LinuxSecurity.com: Multiple vulnerabilities have been found in 7-Zip, the worst of which may allow execution of arbitrary code.
LinuxSecurity.com: A vulnerability in BIND might allow remote attackers to cause a Denial of Service condition.
LinuxSecurity.com: Multiple vulnerabilities have been found in phpBB, the worst of which may allow remote attackers to inject arbitrary web script or HTML.
LinuxSecurity.com: Multiple vulnerabilities have been found in PgBouncer, the worst of which may allow an attacker to bypass authentication.
LinuxSecurity.com: Multiple vulnerabilities have been found in Botan, the worst of which might allow remote attackers to obtain ECDSA secret keys.
LinuxSecurity.com: Gentoo’s NGINX ebuilds are vulnerable to privilege escalation due to the way log files are handled.
LinuxSecurity.com: Multiple vulnerabilities have been found in Expat, the worst of which may allow execution of arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in libTIFF, the worst of which may allow execution of arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in Python, the worst of which could lead to arbitrary code execution.
LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/
LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]
LinuxSecurity.com: Update —- Update to 0.11 —- Update —- Update. **WARNING:** if youare using your own config file, add “` include /etc/sway/config.d/* “` Atthe end of it, otherwise nothing will work on Wayland
LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/
LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]
security update
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: Update to Samba 4.4.9 —- Security fix for CVE-2016-2125, CVE-2016-2126
LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.6.0/releasenotes/
LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport
LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport
security update
security update
security update
LinuxSecurity.com: New upstream release
LinuxSecurity.com: Update to the latest upstream release
LinuxSecurity.com: This update includes the latest stable release of _Apache Subversion_, version**1.9.5**. #### Client-side bugfixes: * fix accessing non-existent paths duringreintegrate merge * fix handling of newly secured subdirectories in workingcopy * info: remove trailing whitespace in –show-item=revision ([issue4660](http://subversion.tigris.org/issues/show_bug.cgi?id=4660)) * fix recordingwrong revisions for tree conflicts * gpg-agent: improve discovery of gpg-agentsockets * gpg-agent: fix […]
LinuxSecurity.com: Update to 4.5.1.
LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.6.0/releasenotes/
LinuxSecurity.com: **Version 5.2.21** (December 28th 2016) * Fix missed number update in versionfile – no functional changes —- **Version 5.2.20** (December 28th 2016) ***SECURITY** Critical security update for CVE-2016-10045 please update now!Thanks to [Dawid Golunski](https://legalhackers.com) and Paul Buonopane(Zenexer). —- ** Version 5.2.19** (December 26th 2016) * Minor cleanup** Version 5.2.18** (December 24th 2016) * **SECURITY** […]
security update
LinuxSecurity.com: An update for puppet-tripleo is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: CVE-2016-3189 bzip2: heap use after free in bzip2recover
LinuxSecurity.com: libpng 1.6.27 release, fixing a potential security issue. For details, seehttps://sourceforge.net/p/png-mng/mailman/message/35575076/
LinuxSecurity.com: Update to 2.46 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. No more includes Chatzilla and DOM Inspector in the package — installthem yourself now (as usual other addons) from https://addons.mozilla.org
LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox and Thunderbird the worst of which could lead to the execution of arbitrary code.
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: An update for gstreamer1-plugins-bad-free is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]
LinuxSecurity.com: An update for gstreamer-plugins-good is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]
LinuxSecurity.com: An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]
LinuxSecurity.com: An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]
LinuxSecurity.com: upstream version 1.0.9 (BZ#1406277)
LinuxSecurity.com: – Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check incertprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack againstkerberized services by abusing password policy —- – Fixes 1395311 -CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes1370493 – CVE-2016-7030 ipa: DoS attack against kerberized services by abusingpassword policy
LinuxSecurity.com: upstream version 1.0.9 (BZ#1406277)
LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]
LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]
LinuxSecurity.com: CVE-2016-3189 bzip2: heap use after free in bzip2recover
LinuxSecurity.com: Update to 2.46 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. No more includes Chatzilla and DOM Inspector in the package — installthem yourself now (as usual other addons) from https://addons.mozilla.org
LinuxSecurity.com: – Fixed crash in auth process when auth-policy was configured and authenticationwas aborted/failed without a username set. – director: If two users haddifferent tags but the same hash, the users may have been redirected to thewrong tag’s hosts. – Index files may have been thought incorrectly lost, causing”Missing middle file seq=..” to be logged […]
LinuxSecurity.com: An integer overflow in LZO might allow remote attackers to execute arbitrary code or cause a Denial of Service condition.
LinuxSecurity.com: Multiple vulnerabilities have been found in HDF5 which could lead to the arbitrary execution of code.
LinuxSecurity.com: Multiple vulnerabilities have been found in memcached which could lead to the remote execution of arbitrary code.
LinuxSecurity.com: An integer overflow in musl might allow an attacker to execute arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in libotr and Pidgin OTR, allowing remote attackers to execute arbitrary code.
LinuxSecurity.com: An update for ipa is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]
LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581. —- This update adds apatch to fix CVE-2016-9573 and CVE-2016-9572.
LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581.
LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, SeaMonkey, and Thunderbird the worst of which could lead to the execution of arbitrary code.
security update
security update
LinuxSecurity.com: A vulnerability in mod_wsgi could lead to privilege escalation.
LinuxSecurity.com: Security Report Summary
LinuxSecurity.com: New samba packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]
LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]
LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.
LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)
LinuxSecurity.com: This update adds security sandboxing to tracker-extract.
LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)
LinuxSecurity.com: fix for “TLS SecurityMode.required bypass via StripTLS attack”(rhbz#1406703,1406704)
security update
LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]
LinuxSecurity.com: Updated to 2.1.4
LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]
LinuxSecurity.com: Updated to 2.1.4
LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]
LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.
LinuxSecurity.com: Security fix for CVE-2016-4330, CVE-2016-4331, CVE-2016-4332, CVE-2016-4333
LinuxSecurity.com: two security flaws (#1406840) x86 PV guests may be able to mask interrupts[XSA-202, CVE-2016-10024] x86: missing NULL pointer check in VMFUNC emulation[XSA-203, CVE-2016-10025] x86: Mishandling of SYSCALL singlestep duringemulation [XSA-204, CVE-2016-10013] (#1406260)
LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]
LinuxSecurity.com: – fix floating point buffer overflow issues (CVE-2016-9586)
security update
