LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.
LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.
LinuxSecurity.com: OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transfer library, could be tricked into reading data beyond the end of a heap based buffer when parsing invalid headers in an RTSP response.
LinuxSecurity.com: It was discovered that there was an issue in the curl a command-line tool for downloading (eg.) data over HTTP. curl could have be tricked into reading data beyond the end of a heap
security update
LinuxSecurity.com: Several security issues were fixed in PHP.
security update
LinuxSecurity.com: Several security issues were fixed in PHP.
LinuxSecurity.com: A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code.
LinuxSecurity.com: The package firefox before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass, access restriction bypass, content spoofing, denial of service, information disclosure and sandbox escape.
LinuxSecurity.com: The package webkit2gtk before version 2.20.2-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package llpp before version 27-2 is vulnerable to multiple issues including arbitrary code execution and denial of service.
LinuxSecurity.com: Fabian Vogt discovered that incorrect permission handling in the PAM module of the KDE Wallet could allow an unprivileged local user to gain ownership of arbitrary files.
LinuxSecurity.com: Security fix for CVE-2018-10380
LinuxSecurity.com: Security fix for CVE-2018-10380
LinuxSecurity.com: https://www.libraw.org/news/libraw-0-18-11 —- CVE-2018-10529 fixed: out of bounds read in X3F parser CVE-2018-10528 fixed: possible stack overrun in X3F parser
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has 6 fixes is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
security update
LinuxSecurity.com: Harry Sintonen have discovered a cookie injection vulnerability in wget caused by insufficient input validation, enabling an external attacker to inject arbitrary cookie values cookie jar file, adding new
LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code or denial of service.
LinuxSecurity.com: Updated to latest upstream release (#1571443, #1573318, #1573319).
LinuxSecurity.com: Several security issues were fixed in OpenJDK 8.
LinuxSecurity.com: Update to 1.10.1
security update
security update
LinuxSecurity.com: New wget packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1319
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1364
LinuxSecurity.com: The package freetype2 before version 2.9.1-1 is vulnerable to denial of service.
LinuxSecurity.com: Dancer2 0.206000 addresses several potential security issues. There is a potential RCE with regards to Storable. Dancer2 adds session ID validation to the session engine so that session backends based on Storable can reject malformed session IDs that may lead to exploitation of the RCE. Parsing requests now uses HTTP::Entity::Parser which reduces the amount […]
LinuxSecurity.com: ## 4.9.2 https://ckeditor.com/cke4/release/CKEditor-4.9.2 ### Security Updates – Fixed XSS vulnerability in the Enhanced Image (image2) plugin reported by Kyaw Min Thein. – Issue summary: It was possible to execute XSS inside CKEditor using the tag and specially crafted HTML. Please note that the default presets (Basic/Standard/Full) do not include this plugin, so you are […]
LinuxSecurity.com: Security fix for CVE-2017-6888.
LinuxSecurity.com: Security fix for CVE-2018-1000156
LinuxSecurity.com: Regenerate autoconf files using current tools so proper build flags from redhat- rpm-config are used. This applies hardened LDFLAGS. No functional change intended.
LinuxSecurity.com: This release provides Perl 5.26.2 that fixes a heap buffer overflow in the pack() function and two overflows in regular expression engine.
LinuxSecurity.com: Knot Resolver 2.3.0 (2018-04-23) ——– – fix CVE-2018-1110: denial of service triggered by malformed DNS messages (!550, !558, security!2, security!4) – increase resilience against slow lorris attack (security!5) Bugfixes ——– – validation: fix SERVFAIL in case of CNAME to NXDOMAIN in a single zone (!538) – validation: fix SERVFAIL for
security update
LinuxSecurity.com: On May 8, fixes for CVE-2018-1087 and CVE-2018-8897 were released in linuxkernel version 4.4.0-124.148. These CVEs are both related to the way thatthe linux kernel handles certain interrupt and exception instructions. Ifan interrupt or exception instruction (INT3, SYSCALL, etc.) is immediatelypreceded by a MOV SS or POP SS instruction, the resulting interrupt will [More…]
LinuxSecurity.com: Harry Sintonen discovered that wget, a network utility to retrieve files from the web, does not properly handle ‘rn’ from continuation lines while parsing the Set-Cookie HTTP header. A malicious web server could use this flaw to inject arbitrary cookies to the cookie jar file, adding
security update
LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
LinuxSecurity.com: Several security issues were fixed in the kernel.
security update
LinuxSecurity.com: An XML external entity expansion vulnerability was discovered in the DataImportHandler of Solr, a search server based on Lucene, which could result in information disclosure.
LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.
LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.
LinuxSecurity.com: – fix stack-based buffer overflow in utils.c:checkmailpath() (CVE-2018-1100) – fix stack-based buffer overflow in gen_matches_files() (CVE-2018-1083) – fix stack-based buffer overflow in exec.c:hashcmd() (CVE-2018-1071)
LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions or unsafe redirects. More information can be found in the upstream advisory at
security update
LinuxSecurity.com: – https://www.drupal.org/project/drupal/releases/7.59 – https://www.drupal.org/SA-CORE-2018-004
LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.
LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.
LinuxSecurity.com: Red Hat Single Sign-On 7.2.2 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code.
LinuxSecurity.com: This update includes the changes in tzdata 2018e for the Perl bindings. For the list of changes, see DLA-1371-1. For Debian 7 “Wheezy”, these problems have been fixed in version
LinuxSecurity.com: This update includes the changes in tzdata 2018e. Notable changes are: – North Korea switches back to +09 on 2018-05-05.
LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.
LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
