Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.36 up to 8.0.38 which resolvesmultiple CVEs and a problem that 8.0.37 introduces to freeipa: * rhbz#1375581 -CVE-2016-5388 Tomcat: CGI sets environmental variable based on user suppliedProxy request header * rhbz#1390532 – CVE-2016-0762 CVE-2016-5018 CVE-2016-6794CVE-2016-6796 CVE-2016-6797 tomcat: various flaws and includes two additionalCVE fixes along with one […]

LinuxSecurity.com: Security fix for CVE-2016-8864

LinuxSecurity.com: This update backports an upstream patch to fix multiple integer overflows(CVE-2016-9085).

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.36 up to 8.0.38 which resolvesmultiple CVEs and a problem that 8.0.37 introduces to freeipa: * rhbz#1375581 -CVE-2016-5388 Tomcat: CGI sets environmental variable based on user suppliedProxy request header * rhbz#1390532 – CVE-2016-0762 CVE-2016-5018 CVE-2016-6794CVE-2016-6796 CVE-2016-6797 tomcat: various flaws and includes two additionalCVE fixes along with one […]

LinuxSecurity.com: – update to 1.8.18p1 – fixes CVE-2016-7076

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: An update for policycoreutils is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

security update

security update

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: This update contains security fix for CVE-2016-8883, CVE-2016-8882,CVE-2016-8881, CVE-2016-8880, CVE-2016-8884, CVE-2016-8885, CVE-2016-8887,CVE-2016-8886. —- New version of jasper is available (jasper-1.900.13).Security fix for CVE-2016-8690, CVE-2016-8691, CVE-2016-8692, CVE-2016-8693.—- New version of jasper is available (1.900.3) —- Security fix forCVE-2016-2089 —- New version of jasper is available.

LinuxSecurity.com: – fixed permissions of initramfs file, if microcode is prepended(CVE-2016-8637)

LinuxSecurity.com: Security fix for CVE-2016-5181, CVE-2016-5182, CVE-2016-5183, CVE-2016-5184,CVE-2016-5185, CVE-2016-5187, CVE-2016-5188, CVE-2016-5192, CVE-2016-5189,CVE-2016-5186, CVE-2016-5191, CVE-2016-5190, CVE-2016-5193, CVE-2016-5194Security fix for CVE-2016-5198 Update to new stable, 54.0.2840.90.

LinuxSecurity.com: Security fix for CVE-2016-5181, CVE-2016-5182, CVE-2016-5183, CVE-2016-5184,CVE-2016-5185, CVE-2016-5187, CVE-2016-5188, CVE-2016-5192, CVE-2016-5189,CVE-2016-5186, CVE-2016-5191, CVE-2016-5190, CVE-2016-5193, CVE-2016-5194Security fix for CVE-2016-5198 Update to new stable, 54.0.2840.90.

LinuxSecurity.com: several qemu security fixes

security update

LinuxSecurity.com: – new upstream version (49.0.2)

LinuxSecurity.com: Security fix for CVE-2016-7035 (improper IPC guarding)

LinuxSecurity.com: Update to 1.10.12

LinuxSecurity.com: Security Report Summary

Understanding and mitigating the Dirty Cow Vulnerability

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

security update

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for pacemaker is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Add patch to fix dnf module groupinstall handling —- Update to new ansible2.2 version. For full changes see:https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.md

LinuxSecurity.com: Security fix for CVE-2016-6293

LinuxSecurity.com: The 4.8.6 stable update contains a number of important fixes across the tree.

LinuxSecurity.com: This update fixes a rare ocasion where ghostscript would fail when displaying*.ps files. More info can be found[here](http://bugs.ghostscript.com/show_bug.cgi?id=697286). —- This is asecurity update for these CVEs: *[CVE-2016-8602](https://bugzilla.redhat.com/show_bug.cgi?id=1383940) – *checkfor sufficient params in .sethalftone5* *[CVE-2016-7977](https://bugzilla.redhat.com/show_bug.cgi?id=1380415) – *.libfiledoes not honor -dSAFER* [This CVE is now correctly fixed, previous release wasaccidentally missing the fix.]

LinuxSecurity.com: October 2016 CPU fixes: http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html#AppendixJAVA

LinuxSecurity.com: – new upstream version (49.0.2)

LinuxSecurity.com: Bump version to 1.3.5.15-1

LinuxSecurity.com: Security fix for CVE-2016-7035 (improper IPC guarding)

LinuxSecurity.com: – fix cookie injection for other servers (CVE-2016-8615) – compare user/passwdcase-sensitively while reusing connections (CVE-2016-8616) – base64: check forinteger overflow on large input (CVE-2016-8617) – fix double-free in krb5 code(CVE-2016-8619) – fix double-free in curl_maprintf() (CVE-2016-8618) – fix globparser write/read out of bounds (CVE-2016-8620) – fix out-of-bounds read incurl_getdate() (CVE-2016-8621) – fix URL unescape […]

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

security update

security update

security update

LinuxSecurity.com: An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Amazon’s very own Linux now available for download

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JRE and JDK software suites allowing remote attackers to remotely execute arbitrary code, obtain information, and cause Denial of Service.

LinuxSecurity.com: Multiple vulnerabilities have been found in both LibreOffice and OpenOffice, the worst of which allows for the remote execution of arbitrary code.

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: This update addresses multiple security problems and fixes systemd dependencies.

LinuxSecurity.com: This update addresses multiple security problems and fixes systemd dependencies.

LinuxSecurity.com: the new package fixes the CVE-2016-7966. for more info please take a look athttps://www.kde.org/info/security/advisory-20161006-1.txt

LinuxSecurity.com: This update backports an upstream patch to fix multiple integer overflows(CVE-2016-9085).

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for fontconfig is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for mod_nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for util-linux is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for powerpc-utils-python is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for subscription-manager, subscription-manager-migration-data, and python-rhsm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for php is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for libreswan is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for squid is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for resteasy-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

security update

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: update to upstream release 0.2.8.9

LinuxSecurity.com: Fixes CVE-2016-7969, CVE-2016-7970 and CVE-2016-7972 —- Update to 0.13.3.Contains various bugfixes.

LinuxSecurity.com: Security fix for CVE-2016-5407

LinuxSecurity.com: Security fix for CVE-2016-7953

LinuxSecurity.com: Security fix for CVE-2016-7949, CVE-2016-7950

LinuxSecurity.com: Security fix for CVE-2016-7951, CVE-2016-7952

LinuxSecurity.com: Security fix for CVE-2016-7947, CVE-2016-7948

How To Protect Linux Servers And Android Phones Against Dirty COW Security Bug
New leak may show if you were hacked by the NSA

LinuxSecurity.com: An update for java-1.7.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for mysql55-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

US DMCA rules updated to give security experts legal backing to research

LinuxSecurity.com: Multiple vulnerabilities have been found in UnZip allowing remote attackers to execute arbitrary code and cause Denial of Service.

LinuxSecurity.com: update to upstream release 0.2.8.9

LinuxSecurity.com: New x11 packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]