security update
LinuxSecurity.com: Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rhev-hypervisor7 is now available for RHEV 3.X Hypervisor and Agents for Red Hat Enterprise Linux 6 and RHEV 3.X Hypervisor and Agents Extended Lifecycle Support for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update for rh-ror50-rubygem-sprockets is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for rh-ror42-rubygem-sprockets is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL6 x86_64 java-1.8.0-openjdk-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-debug-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8 [More…]
LinuxSecurity.com: Update to 1.2.6 to fix a local authenticated privilege escalation bug (CVE-2018-10900). The issue has been discovered and responsibly disclosed by Denis Andzakovic: https://pulsesecurity.co.nz/advisories/NM-VPNC-Privesc
LinuxSecurity.com: A regression that caused boot failures was fixed in the Linux kernel.
LinuxSecurity.com: A regression that caused boot failures was fixed in the Linux kernel.
LinuxSecurity.com: Multiple vulnerabilities have been found in Passenger, the worst of which could result in the execution of arbitrary code.
LinuxSecurity.com: CVE-2018-7033 Fix for issue in accounting_storage/mysql plugin by always escaping strings within the slurmdbd.
LinuxSecurity.com: Early versions of opencv have problems while reading data, which might result in either buffer overflows, out-of bounds errors or integer
LinuxSecurity.com: The package networkmanager-vpnc before version 1.2.6-1 is vulnerable to privilege escalation.
LinuxSecurity.com: The package apache before version 2.4.34-1 is vulnerable to denial of service.
LinuxSecurity.com: The package znc before version 1.7.1-1 is vulnerable to multiple issues including privilege escalation and directory traversal.
LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program.
LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)
LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.
LinuxSecurity.com: An update for openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: The dns-root-data update to 2017072601~deb8u2 broke dnsmasq’s init script, making dnsmasq no longer start when dns-root-data was installed.
LinuxSecurity.com: The linux-base package has been updated to support the package of Linux 4.9 that was recently added to Debian 8. This resolves a dependency that was not satisfiable by the jessie and jessie-security suites.
LinuxSecurity.com: CVE-2015-1239 Fix for denial of service (process crash) via a crafted PDF.
security update
security update
LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)
LinuxSecurity.com: Fix heap memory corruption, CVE-2017-17833
LinuxSecurity.com: – Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408) – Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373) – Fix two-key 3DES (PR #390) – Fix accelerated CTR mode (PR #359) – Fix Fortuna PRNG (PR #363) – Fix compilation on platforms where cc doesn’t point to gcc (PR #382) […]
LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.
LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.
LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.
LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for fluentd is now available for Red Hat OpenStack Platform 13.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.
LinuxSecurity.com: unzip and untar target tasks in ant allows the extraction of files outside the target directory. A crafted zip or tar file submitted to an Ant build could create or overwrite arbitrary files with the
LinuxSecurity.com: Jeriko One discovered two vulnerabilities in the ZNC IRC bouncer which could result in privilege escalation or denial of service. For the stable distribution (stretch), these problems have been fixed in
LinuxSecurity.com: A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.
LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: CVE-2018-11439 Fix for a heap-based buffer over-read via a crafted audio file.
security update
security update
LinuxSecurity.com: New release (1:12.2.6-1) Security fix for CVE-2018-1128 Security fix for CVE-2018-1129 Security fix for CVE-2018-10861
LinuxSecurity.com: The package curl before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-curl before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: Several security issues were fixed in PolicyKit.
LinuxSecurity.com: A vulnerability was discovered in WordPress, a web blogging tool. It allowed remote attackers with specific roles to execute arbitrary code.
LinuxSecurity.com: A vulnerability in tqdm could allow remote attackers to execute arbitrary code.
security update
LinuxSecurity.com: Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in various parsers of Blender, a 3D modeller/ renderer. Malformed .blend model files and malformed multimedia files (AVI, BMP, HDR, CIN, IRIS, PNG, TIFF) may result in the execution of arbitrary code.
LinuxSecurity.com: New mutt packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
security update
LinuxSecurity.com: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification (CVE-2018-12020) SL7 x86_64 gnupg2-2.0.22-5.el7_5.x86_64.rpm gnupg2-debuginfo-2.0.22-5.el7_5.x86_64.rpm gnupg2-smime-2.0.22-5.el7_5.x86_64.rpm gnupg2-2.0.22-5.el7_5.src.rpm – Scientific Linux Development Team
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: The package thunderbird before version 52.9.1-1 is vulnerable to multiple issues including arbitrary code execution, cross-site request forgery and information disclosure.
LinuxSecurity.com: A timing attack was discovered in the function for CSRF token validation of the “Ruby rack protection” framework. For the stable distribution (stretch), this problem has been fixed in
security update
security update
LinuxSecurity.com: The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo
LinuxSecurity.com: – Security fix for CVE-2017-9258, CVE-2017-9259, CVE-2017-9260
LinuxSecurity.com: CVE-2015-1854 A flaw was found while doing authorization of modrdn operations. An unauthenticated attacker able to issue an ldapmodrdn call to
LinuxSecurity.com: It was discovered that there were two issues in znc, a modular IRC bouncer: * There was insufficient validation of lines coming from the network
LinuxSecurity.com: Update to 4.9.7 security release. https://wordpress.org/news/2018/07/wordpress-4-9-7-security-and-maintenance- release/
LinuxSecurity.com: Security fix for CVE-2018-8009 —- Version update to 2.7.6. Fixes many open CVEs and bugs.
LinuxSecurity.com: Update to Sprockets 3.7.2. Fixes CVE-2018-3760: https://access.redhat.com/security/cve/cve-2018-3760
security update
LinuxSecurity.com: Several vulnerabilities were discovered in CUPS, the Common UNIX Printing System. These issues have been identified with the following CVE ids: CVE-2018-4180
LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.
