LinuxSecurity.com: Upstream announcement: **Version 1.3.6** This is a security update to the stable version 1.3. It primarily fixes a recently discovered IMAP command injection vulnerability caused by insufficient input validation within the archive plugin. Details about the vulnerability are published under CVE-2018-9846. Additionally, we back-ported some minor fixes from the master
LinuxSecurity.com: An update that fixes 33 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: Two vulnerabilities were discovered in LibreOffice’s code to parse MS Word and Structured Storage files, which could result in denial of service and potentially the execution of arbitrary code if a malformed file is opened.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in the image loading library for Simple DirectMedia Layer 2, which could result in denial of service or the execution of arbitrary code if malformed image files are opened.
LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084
LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.60, which includes additional changes. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for
security update
LinuxSecurity.com: Fuzzing by the OSS-Fuzz project found two memory safety issues in LibreOffice, which could result in an application crash or possibly other unspecified impact.
LinuxSecurity.com: OpenJDK: incorrect handling of Reference clones can lead to sandbox bypass (Hotspot, 8192025) (CVE-2018-2814) * OpenJDK: unrestricted deserialization of data from JCEKS key stores (Security, 8189997) (CVE-2018-2794) * OpenJDK: insufficient consistency checks in deserialization of multiple classes (Security, 8189977) (CVE-2018-2795) * OpenJDK: unbounded memory allocation during deserializati [More…]
LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.60, which includes additional changes. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for
LinuxSecurity.com: New gd packages are available for Slackware 14.2 and -current to fix security issues.
LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084
LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079
LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities that could result in infinite loops in different dissectors. Other issues are related to crash in dissectors that are
LinuxSecurity.com: Two vulnerabilities were found in OpenCV, the “Open Computer Vision Library”. CVE-2018-5268
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: Wojciech Regula discovered an XML External Entity vulnerability in the XML Parser of the mindmap loader in freeplane, a Java program for working with mind maps, resulting in potential information disclosure if a malicious mind map file is opened.
LinuxSecurity.com: Version 2.1.3 (March 5th, 2018) ——————————- **Security fixes** * Attributes that have URI values weren’t properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized. This security issue was introduced in Bleach 2.1. […]
security update
security update
LinuxSecurity.com: The Citrix Security Response Team discovered that corosync, a cluster engine implementation, allowed an unauthenticated user to cause a denial-of-service by application crash.
LinuxSecurity.com: – update to the latest upstream release (fixes CVE-2018-1000168)
LinuxSecurity.com: Update to latest upstream version.
LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084
LinuxSecurity.com: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: https://apps.ankiweb.net/docs/changes.html
LinuxSecurity.com: update to latest upstream release, which fixes the following vulnerabilities: – CVE-2018-1100 – stack-based buffer overflow in utils.c:checkmailpath() – CVE-2018-1083 – stack-based buffer overflow in compctl.c:gen_matches_files() – CVE-2018-1071 – stack-based buffer overflow in exec.c:hashcmd()
LinuxSecurity.com: Removing dependency on wireshark metapackage from wireshark-cli —- Added wireshark-qt to wireshark metapackage —- – New version 2.4.5 – Contains fixes for CVE-2018-7419, CVE-2018-7418, CVE-2018-7417, CVE-2018-7420, CVE-2018-7320, CVE-2018-7336, CVE-2018-7337, CVE-2018-7334, CVE-2018-7335, CVE-2018-6836, CVE-2018-5335, CVE-2018-5334, CVE-2017-6014, CVE-2017-9616,
security update
LinuxSecurity.com: This update doesn’t fix a vulnerability in linux-tools, but provides support for building Linux kernel modules with the “retpoline” mitigation for CVE-2017-5715 (Spectre variant 2).
LinuxSecurity.com: Marcin Noga discovered multiple vulnerabilities in readxl, a GNU R package to read Excel files (via the integrated libxls library), which could result in the execution of arbitrary code if a malformed spreadsheet is processed.
LinuxSecurity.com: Several security issues were fixed in Ruby.
LinuxSecurity.com: Minor update from upstream with fix for CVE-2018-9234 and other bug fixes.
LinuxSecurity.com: Several security issues were fixed in Patch.
LinuxSecurity.com: It was discovered that there was an input validation vulnerability in the patch(1) utility where an ed(1) script embedded in a regular input file could result in arbitrary code execution. This was reported by Rachel Kroll [0] et al.
LinuxSecurity.com: A NULL Pointer Dereference was discovered in the TIFFPrintDirectory function (tif_print.c) when using the tiffinfo tool to print crafted TIFF information. This vulnerability could be leveraged by remote attackers to cause a crash of the application.
LinuxSecurity.com: A NULL Pointer Dereference was discovered in the TIFFPrintDirectory function (tif_print.c) when using the tiffinfo tool to print crafted TIFF information. This vulnerability could be leveraged by remote attackers to cause a crash of the application.
LinuxSecurity.com: A vulnerability in Go allows remote attackers to execute arbitrary commands.
LinuxSecurity.com: The package lib32-openssl before version 1:1.1.0.h-1 is vulnerable to private key recovery.
LinuxSecurity.com: The package zsh before version 5.5-1 is vulnerable to arbitrary code execution.
security update
LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:
LinuxSecurity.com: * Rebase to Ruby 2.5.1. * Several CVE fixes. * Conflict requirement needs to generate dependency. * Stop using –with-setjmp-type=setjmp on aarch64.
LinuxSecurity.com: Minor update from upstream with fix for CVE-2018-9234 and other bug fixes.
LinuxSecurity.com: harden the binaries (rhbz#1548670)
LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079 Rebased to latest upstream sources
LinuxSecurity.com: Fixes several heap-buffer-overflows, see related Bugzilla tickets!
LinuxSecurity.com: Fix CVE-2017-11550 and CVE-2004-2779
LinuxSecurity.com: GwanYeong Kim reported that ‘pack()’ could cause a heap buffer write overflow with a large item count. For Debian 7 “Wheezy”, these problems have been fixed in version
security update
LinuxSecurity.com: python-paramiko: Authentication bypass in transport.py (CVE-2018-7750) SL6 noarch python-paramiko-1.7.5-4.el6_9.noarch.rpm – Scientific Linux Development Team
LinuxSecurity.com: USN-3621-1 caused a regression in Ruby.
LinuxSecurity.com: The package apache before version 2.4.33-1 is vulnerable to multiple issues including session hijacking, access restriction bypass, content spoofing and denial of service.
LinuxSecurity.com: An update that solves three vulnerabilities and has 7 fixes is now available.
LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, and Red Hat Enterprise
LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 11.0 (Ocata), Red Hat OpenStack Platform 12.0 (Pike), Red Hat OpenStack Platform 8.0 (Liberty), and Red Hat OpenStack Platform 9.0 (Mitaka).
LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 11.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: This updates LibOFX to fix assorted CVEs.
LinuxSecurity.com: It was discovered that the poppler upload for the oldstable distribution (jessie), released as DSA-4079-1, did not correctly address CVE-2017-9776 and additionally caused regressions when rendering PDFs embedding JBIG2 streams. Updated packages are now available to correct
LinuxSecurity.com: This update upgrades Firefox to version 52.7.3 ESR. * firefox: Use-after-free in compositor potentially allows code execution (CVE-2018-5148) SL6 x86_64 firefox-52.7.3-1.el6_9.x86_64.rpm firefox-debuginfo-52.7.3-1.el6_9.x86_64.rpm firefox-52.7.3-1.el6_9.i686.rpm firefox-debuginfo-52.7.3-1.el6_9.i686.rpm i386 firefox-52.7.3-1.el6_9.i686.rpm firefox-debuginfo-52.7.3-1 [More…]
LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.
LinuxSecurity.com: This updates LibOFX to fix assorted CVEs.
LinuxSecurity.com: Fixes for CVE-2018-1002150.
LinuxSecurity.com: Several security issues were fixed in Patch.
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves three vulnerabilities and has 7 fixes is now available.
LinuxSecurity.com: C?dric Buissart from Red Hat discovered an information disclosure bug in pcs, a pacemaker command line interface and GUI. The REST interface normally doesn’t allow passing –debug parameter to prevent information leak, but the check wasn’t sufficient.
security update
security update
