LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow a remote attacker to cause a Denial of Service or gain elevated privileges from a guest VM. [More…]
LinuxSecurity.com: Multiple vulnerabilities have been found in Shadow, the worst of which might allow privilege escalation.
LinuxSecurity.com: Gentoo’s MUNGE ebuilds are vulnerable to privilege escalation due to improper permissions.
LinuxSecurity.com: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents
LinuxSecurity.com: Update to 4.12 (#1456190)
LinuxSecurity.com: Security fix for CVE-2017-7494
LinuxSecurity.com: Update to latest stable release, include fixes for gnutls and gtk-vnc compatibility.
LinuxSecurity.com: – update to 1.8.20p2 – added sudo package to dnf/yum protected packages —- – update to 1.8.20p1 – fixes CVE-2017-1000367
LinuxSecurity.com: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c
LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)
LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053
LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053
LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)
LinuxSecurity.com: The cPanel Security Team reported a time of check to time of use (TOCTTOU) race condition flaw in File::Path, a core module from Perl to create or remove directory trees. An attacker can take advantage of this flaw to set the mode on an attacker-chosen file to a attacker-chosen
security update
LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079
LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079
security update
security update
LinuxSecurity.com: Several vulnerabilities were discovered in NSS, a set of cryptographic libraries, which may result in denial of service or information disclosure.
LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, didn’t restrict access to the computationally expensive wchp/wchc commands which could result in denial of service by elevated CPU consumption.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: OpenLDAP could be made to crash if it received specially crafted network traffic.
LinuxSecurity.com: Several security issues were fixed in libsndfile.
LinuxSecurity.com: An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes is now available. is now available.
LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool. They would allow remote attackers to force password resets, and perform various cross-site scripting and cross-site request forgery attacks.
security update
security update
security update
security update
security update
LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]
LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]
LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]
LinuxSecurity.com: Karsten Heymann discovered that the OpenLDAP directory server can be crashed by performing a paged search with a page size of 0, resulting in denial of service. This vulnerability is limited to the MDB storage backend.
LinuxSecurity.com: New sudo packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.
LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.
LinuxSecurity.com: Sudo could be made to overwrite files as the administrator.
LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.
LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
security update
LinuxSecurity.com: It was discovered that pattern-based ACLs in the Mosquitto MQTT broker could be bypassed. For the stable distribution (jessie), this problem has been fixed in
LinuxSecurity.com: A security fix for a systemd-resolved crash on a crafted DNS packet. Relevant only to systemd-resolved users (not enabled by default). No need to reboot or logout.
LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus
LinuxSecurity.com: Fix for CVE-2016-8728 CVE-2016-8729 —- Rebuild with new jbig2dec
LinuxSecurity.com: An issue in `git-shell` could allow remote users to run an interactive pager. From the [update announcement](https://public- inbox.org/git/xmqq8tm5ziat.fsf@gitster.mtv.corp.google.com/): … fix a recently disclosed problem with “git shell”, which may allow a user who comes over SSH to run an interactive pager by causing it to spawn “git
LinuxSecurity.com: strongSwan could be made to crash or hang if it received specially crafted network traffic.
LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.
LinuxSecurity.com: Several security issues were fixed in ImageMagick.
LinuxSecurity.com: USN-3212-1 caused a regression in LibTIFF.
LinuxSecurity.com: Two denial of service vulnerabilities were identified in strongSwan, an IKE/IPsec suite, using Google’s OSS-Fuzz fuzzing project. CVE-2017-9022
LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
security update
security update
LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
LinuxSecurity.com: A vulnerability in Smb4K could allow local attackers to execute commands as root.
LinuxSecurity.com: Teeworlds client vulnerability in snap handling could result in execution of arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could allow for privilege escalation.
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.
LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.
LinuxSecurity.com: Firefox was updated to a new version.
LinuxSecurity.com: New samba packages are available for Slackware 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
LinuxSecurity.com: Samba could be made to run programs as an administrator.
LinuxSecurity.com: Samba could be made to run programs as an administrator.
LinuxSecurity.com: Several security issues were fixed in jbig2dec.
LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.
LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update for samba3x is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Jakub Jirasek of Secunia Research discovered that libtasn1, a library used to handle Abstract Syntax Notation One structures, did not properly validate its input. This would allow an attacker to cause a crash by denial-of-service, or potentially execute arbitrary code, by
LinuxSecurity.com: steelo discovered a remote code execution vulnerability in Samba, a SMB/CIFS file, print, and login server for Unix. A malicious client with access to a writable share, can take advantage of this flaw by uploading a shared library and then cause the server to load and execute it.
LinuxSecurity.com: This updates fixes a security bug in the route manager, to prevent it from overwriting arbitrary files (CVE-2017-8921)
security update
security update
LinuxSecurity.com: An update for rpcbind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
