-2018-10393, bz#1516379)
LinuxSecurity.com: Update Python 2 dependency declarations to new packaging standards
security update
LinuxSecurity.com: Update Python 2 dependency declarations to new packaging standards
LinuxSecurity.com: The 4.17.11 stable update contains a number of important fixes across the tree. Also of note, starting with this release, kernel-headers is built from a different srpm. The contents should be the same, but there were some benefits to breaking it from the kernel build. —- The 4.17.10 stable kernel update contains a number […]
LinuxSecurity.com: Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to open redirects, cross-site request forgery, information disclosure, session fixation or denial of service.
LinuxSecurity.com: Enrico Zini discovered a vulnerability in Syntastic, an addon module for the Vim editor that runs a file through external checkers and displays any resulting errors. Config files were looked up in the current working directory which could result in arbitrary
LinuxSecurity.com: Update to 2.26, fixes CVE-2018-9275
LinuxSecurity.com: Update to 2.26, fixes CVE-2018-9275
LinuxSecurity.com: Several security issues were fixed in ClamAV.
LinuxSecurity.com: It was found that the security update of busybox announced as DLA-1445-1 to prevent the exploitation of CVE-2011-5325, a symlinking attack, was too strict in case of cpio archives. This update restores the old behavior.
LinuxSecurity.com: Various vulnerabilities were discovered in graphicsmagick, a collection of image processing tools and associated libraries, resulting in denial of service, information disclosure, and a variety of buffer overflows and overreads.
security update
LinuxSecurity.com: New lftp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.
LinuxSecurity.com: Several vulnerabilities were discovered in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious CAB, CHM or KWAJ files and use these flaws to cause a denial of service via application crash, or potentially execute arbitrary code.
LinuxSecurity.com: openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution (CVE-2017-17833) SL6 x86_64 openslp-2.0.0-3.el6.i686.rpm openslp-2.0.0-3.el6.x86_64.rpm openslp-debuginfo-2.0.0-3.el6.i686.rpm openslp-debuginfo-2.0.0-3.el6.x86_64.rpm openslp-devel-2.0.0-3.el6.i686.rpm openslp-devel-2.0.0-3.el6.x86_64.rpm openslp-server- [More…]
LinuxSecurity.com: New version 2.6.2. Security fix for CVE-2018-14339, CVE-2018-14340, CVE-2018-14341, CVE-2018-14342, CVE-2018-14343, CVE-2018-14344, CVE-2018-14367, CVE-2018-14368, CVE-2018-14369, CVE-2018-14370.
LinuxSecurity.com: Update to 6.6. —- Version 6.5 – address CVE-2018-10773, CVE-2018-10774, CVE-2018-10775 – fix injection of Fedora LDFLAGS
