LinuxSecurity.com: Gentoo’s collectd package contains multiple vulnerabilities, the worst of which may allow local attackers to escalate privileges.
LinuxSecurity.com: An update that solves 8 vulnerabilities and has four fixes is now available.
security update
LinuxSecurity.com: Various issues were discovered in exempi, a library to parse XMP metadata that may cause a denial-of-service or may have other unspecified impact via crafted files.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0549
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0549
LinuxSecurity.com: An update for collectd is now available for RHEV 4.X RHEV-H and Agents for RHEL-7 and RHEV Engine version 4.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for rh-mariadb101-mariadb and rh-mariadb101-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Paramiko could be made to run programs if it received speciallycrafted network traffic.
LinuxSecurity.com: Paramiko could be made to run programs if it received speciallycrafted network traffic.
LinuxSecurity.com: This update upgrades Firefox to version 52.7.2 ESR. * Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) (CVE-2018-5146) SL6 x86_64 firefox-52.7.2-1.el6_9.x86_64.rpm firefox-debuginfo-52.7.2-1.el6_9.x86_64.rpm firefox-52.7.2-1.el6_9.i686.rpm firefox-debuginfo-52.7.2-1.el6_9.i686.rpm i386 firefox-52.7.2-1.el6_9.i686.rpm firefox-debuginfo-52.7.2-1.el6 [More…]
LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.
LinuxSecurity.com: The package libcurl-gnutls before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.
LinuxSecurity.com: The package libcurl-compat before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.
LinuxSecurity.com: The package lib32-libcurl-compat before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.
LinuxSecurity.com: The package lib32-curl before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.
LinuxSecurity.com: The package curl before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: The package clamav before version 0.99.4-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
security update
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves 7 vulnerabilities and has one errata is now available.
LinuxSecurity.com: The package firefox before version 59.0.1-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package libvorbis before version 1.3.6-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Multiple vulnerabilities have been found in KDE Plasma Workspaces, the worst of which allows local attackers to execute arbitrary commands.
LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in Gentoo’s JabberD 2.x ebuild, the worst of which allows local attackers to escalate privileges. [More…]
LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JDK and JRE software suites, the worst of which may allow execution of arbitrary code. [More…]
LinuxSecurity.com: Multiple vulnerabilities were found in cURL, an URL transfer library: CVE-2018-1000120
LinuxSecurity.com: The package ntp before version 4.2.8.p11-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing and denial of service.
security update
security update
security update
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
security update
security update
LinuxSecurity.com: Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execution of arbitrary code.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: Huzaifa Sidhpurwala discovered that an out-of-bounds memory write in the codebook parsing code of the Libtremor multimedia library could result in the execution of arbitrary code if a malformed Vorbis file is opened.
security update
LinuxSecurity.com: Richard Zhu discovered that an out-of-bounds memory write in the codeboook parsing code of the Libvorbis multimedia library could result in the execution of arbitrary code.
LinuxSecurity.com: Some vulnerabilities have been found in ClamAV, an open source antivirus engine:
LinuxSecurity.com: An update that fixes 27 vulnerabilities is now available.
LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code, denial of service or information disclosure.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.
LinuxSecurity.com: This update upgrades Firefox to version 52.7.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7 (MFSA 2018-07) (CVE-2018-5125) * Mozilla: Buffer overflow manipulating SVG animatedPathSegList (MFSA 2018-07) (CVE-2018-5127) * Mozilla: Out-of-bounds write with malformed IPC messages (MFSA 2018-07) (CVE-2018-5129) * Mozilla: Mismatched RTP payload type can trigger memo […]
LinuxSecurity.com: This update upgrades Firefox to version 52.7.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7 (MFSA 2018-07) (CVE-2018-5125) * Mozilla: Buffer overflow manipulating SVG animatedPathSegList (MFSA 2018-07) (CVE-2018-5127) * Mozilla: Out-of-bounds write with malformed IPC messages (MFSA 2018-07) (CVE-2018-5129) * Mozilla: Mismatched RTP payload type can trigger memo […]
security update
security update
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0527
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0526
LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code or denial of service.
LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 3.0 for Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 3.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Updates for rh-dotnet20-dotnet, rh-dotnetcore10-dotnetcore, and rh-dotnetcore11-dotnetcore are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update for erlang is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update that fixes 14 vulnerabilities is now available.
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: Several vulnerabilities were discovered in mbed TLS, a lightweight crypto and SSL/TLS library, that allowed a remote attacker to either cause a denial-of-service by application crash, or execute arbitrary code.
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available.
security update
LinuxSecurity.com: This update fixes CVE-2017-18196. —- This update backports security fixes for CVE-2018-3836, CVE-2018-7186 and CVE-2018-7247.
LinuxSecurity.com: This update fixes CVE-2017-18196. —- This update backports security fixes for CVE-2018-3836, CVE-2018-7186 and CVE-2018-7247.
LinuxSecurity.com: The package postgresql before version 10.3-1 is vulnerable to privilege escalation.
LinuxSecurity.com: The package calibre before version 3.19.0-1 is vulnerable to arbitrary command execution.
LinuxSecurity.com: The package dovecot before version 2.3.0.1-1 is vulnerable to multiple issues including information disclosure and denial of service.
LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.
LinuxSecurity.com: mailman: Cross-site scripting (XSS) vulnerability in web UI (CVE-2018-5950) SL6 x86_64 mailman-2.1.12-26.el6_9.3.x86_64.rpm mailman-debuginfo-2.1.12-26.el6_9.3.x86_64.rpm i386 mailman-2.1.12-26.el6_9.3.i686.rpm mailman-debuginfo-2.1.12-26.el6_9.3.i686.rpm – Scientific Linux Development Team
LinuxSecurity.com: mailman: Cross-site scripting (XSS) vulnerability in web UI (CVE-2018-5950) SL7 x86_64 mailman-2.1.15-26.el7_4.1.x86_64.rpm mailman-debuginfo-2.1.15-26.el7_4.1.x86_64.rpm – Scientific Linux Development Team
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for libreoffice is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:
security update
LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, and Red Hat Enterprise
LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.7, 3.6, 3.5, 3.4, and 3.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: dhcp: Buffer overflow in dhclient possibly allowing code execution triggered by malicious server (CVE-2018-5732) * dhcp: Reference count overflow in dhcpd allows denial of service (CVE-2018-5733) SL7 x86_64 dhclient-4.2.5-58.el7_4.3.x86_64.rpm dhcp-common-4.2.5-58.el7_4.3.x86_64.rpm dhcp-debuginfo-4.2.5-58.el7_4.3.i686.rpm dhcp-debuginfo-4.2.5-58.el7_4.3.x86_64.rpm dhcp [More…]
LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions, and Red Hat Enterprise Linux 7.3 Extended Update Support.
LinuxSecurity.com: Update to latest version. Security-Fixes TROVE-2018-001, TROVE-2018-002,
