Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Several security vulnerabilities were discovered in Zabbix, a server/client network monitoring solution. CVE-2016-10742

The package pacman before version 5.1.3-1 is vulnerable to arbitrary code execution.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0462

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

poppler could be made to crash if it opened a specially craftedfile.

Why Your Email Security Solution May Not Be Enough

A vulnerability in GNU Wget which could allow an attacker to obtain sensitive information.

Multiple vulnerabilities have been found in systemd, the worst of which may allow execution of arbitrary code.

Multiple vulnerabilities have been discovered in rdesktop, the worst of which could result in the remote execution of arbitrary code.

security update

A vulnerability in Tar could led to a Denial of Service condition.

Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

Multiple vulnerabilities have been found in cURL, the worst of which could result in a Denial of Service condition.

Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec, that could be leveraged to cause a denial of service or possibly remote code execution.

Clement Lecigne discovered a use-after-free issue in chromium’s file reader implementation. A maliciously crafted file could be used to remotely execute arbitrary code because of this problem.

Input validation errors in Zsh could result in arbitrary code execution.

Multiple vulnerabilities have been found in Keepalived, the worst of which could allow an attacker to cause Denial of Service condition.

Several security vulnerabilities have been discovered in symfony, a PHP web application framework. Numerous symfony components are affected: Security, bundle readers, session handling, SecurityBundle,

security update

An update that fixes one vulnerability is now available.

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF extension had multiple cases of invalid memory access and rename() was implemented insecurely.

Security fix for CVE-2018-15587

An update that solves one vulnerability and has 5 fixes is now available.

An update that fixes two vulnerabilities is now available.

New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

An update that solves 5 vulnerabilities and has 6 fixes is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0230

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 15 vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –

## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –

A flaw was found in Nagios Core version 4.4.1 and earlier. The qh_help function is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket (CVE-2018-13441).

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. […]

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a […]

When symmetric encryption is used, data can be injected through the passphrase property of the gnupg.GPG.encrypt() and gnupg.GPG.decrypt() methods. The supplied passphrase is not validated for newlines, and the library passes –passphrase-fd=0 to the gpg executable, which expects the passphrase on the first line of stdin, and the ciphertext to be decrypted

NVIDIA graphics drivers could be made to expose sensitive information.

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update that solves two vulnerabilities and has one errata is now available.

An update that solves four vulnerabilities and has four fixes is now available.

An update that solves one vulnerability and has one errata is now available.

security update

Several security issues were fixed in PHP.

– https://www.drupal.org/project/link/releases/7.x-1.6 – https://www.drupal.org/sa-contrib-2019-020 – https://www.drupal.org/sa- core-2019-003 – https://www.drupal.org/project/link/releases/7.x-1.5 – https://www.drupal.org/project/link/releases/7.x-1.5-beta3

## 1.7.1 – #475: “Loose” lists will now contain paragraphs in all items, not just some. – #433: Links will no longer be double nested – #525: The info- string when beginning a code block may now contain non-word characters (e.g. `c++`) – #561: The `mbstring` extension (which we already depend on) has been added […]

Fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165.

– bugfix {foreach} using new style property access like {$item@property} on Smarty 2 style named foreach loop could produce errors https://github.com/smarty-php/smarty/issues/484 31.08.2018 – bugfix some custom left and right delimiters like ‘{^’ ‘^}’ did not work

Bump to ignition-dracut 2c69925 * support platform configs and user configs in /boot ^ https://github.com/coreos/ignition-dracut/pull/43 * Add ability to parse config.ign file on boot ^ https://github.com/coreos/ignition-dracut/pull/42

You’ve Invested in an Email Security Solution… Why your Email may be in Danger, Regardless
Linux and Open Source FAQs: Common Myths and Misconceptions Addressed
New & Improved LinuxSecurity Site Coming Soon!
As Trump and Kim Met, North Korean Hackers Hit Over 100 Targets in U.S. and Ally Nations
Hackers have started attacks on Cisco RV110, RV130, and RV215 routers
Revealed: Facebooks global lobbying against data privacy laws

LinuxSecurity.com: An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for vdsm is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Vulnerabilities have been discovered in nss, the Mozilla Network Security Service library.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: One of the fixes in USN-3885-1 was incomplete.

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 5.0 for RHEL 6 and Red Hat JBoss Web Server 5.0 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: This is the six-month notification for the retirement of Red Hat Enterprise Linux 7.4 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.4.

LinuxSecurity.com: The package lib32-openssl-1.0 before version 1.0.2.r-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package file before version 5.36-1 is vulnerable to multiple issues including information disclosure and denial of service.

LinuxSecurity.com: The package pcre before version 8.43-1 is vulnerable to denial of service.

LinuxSecurity.com: The package gdm before version 3.30.3-1 is vulnerable to access restriction bypass.

LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.r-1 is vulnerable to information disclosure.

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: The package chromium before version 72.0.3626.121-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: Update to 4.01. Fixes lots of security bugs (and non-security bugs).

LinuxSecurity.com: It was found that a security update (DSA-4387-1) of OpenSSH, an implementation of the SSH protocol suite, was incomplete. This update did not completely fix CVE-2019-6111, an arbitrary file overwrite vulnerability in the scp client implementing the SCP protocol.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: gdm 3.30.3 release. – Screen lock bypass fix (when timed login is enabled) (CVE-2019-3825) – Translation updates

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: FreeRDP fix for CVE-2018-1000852, Remmina bugfix update and rebuilds for updated FreeRDP.

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: Restrict default configuration to localhost.

LinuxSecurity.com: This release fixes various buffer overflows when parsing or processing damaged Waveform audio and BMP image files.

LinuxSecurity.com: fix for CVE-2018-5704 (RHBZ 1534844)

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

security update

security update

security update

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is now available.