LinuxSecurity.com: Update to 6.6. —- Version 6.5 – address CVE-2018-10773, CVE-2018-10774, CVE-2018-10775 – fix injection of Fedora LDFLAGS
LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.
LinuxSecurity.com: Several security issues were fixed in ClamAV.
LinuxSecurity.com: Several vulnerabilities have been discovered in mutt, a sophisticated text-based Mail User Agent, resulting in denial of service, stack-based buffer overflow, arbitrary command execution, and directory traversal
LinuxSecurity.com: The security update of busybox announced as DLA-1445-1 introduced a regression due to an incomplete fix for CVE-2015-9261. It was no longer possible to decompress gzip archives which exceeded a certain file size.
LinuxSecurity.com: New blueman packages are available for Slackware 14.2 and -current to fix a security issue.
security update
LinuxSecurity.com: Several security issues were fixed in libmspack.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA
LinuxSecurity.com: Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA
LinuxSecurity.com: # New upstream release 2.3 Fixes possible tag truncation security bug in AEAD API, see RHBZ#1602752 ## 2.3 – 2018-07-18 * SECURITY ISSUE: finalize_with_tag() allowed tag truncation by default which can allow tag forgery in some cases. The method now enforces the min_tag_length provided to the GCM constructor. * Added support for Python 3.7. […]
LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in incorrect processing of HTTP/FTP, directory traversal, command injection, unintended socket creation or information disclosure.
LinuxSecurity.com: Update zziplib to 0.13.69 version, fixes all known CVEs for the package.
LinuxSecurity.com: Security fix for CVE-2018-13988.
LinuxSecurity.com: Denis Andzakovic discovered that network-manager-vpnc, a plugin to provide VPNC support for NetworkManager, is prone to a privilege escalation vulnerability. A newline character can be used to inject a
LinuxSecurity.com: New seamonkey packages are available for Slackware 14.2 and -current to fix security issues.
LinuxSecurity.com: New file packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
security update
LinuxSecurity.com: Several security issues were fixed in MySQL.
LinuxSecurity.com: yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) SL6 noarch yum-plugin-aliases-1.1.30-42.el6_10.noarch.rpm yum-plugin-changelog-1.1.30-42.el6_10.noarch.rpm yum-plugin-ovl-1.1.30-42.el6_10.noarch.rpm yum-plugin-security-1.1.30-42.el6_10.noarch.rpm yum-plugin-tmprepo-1.1.30-42.el6_10.noarch.rpm yum-plugin-verify-1.1.30-42.e [More…]
LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL6 x86_64 java-1.7.0-openjdk-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm java-1.7.0-openjdk-debuginfo-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm java-1.7.0-openjdk-devel-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm java-1.7.0-openjdk-demo-1.7.0.191-2.6.15.4.el6_10.x86_64.rpm [More…]
LinuxSecurity.com: yum-utils: reposync: improper path validation may lead to directory traversal (CVE-2018-10897) SL7 noarch yum-plugin-aliases-1.1.31-46.el7_5.noarch.rpm yum-plugin-changelog-1.1.31-46.el7_5.noarch.rpm yum-plugin-ovl-1.1.31-46.el7_5.noarch.rpm yum-plugin-tmprepo-1.1.31-46.el7_5.noarch.rpm yum-plugin-verify-1.1.31-46.el7_5.noarch.rpm yum-plugin-versionlock-1.1.31-46.el7 [More…]
LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL7 x86_64 java-1.7.0-openjdk-1.7.0.191-2.6.15.4.el7_5.x86_64.rpm java-1.7.0-openjdk-debuginfo-1.7.0.191-2.6.15.4.el7_5.x86_64.rpm java-1.7.0-openjdk-headless-1.7.0.191-2.6.15.4.el7_5.x86_64.rpm java-1.7.0-openjdk-accessibility-1.7.0.191-2.6.15.4.el7_5.x86_64. [More…]
LinuxSecurity.com: CVE-2018-14339 CVE-2018-14340 CVE-2018-14341
LinuxSecurity.com: The host name verification in Tomcat when using TLS with the WebSocket client was missing. It is now enabled by default. For Debian 8 “Jessie”, this problem has been fixed in version
LinuxSecurity.com: Two vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following issues.
LinuxSecurity.com: Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.
LinuxSecurity.com: A heap-based buffer overflow in cURL might allow remote attackers to execute arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in ZNC, the worst of which could result in privilege escalation.
LinuxSecurity.com: Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine.
LinuxSecurity.com: Fixes **CVE-2017-11332**, **CVE-2017-11358**, and **CVE-2017-11359**. —- **Prevents division by zero in `src/ao.c`** This bug is hard to reproduce, depending on the HW configuration or installed OS parts. For me, it can be reproduced only in `mock`. In this update, error message should be displayed instead of SIGFPE.
LinuxSecurity.com: Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA
LinuxSecurity.com: upstream security fix release
LinuxSecurity.com: **PHP version 7.2.8** (19 Jul 2018) **Core:** * Fixed bug php#76534 (PHP hangs on ‘illegal string offset on string references with an error handler). (Laruence) * Fixed bug php#76520 (Object creation leaks memory when executed over HTTP). (Nikita) * Fixed bug php#76502 (Chain of mixed exceptions and errors does not serialize properly). (Nikita) **Date:** […]
LinuxSecurity.com: It was discovered that there was a denial of service vulnerability in policykit-1, a framework for managing administrative policies and privileges.
LinuxSecurity.com: The package libextractor before version 1.7-1 is vulnerable to denial of service.
LinuxSecurity.com: The package wesnoth before version 1.14.4-1 is vulnerable to arbitrary code execution.
security update
LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to fix security issues.
security update
LinuxSecurity.com: The fix for arbitrary code execution documented in CVE-2017-17458 was incomplete in the previous upload. A more exhaustive change was implemented upstream and completely disables non-Mercurial subrepositories unless users changed the subrepos.allowed setting.
LinuxSecurity.com: USN-3722-1 introduced a regression in ClamAV.
LinuxSecurity.com: A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: The security update of mailman announced as DLA-1442-1 introduced a regression due to an incomplete fix for CVE-2018-13796 that broke the admin and listinfo overview pages.
LinuxSecurity.com: Security researchers identified two software analysis methods that, if used for malicious purposes, have the potential to improperly gather sensitive data from multiple types of computing devices with different vendors’ processors and operating systems.
LinuxSecurity.com: Busybox, utility programs for small and embedded systems, was affected by several security vulnerabilities. The Common Vulnerabilities and Exposures project identifies the following issues.
LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-4117
LinuxSecurity.com: CVE-2018-11319 The improper handling of search for configuration files might be exploited for arbitrary code execution via a malicious gcc plugin.
LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2241
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2252
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2242
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2240
LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: The package jenkins before version 2.133-1 is vulnerable to multiple issues including access restriction bypass, arbitrary filesystem access, cross-site scripting and information disclosure.
security update
security update
LinuxSecurity.com: This update includes the latest upstream release, **httpd 2.4.34**, with multiple bug fixes and enhancements. See http://www.apache.org/dist/httpd/CHANGES_2.4.34 for more information on the changes in this version. A security vulnerability is addressed in this update: * `mod_md`: DoS via Coredumps on specially crafted requests (CVE-2018-8011)
LinuxSecurity.com: New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2251
LinuxSecurity.com: A vulnerability has been discovered in Sympa, a modern mailing list manager, that allows write access to files on the server filesystem. This flaw allows to create or modify any file writable by the Sympa user, located on the server filesystem, using the function of Sympa
LinuxSecurity.com: The libarchive-zip-perl package is vulnerable to a directory traversal attack in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use
LinuxSecurity.com: CVE-2018-12584 A flaw in function ConnectionBase::preparseNewBytes of resip/stack/ConnectionBase.cxx has been detected, that
LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
security update
LinuxSecurity.com: Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rhev-hypervisor7 is now available for RHEV 3.X Hypervisor and Agents for Red Hat Enterprise Linux 6 and RHEV 3.X Hypervisor and Agents Extended Lifecycle Support for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update for rh-ror50-rubygem-sprockets is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
