security update
LinuxSecurity.com: A remote code execution vulnerability exists in PHP’s built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being
LinuxSecurity.com: Bug fixes for binutils including one that is preventing Yocot/oe-core from building properly
LinuxSecurity.com: New mariadb packages are available for Slackware 14.1 and 14.2 to fix security issues.
LinuxSecurity.com: Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.38. Please see the MariaDB 10.0 Release Notes for further details:
LinuxSecurity.com: The 4.20.5 stable kernel update contains a number of important fixes across the tree.
security update
security update
security update
LinuxSecurity.com: Several security issues were fixed in Avahi.
LinuxSecurity.com: The package ghostscript before version 9.26-2 is vulnerable to sandbox escape.
security update
LinuxSecurity.com: New mozilla-firefox packages are available for 14.2 and -current to fix security issues.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
LinuxSecurity.com: Security fix for CVE-2019-6706.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several issues in wireshark, a network traffic analyzer, have been found. Dissectors of – ISAKMP, a Internet Security Association and Key Management Protocol
LinuxSecurity.com: Several issues were discovered in qtbase-opensource-src, a cross-platform C++ application framework, which could lead to denial-of-service via application crash. Additionally, this update fixes a problem affecting vlc, where it would start without a GUI.
LinuxSecurity.com: Multiple vulnerabilities were discovered in coTURN, a TURN and STUN server for VoIP. CVE-2018-4056
security update
security update
LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).
LinuxSecurity.com: The package nasm before version 2.14.02-1 is vulnerable to denial of service.
LinuxSecurity.com: The package haproxy before version 1.9.0-1 is vulnerable to denial of service.
LinuxSecurity.com: The package matrix-synapse before version 0.34.1.1-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package powerdns-recursor before version 4.1.9-1 is vulnerable to multiple issues including insufficient validation and access restriction bypass.
LinuxSecurity.com: The package apache before version 2.4.38-1 is vulnerable to multiple issues including denial of service and insufficient validation.
LinuxSecurity.com: The package go before version 2:1.11.5-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package go before version 2:1.11.5-1 is vulnerable to private key recovery.
LinuxSecurity.com: New version 2.6.6. Security fix for CVE-2019-5716, CVE-2019-5717, CVE-2019-5718, CVE-2019-5719
security update
LinuxSecurity.com: krb5, a MIT Kerberos implementation, had several flaws in LDAP DN checking, which could be used to circumvent a DN containership check by supplying special parameters to some calls.
LinuxSecurity.com: The PostgreSQL project has release a new minor release of the 9.4 branch. For Debian 8 “Jessie”, this has been uploaded as version
LinuxSecurity.com: New Version
LinuxSecurity.com: Ghostscript could be made to crash, access files, or run programs if it opened a specially crafted file.
LinuxSecurity.com: Several security issues were fixed in MySQL.
LinuxSecurity.com: A vulnerability in the HTML_QuickForm package has been found which potentially allows remote code execution. References: – https://bugs.mageia.org/show_bug.cgi?id=24185
LinuxSecurity.com: It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service (CVE-2018-20544). It was discovered that libcaca incorrectly handled certain images. An
LinuxSecurity.com: An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806).
LinuxSecurity.com: Security fix for CVE-2018-20551, CVE-2018-20481, CVE-2018-20650 and CVE-2018-18897.
LinuxSecurity.com: Security fix for CVE-2019-5010 in Python. Anaconda is joined because an unrelated fix was done there that allowed to remove a workaround in Python.
LinuxSecurity.com: – xattr: strip credentials from any URL that is stored (CVE-2018-20483)
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: Multiple vulnerabilities were found in the journald component of systemd which can lead to a crash or code execution. CVE-2018-16864
LinuxSecurity.com: Fix for CVE-2019-5885 Upgrade notes available at https://github.com/matrix- org/synapse/blob/v0.34.0/UPGRADE.rst#upgrading-to-v0340 – Note this continues to use Python 2.
LinuxSecurity.com: Several vulnerabilities have been resolved in libjpeg-turbo, Debian’s default JPEG implemenation. CVE-2016-3616
LinuxSecurity.com: It was discovered that aria2 (the lightweight command-line download utility) can store passed user credentials in a log file when using the –log option. This might allow local users to obtain sensitive information by reading this file.
security update
LinuxSecurity.com: admin: Prevent access if any authentication agent isn’t available
LinuxSecurity.com: Fix for use after free in affile_dw_reap
LinuxSecurity.com: libssh versions 0.6 and above have an authentication bypass vulnerability in the server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS message in place of the SSH2_MSG_USERAUTH_REQUEST message which the server would expect to initiate authentication, the attacker could successfully authentciate
LinuxSecurity.com: Security fix for CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 through rebase to 3.2.0
LinuxSecurity.com: **PHP version 7.2.14** (10 Jan 2019) **Core:** * Fixed bug php#77369 (memcpy with negative length via crafted DNS response). (Stas) * Fixed bug php#71041 (zend_signal_startup() needs ZEND_API). (Valentin V. Bartenev) * Fixed bug php#76046 (PHP generates “FE_FREE” opcode on the wrong line). (Nikita) **Date:** * Fixed bug php#77097 (DateTime::diff gives wrong diff when the
security update
LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.
LinuxSecurity.com: Several security issues were fixed in libcaca.
LinuxSecurity.com: This update fixes CVE-2018-20685 (the first “variant”) and backports several fixes to unbreak ECDSA authentication from PKCS#11, certificate authentication and so on.
LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).
LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).
LinuxSecurity.com: Patch for CVE-2016-10091
LinuxSecurity.com: It was observed that URL’s which gets downloaded via “–log=” attribute stores sensitive information. This update fixes that. References: – https://bugs.mageia.org/show_bug.cgi?id=24112
LinuxSecurity.com: A heap use-after-free vulnerability in the server code of the file transfer extension, which can result in remote code execution. This attack appears to be exploitable via network connectivity (CVE-2018-6307).
LinuxSecurity.com: Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys (CVE-2018-0495). References:
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
security update
security update
LinuxSecurity.com: Several issues in wireshark, a tool that captures and analyzes packets off the wire, have been found by different people. These are basically issues with length checks or invalid memory access in
LinuxSecurity.com: libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) SL7 x86_64 libvncserver-0.9.9-13.el7_6.i686.rpm libvncserver-0.9.9-13.el7_6.x86_64.rpm libvncserver-debuginfo-0.9.9-13.el7_6.i686.rpm libvncserver-debuginfo-0.9.9-13.el7_6.x86_64.rpm libvncserver-devel-0.9.9-13.el7_6.i686.rpm [More…]
LinuxSecurity.com: Several security issues were fixed in libcaca.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0049
LinuxSecurity.com: An update for libvncserver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: The v4.19.14 stable update contains important fixes across the tree.
