LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
LinuxSecurity.com: Talosintelligence discovered a command injection vulnerability in the gplotMakeOutput function of leptonlib. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary
LinuxSecurity.com: An update that solves 10 vulnerabilities and has three fixes is now available.
LinuxSecurity.com: An update that solves 16 vulnerabilities and has 12 fixes is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: Several security issues were fixed in Quagga.
LinuxSecurity.com: Several vulnerabilities have been discovered in Quagga, a routing daemon. The Common Vulnerabilities and Exposures project identifies the following issues:
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
security update
security update
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: – CVE-2018-1055 Remote arbitrary file disclosure vulnerability via WEBSERVICE formula
LinuxSecurity.com: Updated AppStream metadata
LinuxSecurity.com: This is an update to Mozilla’s CA certificates list version 2.22, which has been published as part of Mozilla NSS 3.35. For additional details, please refer to the NSS 3.35 release notes: https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.35_release_notes
LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, did not properly validate user input before attempting deserialization. This allowed an attacker to perform code execution by providing maliciously crafted input.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
security update
LinuxSecurity.com: Two vulnerabilities were discovered in the libraries of the Vorbis audio compression codec, which could result in denial of service or the execution of arbitrary code if a malformed media file is processed.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor: CVE-2017-17563
LinuxSecurity.com: An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQ. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: FreeType could be made to crash if it opened a specially crafted file.
LinuxSecurity.com: An update for httpd24-apr is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for openstack-aodh is now available for Red Hat OpenStack Platform 11.0 (Ocata). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Joonun Jang discovered that the advzip tool in advancecomp, a collection of recompression utilities, was prone to a heap-based buffer overflow. This might allow an attacker to cause a denial-of-service (application crash) or other unspecified impact via
LinuxSecurity.com: An update for openstack-nova is now available for Red Hat OpenStack Platform 11.0 (Ocata). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for erlang is now available for Red Hat OpenStack Platform 11.0 (Ocata). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for collectd is now available for Red Hat OpenStack Platform 11.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: A denial of service vulnerability has been discovered in graphicsmagick, a collection of image processing tools and associated libraries.
LinuxSecurity.com: The package exim before version 4.90.1-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package mpv before version 1:0.27.1-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: An update that solves 8 vulnerabilities and has 13 fixes is now available.
LinuxSecurity.com: Several security issues were fixed in libvorbis.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: Red Hat JBoss Data Grid 7.1.2 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: A request smuggling vulnerability was discovered in pound that may allow attackers to send a specially crafted http request to a web server or reverse proxy while pound may see a different set of requests. This facilitates several possible exploitations, such as partial cache
LinuxSecurity.com: CVE-2017-6419 CVE-2017-11423
LinuxSecurity.com: Mikhail Klementev, Ronnie Goodrich and Andrew Krasichkov discovered that missing restrictions in the implementation of the WEBSERVICE function in LibreOffice could result in the disclosure of arbitrary files readable by the user who opens a malformed document.
LinuxSecurity.com: The package sthttpd before version 2.27.1-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: WavPack could be made to crash if it opened a specially crafted file.
LinuxSecurity.com: Mikhail Klementev, Ronnie Goodrich and Andrew Krasichkov discovered that missing restrictions in the implementation of the WEBSERVICE function in LibreOffice could result in the disclosure of arbitrary files readable by the user who opens a malformed document.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: It was discovered that there was an input validation vulnerability in the librsvg renderer library that could result in data being leaked to remote attackers via a specially-crafted file.
LinuxSecurity.com: Chris Navarrete from Fortinet’s FortiGuard Labs discovered that Audacity, a multi-track audio editor, contains a vulnerability such that a .wav file with a crafted FORMATCHUNK structure (many channels) can result in
LinuxSecurity.com: Multiple vulnerabilities have been found in VirtualBox, the worst of which could allow an attacker to take control of VirtualBox.
LinuxSecurity.com: Jonas Klempel discovered that, when parsing the AIA-Extension field of a client certificate, Apache Tomcat Native did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the
security update
security update
LinuxSecurity.com: It was discovered that the uwsgi_expand_path function in utils.c in Unbit uWSGI, an application container server, has a stack-based buffer overflow via a large directory length that can cause a denial-of-service (application crash) or stack corruption.
security update
LinuxSecurity.com: Meh Chang discovered a buffer overflow flaw in a utility function used in the SMTP listener of Exim, a mail transport agent. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code via a specially crafted
LinuxSecurity.com: Meh Chang discovered a buffer overflow flaw in a utility function used in the SMTP listener of Exim, a mail transport agent. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code via a specially crafted
LinuxSecurity.com: Security fix for CVE-2017-15698
LinuxSecurity.com: PostgreSQL could be made to expose sensitive information.
LinuxSecurity.com: The package clamav before version 0.99.3-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
LinuxSecurity.com: An update that solves 9 vulnerabilities and has 70 fixes is now available.
LinuxSecurity.com: Lalith Rallabhandi discovered that OmniAuth, a Ruby library for implementing multi-provider authentication in web applications, mishandled and leaked sensitive information. An attacker with access to the callback environment, such as in the case of a crafted web
LinuxSecurity.com: The package plasma-workspace before version 5.12.0-1 is vulnerable to arbitrary command execution.
LinuxSecurity.com: The package plasma-workspace before version 5.12.0-1 is vulnerable to arbitrary command execution.
LinuxSecurity.com: The package go-pie before version 1.9.4-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package go before version 1.9.4-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: An update that solves 9 vulnerabilities and has 44 fixes is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: Mailman could be made to run arbitrary code.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Security fix for CVE-2017-15698
LinuxSecurity.com: simplesamlphp, an authentication and federation application has been found vulnerable to Cross Site Scripting (XSS), signature validation byepass and using insecure connection charset.
LinuxSecurity.com: The mailman package has a Cross-site scripting (XSS) vulnerability in the web UI before 2.1.26 which allows remote attackers to inject arbitrary web script or HTML via a user-options URL
LinuxSecurity.com: A regression was detected in the previously issued fix for CVE-2018-6360. The patch released with DSA 4105-1 broke the feature of invoking mpv with raw YouTube ids. This update fixes this functionality issue. For reference, the relevant part of the original advisory text follows.
LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.
security update
security update
security update
LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update that solves 9 vulnerabilities and has 68 fixes is now available.
LinuxSecurity.com: Several security issues were fixed in Django.
LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.
LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
