LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: The package firefox before version 64.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass and access restriction bypass.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
LinuxSecurity.com:
LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.
LinuxSecurity.com: USN-3837-1 introduced a regression in poppler.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.
security update
LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.
LinuxSecurity.com: pixman could be made to crash or run programs if it processed specially crafted instructions.
LinuxSecurity.com: The package openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package lib32-openssl-1.0 before version 1.0.2.q-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package lib32-openssl before version 1:1.1.1.a-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package openssl before version 1.1.1.a-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package texlive-bin before version 2018.48691-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package wireshark-cli before version 2.6.5-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: The package chromium before version 71.0.3578.80-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and insufficient validation.
LinuxSecurity.com: CUPS could be made to expose sensitive information.
LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.
LinuxSecurity.com: lxml could allow cross-site scripting (XSS) attacks.
LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.6 Telco Update Service (TUS). This notification applies only to those customers subscribed to the Telco Update Service (TUS) channel for Red Hat Enterprise Linux 6.6.
LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 7.3 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 7.3.
LinuxSecurity.com: This is the one-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.
LinuxSecurity.com: Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF module was susceptible to denial of service/information disclosure when parsing malformed images, the Apache module allowed cross-site-scripting via the body of a
LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: It was discovered that there was a XSS injection vulnerability in the LXML HTML/XSS manipulation library for Python. LXML did not remove “javascript:” URLs that used escaping such as
LinuxSecurity.com: An update for rh-git218-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service (CVE-2018-1336). The defaults settings for the CORS filter are insecure and enable
LinuxSecurity.com: An update that fixes 27 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
security update
LinuxSecurity.com: Use after free flaw enabling arbitrary code execution. (CVE-2018-15982) Insecure Library Loading (DLL hijacking) flaw enabling privilege escalation. (CVE-2018-15983)
LinuxSecurity.com: The HTML thumbnailer was incorrectly accessing some content of remote URLs listed in HTML files. This meant that the owners of the servers referred in HTML files in your system could have seen in their access logs your IP address every time the thumbnailer tried to create the thumbnail (CVE-2018-19120).
security update
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves 7 vulnerabilities and has two fixes is now available.
LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
security update
LinuxSecurity.com: A vulnerability in EDE could result in privilege escalation.
LinuxSecurity.com: The package jupyter-notebook before version 5.7.2-1 is vulnerable to cross-site scripting.
LinuxSecurity.com: It was discovered that incorrect processing of very high UIDs in Policykit, a framework for managing administrative policies and privileges, could result in authentication bypass.
LinuxSecurity.com: Several security issues were fixed in OpenSSL.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3760
LinuxSecurity.com: Several security issues were fixed in SpamAssassin.
LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for openstack-neutron is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: It was discovered that the ghostscript /invalidaccess checks fail under certain conditions. An attacker could possibly exploit this to bypass the – -dSAFER protection and, for example, execute arbitrary shell commands via a specially crafted PostScript document. (CVE-2018-16509) SL6 x86_64 ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript- [More…]
LinuxSecurity.com: ghostscript: incomplete fix for CVE-2018-16509 (CVE-2018-16863) Bug Fix(es): * Previously, the flushpage operator has been removed as part of a major clean-up of a non-standard operator. However, flushpage has been found to be used in a few specific use cases. With this update, it has been re- added to support those use cases. SL7 […]
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform release 3.6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML. This happens even if the option to allow the HTML emails to access remote servers is disabled in KMail settings. This means that the owners of the servers referred in the email can see in their […]
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in Perl.
LinuxSecurity.com: Several security issues were fixed in Perl.
LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to arbitrary code execution.
LinuxSecurity.com: A vulnerability in Nagios allows local users to escalate privileges.
LinuxSecurity.com: Multiple vulnerabilities have been found in ConnMan, the worst of which could result in the remote execution of code.
LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could result in a Denial of Service condition.
LinuxSecurity.com: An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: It was discovered that Requests incorrectly handled certain HTTP headers. An attacker could possibly use this issue to access sensitive information (CVE-2018-18074). References:
LinuxSecurity.com: A flaw was found in mod_perl 2.0 through 2.0.10 which allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator’s control of HTTP request processing without also permitting unprivileged users to run
