Debian: 3592-1: nginx: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3592-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : nginx CVE ID : CVE-2016-4450 It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a […]
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1190-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2016:1190 Issue date: 2016-06-01 CVE Names: […]
Debian: 3591-1: imagemagick: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3591-1 security@debian.org https://www.debian.org/security/ Luciano Bello June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick CVE ID : CVE-2016-5118 Debian Bug : 825799 Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite […]
Ubuntu: 2989-1: Linux kernel vulnerabilities Posted by Anthony Pell Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2989-1 June 01, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: […]
Debian: 3590-1: chromium-browser: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3590-1 security@debian.org https://www.debian.org/security/ Michael Gilbert June 01, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1667 CVE-2016-1668 CVE-2016-1669 CVE-2016-1670 CVE-2016-1672 CVE-2016-1673 CVE-2016-1674 CVE-2016-1675 CVE-2016-1676 CVE-2016-1677 CVE-2016-1678 CVE-2016-1679 CVE-2016-1680 CVE-2016-1681 CVE-2016-1682 CVE-2016-1683 CVE-2016-1684 CVE-2016-1685 CVE-2016-1686 CVE-2016-1687 CVE-2016-1688 […]
Ubuntu: 2988-1: LXD vulnerabilities Posted by Anthony Pell Several security issues were fixed in LXD. ========================================================================== Ubuntu Security Notice USN-2988-1 May 31, 2016 lxd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 Summary: Several security issues were fixed in LXD. Software Description: […]
Ubuntu: 2987-1: GD library vulnerabilities Posted by Anthony Pell The GD library could be made to crash or run programs if it processed aspecially crafted image file. ========================================================================== Ubuntu Security Notice USN-2987-1 May 31, 2016 libgd2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – […]
Ubuntu: 2986-1: dosfstools vulnerabilities Posted by Anthony Pell dosfstools could be made to crash or run programs if it processed aspecially crafted filesystem. ========================================================================== Ubuntu Security Notice USN-2986-1 May 31, 2016 dosfstools vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1667 Mariusz Mylinski discovered a cross-origin bypass. CVE-2016-1668 Mariusz Mylinski discovered a cross-origin bypass in bindings to v8. CVE-2016-1669 Choongwoo Han discovered a buffer overflow in the v8 javascript library. CVE-2016-1670 A race condition was found that could cause the renderer process to reuse ids […]
Bob Friesenhahn from the GraphicsMagick project discovered a command injection vulnerability in ImageMagick, a program suite for image manipulation. An attacker with control on input image or the input filename can execute arbitrary commands with the privileges of the user running the application. This update removes the possibility of using pipe (|) in filenames to […]
It was discovered that a NULL pointer dereference in the Nginx code responsible for saving client request bodies to a temporary file might result in denial of service: Malformed requests could crash worker processes. For the stable distribution (jessie), this problem has been fixed in version 1.6.2-5+deb8u2. For the unstable distribution (sid), this problem has […]
Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using gdk-pixbuf (application crash), or potentially, to execute arbitrary code with the privileges of the user running the application, if a malformed image […]
An update for ntp is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: ntp security update Advisory ID: RHSA-2016:1141-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1141 Issue […]
Slackware: 2016-152-01: imagemagick: Security Update Posted by Anthony Pell New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] imagemagick (SSA:2016-152-01) New imagemagick packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 […]
Slackware: 2016-152-02: mozilla-thunderbird: Security Update Posted by Anthony Pell New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. [More Info…] [slackware-security] mozilla-thunderbird (SSA:2016-152-02) New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ patches/packages/mozilla-thunderbird-45.1.1-i486-1_slack14.1.txz: Upgraded. […]
An update for squid is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid security update Advisory ID: RHSA-2016:1139-01 Product: Red Hat Enterprise […]
An update for squid is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid security update Advisory ID: RHSA-2016:1138-01 Product: Red Hat Enterprise […]
An update for squid34 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: squid34 security update Advisory ID: RHSA-2016:1140-01 Product: Red Hat Enterprise […]
Multiple vulnerabilities have been found in Firefox, Thunderbird, Network Security Services (NSS), and NetScape Portable Runtime (NSPR) with the worst of which may allow remote execution of arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Gentoo: 201605-05 Linux-PAM: Multiple vulnerabilities Posted by Anthony Pell Multiple vulnerabilities have been found in Linux-PAM, allowing remote attackers to bypass the auth process and cause Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – […]
Gentoo: 201605-04 rsync: Multiple vulnerabilities Posted by Anthony Pell Multiple vulnerabilities have been found in rsync, the worst of which could allow remote attackers to write arbitrary files. – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Gentoo: 201605-03 libfpx: Denial of Service Posted by Anthony Pell A double free vulnerability has been discovered in libfpx that allows remote attackers to cause a Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – […]
Debian: 3589-1: gdk-pixbuf: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3589-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 30, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : gdk-pixbuf CVE ID : CVE-2015-7552 CVE-2015-8875 Several vulnerabilities have been discovered in gdk-pixbuf, a toolkit for image loading and pixel buffer manipulation. A remote attacker […]
Debian: 3588-1: symfony: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3588-1 security@debian.org https://www.debian.org/security/ Luciano Bello May 29, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : symfony CVE ID : CVE-2016-1902 CVE-2016-4423 Two vulnerabilities were discovered in Symfony, a PHP framework. CVE-2016-1902 Lander Brandt discovered that the class SecureRandom might generate […]
Two vulnerabilities were discovered in Symfony, a PHP framework. CVE-2016-1902 Lander Brandt discovered that the class SecureRandom might generate weak random numbers for cryptographic use under certain settings. If the functions random_bytes() or openssl_random_pseudo_bytes() are not available, the output of SecureRandom should not be consider secure. CVE-2016-4423 Marek Alaksa from Citadelo discovered that it is […]
Ubuntu: 2985-2: GNU C Library regression Posted by Anthony Pell USN-2985-1 introduced a regression in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-2 May 26, 2016 eglibc, glibc regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: […]
Several vulnerabilities were discovered in libgd2, a library for programmatic graphics creation and manipulation. A remote attacker can take advantage of these flaws to cause a denial-of-service against an application using the libgd2 library. For the stable distribution (jessie), these problems have been fixed in version 2.1.0-5+deb8u3. For the unstable distribution (sid), these problems have […]
An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: rh-mariadb100-mariadb security update Advisory ID: RHSA-2016:1132-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2016:1132 Issue date: 2016-05-26 CVE Names: CVE-2015-3210 CVE-2015-3217 CVE-2015-4792 […]
Ubuntu: 2985-1: GNU C Library vulnerabilities Posted by Anthony Pell Several security issues were fixed in the GNU C Library. ========================================================================== Ubuntu Security Notice USN-2985-1 May 25, 2016 eglibc, glibc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS […]
Ubuntu: 2950-5: Samba regression Posted by Anthony Pell USN-2950-1 introduced a regression in Samba. ========================================================================== Ubuntu Security Notice USN-2950-5 May 25, 2016 samba regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS Summary: USN-2950-1 introduced a regression in Samba. […]
Slackware: 2016-145-01: libarchive: Security Update Posted by Anthony Pell New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. [More Info…] [slackware-security] libarchive (SSA:2016-145-01) New libarchive packages are available for Slackware 14.1 and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +————————–+ […]
Red Hat: 2016:1106-01: jq: Moderate Advisory Posted by Anthony Pell An update for jq is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory ID: RHSA-2016:1106-01 Product: Red Hat […]
Several security issues were fixed in PHP. ========================================================================== Ubuntu Security Notice USN-2984-1 May 24, 2016 php5, php7.0 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in PHP. Software Description: […]
An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security, bug fix, and enhancement update Advisory ID: RHSA-2016:1100-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1100.html […]
It was discovered that a buffer overflow in the XMLRPC response encoding code of the Atheme IRC services may result in denial of service. For the stable distribution (jessie), this problem has been fixed in version 6.0.11-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 7.0.7-2. For the unstable distribution (sid), […]
Red Hat: 2016:1098-01: jq: Moderate Advisory Posted by Anthony Pell An update for jq is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory […]
Red Hat: 2016:1099-01: jq: Moderate Advisory Posted by Anthony Pell An update for jq is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: jq security update Advisory […]
Debian: 3586-1: atheme-services: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3586-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 23, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : atheme-services CVE ID : CVE-2016-4478 It was discovered that a buffer overflow in the XMLRPC response encoding code of the Atheme IRC services may result […]
An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:1096-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1096.html Issue […]
Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which could result in denial of service. For the stable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u6. For the testing distribution (stretch), these problems have been fixed in version 2.0.3+geed34f0-1. For the unstable distribution (sid), these problems have […]
Debian: 3585-1: wireshark: Summary Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3585-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 22, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : wireshark CVE ID : CVE-2016-4006 CVE-2016-4079 CVE-2016-4080 CVE-2016-4081 CVE-2016-4082 CVE-2016-4085 Multiple vulnerabilities were discovered in the dissectors/parsers for PKTC, IAX2, GSM CBCH and NCP which […]
Slackware: 2016-141-01: curl: Security Update Posted by Anthony Pell New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info…] [slackware-security] curl (SSA:2016-141-01) New curl packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are […]
Gustavo Grieco discovered several flaws in the way librsvg, a SAX-based renderer library for SVG files, parses SVG files with circular definitions. A remote attacker can take advantage of these flaws to cause an application using the librsvg library to crash. For the stable distribution (jessie), these problems have been fixed in version 2.40.5-1+deb8u2. For […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3584-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 19, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : librsvg CVE ID : CVE-2015-7558 CVE-2016-4347 CVE-2016-4348 Gustavo Grieco discovered several flaws in the way librsvg, a SAX-based renderer library for SVG files, parses SVG files with circular definitions. A remote attacker can take […]
It was discovered that the swift3 (S3 compatibility) middleware plugin for Swift performed insufficient validation of date headers which might result in replay attacks. For the stable distribution (jessie), this problem has been fixed in version 1.7-5+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1.9-1. For the unstable distribution (sid), […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3583-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : swift-plugin-s3 CVE ID : CVE-2015-8466 Debian Bug : 822688 It was discovered that the swift3 (S3 compatibility) middleware plugin for Swift performed insufficient validation of date headers which might result in replay attacks. For […]
Posted by Anthony Pell USN-2950-1 introduced regressions in Samba. ========================================================================== Ubuntu Security Notice USN-2950-4 May 18, 2016 samba regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 LTS Summary: USN-2950-1 introduced regressions in Samba. Software Description: – samba: SMB/CIFS file, print, and login server for Unix Details: […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2950-4: Samba regressions Ubuntu: 2983-1: Expat vulnerability Debian: 3582-1: expat: Summary Ubuntu: 2982-1: Libksba vulnerabilities Ubuntu: 2981-1: libarchive vulnerabilities Ubuntu: 2980-1: libndp vulnerability Debian: 3581-1: libndp: Summary Gentoo: 201605-02 […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3582-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 18, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : expat CVE ID : CVE-2016-0718 Gustavo Grieco discovered that Expat, an XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. […]
Posted by Anthony Pell Libksba could be made to crash or run programs if it decoded speciallycrafted data. ========================================================================== Ubuntu Security Notice USN-2982-1 May 17, 2016 libksba vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 […]
libarchive could be made to crash or run programs if it opened a speciallycrafted file. ========================================================================== Ubuntu Security Notice USN-2981-1 May 17, 2016 libarchive vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: libarchive could […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2950-4: Samba regressions Ubuntu: 2983-1: Expat vulnerability Debian: 3582-1: expat: Summary Ubuntu: 2982-1: Libksba vulnerabilities Ubuntu: 2981-1: libarchive vulnerabilities Ubuntu: 2980-1: libndp vulnerability Debian: 3581-1: libndp: Summary Gentoo: 201605-02 […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3581-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libndp CVE ID : CVE-2016-3698 Debian Bug : 824545 Julien Bernard discovered that libndp, a library for the IPv6 Neighbor Discovery Protocol, does not properly perform input and origin checks during the reception of […]
Posted by Anthony Pell Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2978-2 May 16, 2016 linux-lts-wily vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-wily: Linux hardware enablement kernel from Wily for Trusty […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2978-1 May 16, 2016 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 Summary: Several security issues were fixed in the kernel. Software Description: – linux: Linux kernel Details: David Matlack discovered that the Kernel-based […]
The system could be made to crash or run programs as an administrator. ========================================================================== Ubuntu Security Notice USN-2979-4 May 16, 2016 linux-snapdragon vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 16.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: […]
Several security issues were fixed in the kernel. ========================================================================== Ubuntu Security Notice USN-2979-2 May 16, 2016 linux-lts-xenial vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: – linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty […]
Gustavo Grieco discovered that Expat, an XML parsing C library, does not properly handle certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. A remote attacker can take advantage of this flaw to cause an application using the Expat library to crash, or potentially, to execute arbitrary code with […]
Nikolay Ermishkin from the Mail.Ru Security Team and Stewie discovered several vulnerabilities in ImageMagick, a program suite for image manipulation. These vulnerabilities, collectively known as ImageTragick, are the consequence of lack of sanitization of untrusted input. An attacker with control on the image input could, with the privileges of the user running the application, execute […]
Julien Bernard discovered that libndp, a library for the IPv6 Neighbor Discovery Protocol, does not properly perform input and origin checks during the reception of a NDP message. An attacker in a non-local network could use this flaw to advertise a node as a router, and cause a denial of service attack, or act as […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3579-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 16, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : xerces-c CVE ID : CVE-2016-2099 Debian Bug : 823863 Gustavo Grieco discovered an use-after-free vulnerability in xerces-c, a validating XML parser library for C++, due to not properly handling invalid characters in XML input […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3578-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini May 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libidn CVE ID : CVE-2015-2059 It was discovered that libidn, the GNU library for Internationalized Domain Names (IDNs), did not correctly handle invalid UTF-8 input, causing an out-of-bounds read. This could allow attackers to […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3577-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini May 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : jansson CVE ID : CVE-2016-4425 Debian Bug : 823238 Gustavo Grieco discovered that jansson, a C library for encoding, decoding and manipulating JSON data, did not limit the recursion depth when parsing JSON arrays […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3576-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : icedove CVE ID : CVE-2016-1979 CVE-2016-2805 CVE-2016-2807 Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary […]
Gustavo Grieco discovered an use-after-free vulnerability in xerces-c, a validating XML parser library for C++, due to not properly handling invalid characters in XML input documents in the DTDScanner. For the stable distribution (jessie), this problem has been fixed in version 3.1.1-5.1+deb8u2. For the testing distribution (stretch), this problem has been fixed in version 3.1.3+debian-2. […]
It was discovered that libidn, the GNU library for Internationalized Domain Names (IDNs), did not correctly handle invalid UTF-8 input, causing an out-of-bounds read. This could allow attackers to disclose sensitive information from an application using the libidn library. For the stable distribution (jessie), this problem has been fixed in version 1.29-1+deb8u1. For the testing […]
Gustavo Grieco discovered that jansson, a C library for encoding, decoding and manipulating JSON data, did not limit the recursion depth when parsing JSON arrays and objects. This could allow remote attackers to cause a denial of service (crash) via stack exhaustion, using crafted JSON data. For the stable distribution (jessie), this problem has been […]
Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service. For the stable distribution (jessie), these problems have been fixed in version 38.8.0-1~deb8u1. For the unstable distribution (sid), these problems will be fixed […]
It was discovered that XStream, a Java library to serialize objects to XML and back again, was susceptible to XML External Entity attacks. For the stable distribution (jessie), this problem has been fixed in version 1.4.7-2+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 1.4.9-1. For the unstable distribution (sid), this […]
Posted by Anthony Pell An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:1080-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-1080.html […]
An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:1079-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3575-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 12, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : libxstream-java CVE ID : CVE-2016-3674 It was discovered that XStream, a Java library to serialize objects to XML and back again, was susceptible to XML External Entity attacks. For the stable distribution (jessie), this […]
