LinuxSecurity.com: The package krb5 before version 1.16.1-1 is vulnerable to insufficient validation.
LinuxSecurity.com: The package chromium before version 67.0.3396.79-1 is vulnerable to access restriction bypass.
security update
security update
security update
security update
LinuxSecurity.com: Security fix for CVE-2018-8013. Updated to upstream release 1.10.
LinuxSecurity.com: This update fixes CVE-2016-10040, a stack overflow in QXmlSimpleReader due to a too lenient entityCharacterLimit in our version of the patch for CVE-2013-4549. (The limit was increased from the upstream 1024 to 65536 to address QTBUG-35459, an issue where the security fix was breaking existing real-world XML files. Unfortunately, that is too much to […]
LinuxSecurity.com: Alexander Peslyak discovered that insufficient input sanitising of RFB packets in LibVNCServer could result in the disclosure of memory contents.
LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.
LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.
LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.
LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.
LinuxSecurity.com: Ivan Fratric discovered a buffer overflow in the Skia graphics library used by Firefox, which could result in the execution of arbitrary code. For the oldstable distribution (jessie), this problem has been fixed
LinuxSecurity.com: New gnupg2 packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and – -current to fix a security issue.
LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Remove essentially unused pre_release tagging in spec file Fixup Makefile patch to include LDFLAGS in all linking commands
LinuxSecurity.com: DWARF5 and split dwarf, including GNU DebugFission, support.
LinuxSecurity.com: Several vulnerabilities were discovered in jruby, a Java implementation of the Ruby programming language. They would allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop,
LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.
security update
LinuxSecurity.com: A security issue was fixed in Unbound.
LinuxSecurity.com: The package radare2 before version 2.6.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: 8u171 update
LinuxSecurity.com: 8u171 update
LinuxSecurity.com: Security fix for CVE-2017-13685 CVE-2017-15286
LinuxSecurity.com: Several security issues were fixed in procps-ng.
LinuxSecurity.com: **Version 2.8.41** (2018-05-25) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas-grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user is logged out * security #cve-2018-11385 Adding session authentication strategy to Guard
LinuxSecurity.com: **Version 4.0.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user
LinuxSecurity.com: Some more efail fixes, https://enigmail.net/index.php/en/download/changelog
security update
LinuxSecurity.com: Several security issues were fixed in Git.
LinuxSecurity.com: **Version 3.4.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user
security update
security update
LinuxSecurity.com: Several security issues were fixed in Liblouis.
LinuxSecurity.com: CVE-2016-9396
LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for rh-java-common-xmlrpc is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
security update
LinuxSecurity.com: It was discovered that Wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for PCP, ADB, NBAP, UMTS MAC, IEEE 802.11, SIGCOMP, LDSS, GSM A DTAP and Q.931, which result in denial of service or the execution of arbitrary code.
LinuxSecurity.com: The redmine security update announced as DSA-4191-1 caused regressions with multi-value fields while doing queries on project issues due to an bug in the patch to address CVE-2017-15569. Updated packages are now available to correct this issue.
LinuxSecurity.com: CVE-2016-9396
LinuxSecurity.com: Security fix for CVE-2016-5003, CVE-2016-5002
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1780
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1779
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1777
LinuxSecurity.com: Man Yue Mo, Lars Krapf and Pierre Ernst discovered that Batik, a toolkit for processing SVG images, did not properly validate its input. This would allow an attacker to cause a denial-of-service, mount cross-site scripting attacks, or access restricted files on the
LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum.
LinuxSecurity.com: New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL7 noarch xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm – Scientific Linux Development Team
LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the
LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service. CVE-2018-1093
LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the
LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.
LinuxSecurity.com: Applications using Oslo middleware could be made to expose sensitiveinformation.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service: CVE-2017-11613
LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in procps, a set of command line and full screen utilities for browsing procfs. The Common Vulnerabilities and Exposures project identifies the following problems:
LinuxSecurity.com: Several security issues were fixed in libytnef.
LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL6 noarch xmlrpc3-client-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-3.0-4.17.el6_9.noarch.rpm xmlrpc3-client-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-javadoc-3.0-4.17.el6_9.noarch.rpm xmlrpc3-server-3.0-4.17.el6_9.noarch.rpm [More…]
LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
security update
LinuxSecurity.com: Several security issues were fixed in the kernel.
LinuxSecurity.com: Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-15710
LinuxSecurity.com: Git contains multiple vulnerabilities that allow for the remote execution of arbitrary code.
LinuxSecurity.com: The package strongswan before version 5.6.2-2 is vulnerable to denial of service.
LinuxSecurity.com: The package wireshark-common before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: The package wireshark-cli before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: The package wireshark-qt before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: The package wireshark-gtk before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2017-15038
LinuxSecurity.com: Etienne Stalmans discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability exploitable via specially crafted submodule names in a .gitmodules file.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1726
