Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 mercurial-3.7.3-1.fc24 Fedora 24 webkitgtk4-2.12.1-1.fc24 Fedora 23 kernel-4.4.7-300.fc23 Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 Fedora 24 keepassx-0.4.4-1.fc24 Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Community Linux Events Linux […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 mercurial-3.7.3-1.fc24 Fedora 24 webkitgtk4-2.12.1-1.fc24 Fedora 23 kernel-4.4.7-300.fc23 Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 Fedora 24 keepassx-0.4.4-1.fc24 Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Community Linux Events Linux […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 Fedora 24 keepassx-0.4.4-1.fc24 Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Community […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 22 libreswan-3.17-1.fc22 Fedora 24 w3m-0.5.3-24.fc24 Fedora 24 keepassx-0.4.4-1.fc24 Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Community […]
Revert to 0.4.4 for f24+, update to 0.4.4. ——————————————————————————– Fedora Update Notification FEDORA-2016-139a37787e 2016-04-18 17:24:04.550946 ——————————————————————————– Name : keepassx Product : Fedora 24 Version : 0.4.4 Release : 1.fc24 URL : http://keepassx.sourceforge.net Summary : Cross-platform password manager Description : KeePassX is an application for people with extremly high demands on secure personal data management. KeePassX […]
Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF protections and bypass of the SecurityManager. For the oldstable distribution (wheezy), these problems have been fixed in version 7.0.28-4+deb7u4. This update also fixes CVE-2014-0119 and CVE-2014-0096. For the stable distribution (jessie), these […]
Posted by Anthony Pell OptiPNG could be made to crash or run programs as your login if it opened aspecially crafted file. ========================================================================== Ubuntu Security Notice USN-2951-1 April 18, 2016 optipng vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 […]
Posted by Anthony Pell Several security issues were fixed in Samba. ========================================================================== Ubuntu Security Notice USN-2950-1 April 18, 2016 samba vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Samba. Software Description: […]
Posted by Anthony Pell An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0638-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0638.html […]
Posted by Anthony Pell Update to xerces-c 3.1.3, fixing CVE-2016-0729 ——————————————————————————– Fedora Update Notification FEDORA-2016-880b91c090 2016-04-17 23:38:27.306984 ——————————————————————————– Name : xerces-c Product : Fedora 22 Version : 3.1.3 Release : 1.fc22 URL : http://xml.apache.org/xerces-c/ Summary : Validating XML Parser Description : Xerces-C is a validating XML parser written in a portable subset of C++. […]
– New upstream version (45.0.2) ——————————————————————————– Fedora Update Notification FEDORA-2016-0b80c47a4b 2016-04-17 23:39:23.511547 ——————————————————————————– Name : firefox Product : Fedora 23 Version : 45.0.2 Release : 1.fc23 URL : https://www.mozilla.org/projects/firefox/ Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. ——————————————————————————– Update Information: – […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2951-1: OptiPNG vulnerabilities Ubuntu: 2950-1: Samba vulnerabilities Red Hat: 2016:0638-01: chromium-browser: Important Advisory Fedora 22 xerces-c-3.1.3-1.fc22 Fedora 23 firefox-45.0.2-1.fc23 Fedora 24 springframework-amqp-1.3.9-4.fc24 Fedora 24 glpi-0.90.3-1.fc24 Fedora 24 drupal7-block_class-2.3-1.fc24 Community […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3552-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 17, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : tomcat7 CVE ID : CVE-2015-5174 CVE-2015-5345 CVE-2015-5346 CVE-2015-5351 CVE-2016-0706 CVE-2016-0714 CVE-2016-0763 Multiple security vulnerabilities have been discovered in the Tomcat servlet and JSP engine, which may result in information disclosure, the bypass of CSRF […]
Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3551-1 security@debian.org https://www.debian.org/security/ Florian Weimer April 16, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : fuseiso CVE ID : CVE-2015-8836 CVE-2015-8837 Debian Bug : 779047 It was discovered that fuseiso, a user-space implementation of the ISO 9660 file system based on FUSE, contains several […]
It was discovered that fuseiso, a user-space implementation of the ISO 9660 file system based on FUSE, contains several vulnerabilities. CVE-2015-8836 A stack-based buffer overflow may allow attackers who can trick a user into mounting a crafted ISO 9660 file system to cause a denial of service (crash), or, potentially, execute arbitrary code. CVE-2015-8837 An […]
Shayan Sadigh discovered a vulnerability in OpenSSH: If PAM support is enabled and the sshd PAM configuration is configured to read userspecified environment variables and the UseLogin option is enabled, a local user may escalate her privileges to root. In Debian UseLogin is not enabled by default. For the oldstable distribution (wheezy), this problem has […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3549-1 security@debian.org https://www.debian.org/security/ Michael Gilbert April 15, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : chromium-browser CVE ID : CVE-2016-1651 CVE-2016-1652 CVE-2016-1653 CVE-2016-1654 CVE-2016-1655 CVE-2016-1657 CVE-2016-1658 CVE-2016-1659 Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1651 An out-of-bounds read issue was discovered in the pdfium library. CVE-2016-1652 […]
A heap buffer overflow vulnerability was removed from the poppler library. ——————————————————————————– Fedora Update Notification FEDORA-2016-a97dfe609c 2016-04-15 03:13:35.677680 ——————————————————————————– Name : poppler Product : Fedora 23 Version : 0.34.0 Release : 2.fc23 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : Poppler, a PDF rendering library, is a fork of the xpdf PDF viewer […]
Posted by Anthony Pell Rebased to 0.12.1. ——————————————————————————– Fedora Update Notification FEDORA-2016-e6e8436b98 2016-04-15 03:13:35.679696 ——————————————————————————– Name : qpid-proton Product : Fedora 23 Version : 0.12.1 Release : 1.fc23 URL : http://qpid.apache.org/proton/ Summary : A high performance, lightweight messaging library Description : Proton is a high performance, lightweight messaging library. It can be used in […]
Update to 4.8 ——————————————————————————– Fedora Update Notification FEDORA-2016-048ffb6235 2016-04-15 03:16:06.565301 ——————————————————————————– Name : libtasn1 Product : Fedora 24 Version : 4.8 Release : 1.fc24 URL : http://www.gnu.org/software/libtasn1/ Summary : The ASN.1 library used in GNUTLS Description : A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Debian: 3549-1: chromium-browser: Summary Fedora 23 poppler-0.34.0-2.fc23 Fedora 23 qpid-proton-0.12.1-1.fc23 Fedora 24 libtasn1-4.8-1.fc24 Fedora 24 cryptopp-5.6.3-3.fc24 Fedora 24 samba-4.4.2-1.fc24 Debian: 3548-2: samba: Summary Fedora 22 samba-4.2.11-0.fc22 Community Linux Events Linux […]
Posted by Anthony Pell Security fix for CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118 ——————————————————————————– Fedora Update Notification FEDORA-2016-383fce04e2 2016-04-15 03:16:06.564657 ——————————————————————————– Name : samba Product : Fedora 24 Version : 4.4.2 Release : 1.fc24 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1651 An out-of-bounds read issue was discovered in the pdfium library. CVE-2016-1652 A cross-site scripting issue was discovered in extension bindings. CVE-2016-1653 Choongwoo Han discovered an out-of-bounds write issue in the v8 javascript library. CVE-2016-1654 Atte Kettunen discovered an uninitialized memory read condition. CVE-2016-1655 Rob […]
Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2015-5370 Jouni Knuutinen from Synopsys discovered flaws in the Samba DCE-RPC code which can lead to denial of service (crashes and high cpu consumption) and man-in-the-middle attacks. CVE-2016-2110 Stefan […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3548-2 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 14, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : samba Debian Bug : 820947 The upgrade to Samba 4.2 issued as DSA-3548-1 introduced a packaging regression causing an additional dependency on the samba binary package for the samba-libs, samba-common-bin, python-samba and samba-vfs-modules binary […]
Posted by Anthony Pell Security fix for CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118 ——————————————————————————– Fedora Update Notification FEDORA-2016-48b3761baa 2016-04-14 00:52:48.149054 ——————————————————————————– Name : samba Product : Fedora 22 Version : 4.2.11 Release : 0.fc22 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the […]
Posted by Anthony Pell Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3548-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 13, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : samba CVE ID : CVE-2015-5370 CVE-2016-2110 CVE-2016-2111 CVE-2016-2112 CVE-2016-2113 CVE-2016-2114 CVE-2016-2115 CVE-2016-2118 Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The […]
Posted by Anthony Pell Security fix for CVE-2015-5370, CVE-2016-2110, CVE-2016-2111, CVE-2016-2112,CVE-2016-2113, CVE-2016-2114, CVE-2016-2115, CVE-2016-2118 ——————————————————————————– Fedora Update Notification FEDORA-2016-be53260726 2016-04-13 16:54:31.873262 ——————————————————————————– Name : samba Product : Fedora 23 Version : 4.3.8 Release : 0.fc23 URL : http://www.samba.org/ Summary : Server and Client software to interoperate with Windows machines Description : Samba is the […]
Posted by Anthony Pell Rebase to the new upstream bugfix-only version. Add security fixes for thereferenced bugs. ——————————————————————————– Fedora Update Notification FEDORA-2016-f8eee2e628 2016-04-13 03:26:08.777154 ——————————————————————————– Name : imlib2 Product : Fedora 23 Version : 1.4.8 Release : 1.fc23 URL : http://docs.enlightenment.org/api/imlib2/html/ Summary : Image loading, saving, rendering, and manipulation library Description : Imlib 2 […]
Posted by Anthony Pell Update to xerces-c 3.1.3, fixing CVE-2016-0729 ——————————————————————————– Fedora Update Notification FEDORA-2016-ae9ac16cf3 2016-04-13 03:26:08.776399 ——————————————————————————– Name : xerces-c Product : Fedora 23 Version : 3.1.3 Release : 1.fc23 URL : http://xml.apache.org/xerces-c/ Summary : Validating XML Parser Description : Xerces-C is a validating XML parser written in a portable subset of C++. […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 23 imlib2-1.4.8-1.fc23 Fedora 23 xerces-c-3.1.3-1.fc23 Fedora 23 libreswan-3.17-1.fc23 Red Hat: 2016:0612-01: samba and samba4: Critical Advisory Red Hat: 2016:0618-01: samba: Critical Advisory Red Hat: 2016:0625-01: samba: Important Advisory Red […]
An update for samba4 and samba is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7, respectively. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba and samba4 security, bug fix, and enhancement update Advisory ID: RHSA-2016:0612-01 […]
An update for samba is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba security, bug fix, and enhancement update Advisory ID: RHSA-2016:0618-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0618.html […]
An update for samba is now available for Red Hat Enterprise Linux 4 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: samba security update Advisory ID: RHSA-2016:0625-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0625.html Issue date: 2016-04-12 CVE […]
An update for samba4 is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba4 security, bug fix, and enhancement […]
An update for samba3x is now available for Red Hat Enterprise Linux 5.6 Long Life and Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba3x security update Advisory ID: RHSA-2016:0624-01 Product: Red Hat Enterprise Linux […]
An update for samba is now available for Red Hat Enterprise Linux 5.6 Long Life and Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: samba security update Advisory ID: RHSA-2016:0623-01 Product: Red Hat Enterprise Linux […]
An update for samba is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, and Red Hat Enterprise Linux 6.6 Extended Update Support. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba security update Advisory ID: RHSA-2016:0619-01 […]
An update for samba is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba security update Advisory ID: RHSA-2016:0611-01 Product: Red Hat Enterprise […]
An update for samba3x is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: samba3x security update Advisory ID: RHSA-2016:0613-01 Product: Red Hat Enterprise […]
Several vulnerabilities were discovered in Imagemagick, a program suite for image manipulation. This update fixes a large number of potential security problems such as null-pointer access and buffer-overflows that might lead to memory leaks or denial of service. None of these security problems have a CVE number assigned. For the oldstable distribution (wheezy), this problem […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
Posted by Anthony Pell Update to xerces-c 3.1.3, fixing CVE-2016-0729 ——————————————————————————– Fedora Update Notification FEDORA-2016-9ff972ca42 2016-04-12 09:36:30.965273 ——————————————————————————– Name : xerces-c Product : Fedora 24 Version : 3.1.3 Release : 1.fc24 URL : http://xml.apache.org/xerces-c/ Summary : Validating XML Parser Description : Xerces-C is a validating XML parser written in a portable subset of C++. […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
An update for kernel is now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: kernel security and bug fix update Advisory ID: RHSA-2016:0617-01 Product: Red Hat Enterprise Linux Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0617.html Issue […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3485-2 security@debian.org https://www.debian.org/security/ Sebastien Delafond April 12, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : didiwiki Debian Bug : 818708 The update for didiwiki issued as DSA-3485-1 introduced a regression that caused a large number of valid pages to not be accessible anymore. This occurred mostly for pages whose […]
Updated openvswitch packages that fix one security issue are now available for Red Hat OpenShift Enterprise 3.1. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openvswitch security update Advisory ID: RHSA-2016:0615-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2016:0615 Issue date: 2016-04-11 CVE […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 postgresql-9.5.2-1.fc24 Fedora 24 xerces-c-3.1.3-1.fc24 Fedora 24 libreswan-3.17-1.fc24 Red Hat: 2016:0617-01: kernel: Moderate Advisory Debian: 3485-2: didiwiki: Summary Red Hat: 2016:0615-01: openvswitch: Important Advisory Ubuntu: 2948-2: Linux kernel (Utopic […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3547-1 security@debian.org https://www.debian.org/security/ Luciano Bello April 11, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : imagemagick Debian Bug : 811308 Several vulnerabilities were discovered in Imagemagick, a program suite for image manipulation. This update fixes a large number of potential security problems such as null-pointer access and buffer-overflows that […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Update to 2.8.2 for CVE-2016-3095. ——————————————————————————– Fedora Update Notification FEDORA-2016-f75bd73891 2016-04-11 09:11:06.297385 ——————————————————————————– Name : pulp Product : Fedora 24 Version : 2.8.2 Release : 1.fc24 URL : https://github.com/pulp/pulp Summary : An application for managing software repositories Description : Pulp provides replication, access, and accounting for software repositories. ——————————————————————————– Update Information: Update to 2.8.2 for […]
This update fixes an integer overflow in Jpeg2KEncode.c causing a bufferoverflow (CVE-2016-3076). ——————————————————————————– Fedora Update Notification FEDORA-2016-35700c5956 2016-04-10 10:23:15.141497 ——————————————————————————– Name : python-pillow Product : Fedora 23 Version : 3.0.0 Release : 4.fc23 URL : http://python-pillow.github.io/ Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) […]
This update fixes an integer overflow in Jpeg2KEncode.c causing a bufferoverflow (CVE-2016-3076). ——————————————————————————– Fedora Update Notification FEDORA-2016-6ad4474058 2016-04-10 10:18:57.729299 ——————————————————————————– Name : python-pillow Product : Fedora 22 Version : 2.8.2 Release : 5.fc22 URL : http://python-pillow.github.io/ Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) […]
update to 4.5.3 —- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172,CVE-2016-3158, CVE-2016-3159] ——————————————————————————– Fedora Update Notification FEDORA-2016-e5432ca977 2016-04-09 10:22:58.046533 ——————————————————————————– Name : xen Product : Fedora 23 Version : 4.5.3 Release : 1.fc23 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command […]
Update to 2.3.10 for CVE-2015-8106 ——————————————————————————– Fedora Update Notification FEDORA-2016-b9368247d4 2016-04-09 10:22:58.046350 ——————————————————————————– Name : latex2rtf Product : Fedora 23 Version : 2.3.10 Release : 1.fc23 URL : http://latex2rtf.sourceforge.net/ Summary : LaTeX to RTF converter that handles equations, figures, and cross-references Description : LaTeX2rtf is a translator program which is intended to translate a LaTeX […]
Posted by Anthony Pell 31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Posted by Anthony Pell 31 Mar 2016, **PHP 5.6.20** **CLI Server:** * Fixed bug php#69953 (SupportMKCALENDAR request method). (Christoph) **Core:** * Fixed bug php#71596(Segmentation fault on ZTS with date function (setlocale)). (Anatol) **Curl:*** Fixed bug php#71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) **Date:*** Fixed bug php#71635 (DatePeriod::getEndDate segfault). (Thomas Punt)**Fileinfo:** * Fixed bug php#71527 (Buffer over-write […]
update to 4.5.3 —- broken AMD FPU FIP/FDP/FOP leak workaround [XSA-172,CVE-2016-3158, CVE-2016-3159] ——————————————————————————– Fedora Update Notification FEDORA-2016-5f196e4e4a 2016-04-09 10:20:41.903381 ——————————————————————————– Name : xen Product : Fedora 22 Version : 4.5.3 Release : 1.fc22 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Fedora 24 pulp-rpm-2.8.2-1.fc24 Fedora 24 pulp-puppet-2.8.2-1.fc24 Fedora 24 pulp-2.8.2-1.fc24 Fedora 23 python-pillow-3.0.0-4.fc23 Fedora 22 python-pillow-2.8.2-5.fc22 Fedora 23 xen-4.5.3-1.fc23 Fedora 23 latex2rtf-2.3.10-1.fc23 Fedora 23 php-5.6.20-1.fc23 Community Linux Events Linux User Groups […]
Hans Jerry Illikainen discovered that missing input sanitising in the BMP processing code of the optipng PNG optimiser may result in denial of service or the execution of arbitrary code if a malformed file is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 0.6.4-1+deb7u2. This update also fixes CVE-2015-7801, which […]
An update for flash-plugin is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: flash-plugin security update Advisory ID: RHSA-2016:0610-01 Product: Red Hat Enterprise Linux Supplementary Advisory […]
USN-2917-1 introduced several regressions in Firefox. ========================================================================== Ubuntu Security Notice USN-2917-2 April 07, 2016 firefox regressions ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: USN-2917-1 introduced several regressions in Firefox. Software Description: – firefox: Mozilla Open Source web browser […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3546-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : optipng CVE ID : CVE-2016-2191 Hans Jerry Illikainen discovered that missing input sanitising in the BMP processing code of the optipng PNG optimiser may result in denial of service or the execution of arbitrary […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3545-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : cgit CVE ID : CVE-2016-1899 CVE-2016-1900 CVE-2016-1901 Debian Bug : 812411 Several vulnerabilities were discovered in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of […]
Security Report Summary – ————————————————————————- Debian Security Advisory DSA-3544-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso April 07, 2016 https://www.debian.org/security/faq – ————————————————————————- Package : python-django CVE ID : CVE-2016-2512 CVE-2016-2513 Debian Bug : 816434 Several vulnerabilities were discovered in Django, a high-level Python web development framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2512 Mark […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0610-01: flash-plugin: Critical Advisory Ubuntu: 2917-2: Firefox regressions Debian: 3546-1: optipng: Summary Debian: 3545-1: cgit: Summary Debian: 3544-1: python-django: Summary Fedora 23 libmaxminddb-1.2.0-1.fc23 Fedora 23 mercurial-3.5.2-1.fc23 Fedora 22 […]
Security fix for CVE-2016-3630, CVE-2016-3068, CVE-2016-3069 and minor upgrade ——————————————————————————– Fedora Update Notification FEDORA-2016-b7f1f8e3bf 2016-04-07 12:06:32.149355 ——————————————————————————– Name : mercurial Product : Fedora 23 Version : 3.5.2 Release : 1.fc23 URL : http://www.selenic.com/mercurial/ Summary : Mercurial — a distributed SCM Description : Mercurial is a fast, lightweight source control management system designed for efficient handling […]
New upstream release with security bug fix ——————————————————————————– Fedora Update Notification FEDORA-2016-15fb7deba0 2016-04-07 12:06:06.793002 ——————————————————————————– Name : python-rsa Product : Fedora 22 Version : 3.4.1 Release : 1.fc22 URL : http://stuvel.eu/rsa Summary : Pure-Python RSA implementation Description : Python-RSA is a pure-Python RSA implementation. It supports encryption and decryption, signing and verifying signatures, and key […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Red Hat: 2016:0610-01: flash-plugin: Critical Advisory Ubuntu: 2917-2: Firefox regressions Debian: 3546-1: optipng: Summary Debian: 3545-1: cgit: Summary Debian: 3544-1: python-django: Summary Fedora 23 libmaxminddb-1.2.0-1.fc23 Fedora 23 mercurial-3.5.2-1.fc23 Fedora 22 […]
Security fix for CVE-2016-3630, CVE-2016-3068, CVE-2016-3069 and minor upgrade ——————————————————————————– Fedora Update Notification FEDORA-2016-79604dde9f 2016-04-07 12:06:06.791542 ——————————————————————————– Name : mercurial Product : Fedora 22 Version : 3.5.2 Release : 1.fc22 URL : http://www.selenic.com/mercurial/ Summary : Mercurial — a distributed SCM Description : Mercurial is a fast, lightweight source control management system designed for efficient handling […]
