Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Debian: 3513-1: chromium-browser: Summary Red Hat: 2016:0428-01: libssh2: Moderate Advisory Red Hat: 2016:0429-01: chromium-browser: Important Advisory Slackware: 2016-069-02: mozilla-nss: Security Update Slackware: 2016-069-01: bind: Security Update Debian: 3512-1: libotr: Summary […]
This is an update to 5.6.29 that delivers also all fixes for CVE-2015-4766,CVE-2015-4791, CVE-2015-4792, CVE-2015-4800, CVE-2015-4802, CVE-2015-4807,CVE-2015-4815, CVE-2015-4819, CVE-2015-4826, CVE-2015-4830, CVE-2015-4833,CVE-2015-4836, CVE-2015-4858, CVE-2015-4861, CVE-2015-4862, CVE-2015-4864,CVE-2015-4866, CVE-2015-4870, CVE-2015-4879, CVE-2015-4890, CVE-2015-4895,CVE-2015-4904, CVE-2015-4905, CVE-2015-4910, CVE-2015-4913, CVE-2015-7744,CVE-2016-0502, CVE-2016-0503, CVE-2016-0504, CVE-2016-0505, CVE-2016-0546,CVE-2016-0594, CVE-2016-0595, CVE-2016-0596, CVE-2016-0597, CVE-2016-0598,CVE-2016-0599, CVE-2016-0600, CVE-2016-0601, CVE-2016-0605, CVE-2016-0606,CVE-2016-0607, CVE-2016-0608, CVE-2016-0609, CVE-2016-0610, CVE-2016-0611,CVE-2016-0616 (some of them were fixed in […]
Fix CVE-2015-7758 (rhbz#1270816, rhbz#1270816) ——————————————————————————– Fedora Update Notification FEDORA-2016-94b0b50351 2016-03-09 20:10:53.639868 ——————————————————————————– Name : gummi Product : Fedora 23 Version : 0.6.6 Release : 1.fc23 URL : http://gummi.midnightcoding.org Summary : A simple LaTeX editor Description : Gummi is a LaTeX editor written in the C programming language using the GTK+ interface toolkit. It was designed […]
https://www.drupal.org/SA-CORE-2016-001 ——————————————————————————– Fedora Update Notification FEDORA-2016-eeb0f0c94f 2016-03-09 20:10:53.638976 ——————————————————————————– Name : drupal7 Product : Fedora 23 Version : 7.43 Release : 1.fc23 URL : http://www.drupal.org Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1643 cloudfuzzer discovered a type confusion issue in Blink/Webkit. CVE-2016-1644 Atte Kettunen discovered a use-after-free issue in Blink/Webkit. CVE-2016-1645 An out-of-bounds write issue was discovered in the pdfium library. For the stable distribution (jessie), these problems have been fixed in version 49.0.2623.87-1~deb8u1. For the testing […]
Posted by Anthony Pell Multiple vulnerabilities have been found in Roundcube allowing remote authenticated users to execute arbitrary code, inject arbitrary web scripts, and perform cross-site scripting (XSS). – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Posted by Anthony Pell Updated nss packages that fix one security issue are now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having Critical security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: nss security update Advisory ID: RHSA-2016:0371-01 Product: Red Hat Enterprise Linux Advisory URL: […]
Posted by Anthony Pell Updated nss-util packages that fix one security issue are now available for Red Hat Enterprise 6 and 7. Red Hat Product Security has rated this update as having Critical security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Critical: nss-util security update Advisory ID: RHSA-2016:0370-01 Product: Red Hat Enterprise Linux Advisory […]
Posted by Anthony Pell Updated rabbitmq-server packages that fix two security issues and one bug are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rabbitmq-server security and bug fix update Advisory ID: RHSA-2016:0369-01 Product: Red Hat Enterprise Linux OpenStack Platform […]
Posted by Anthony Pell Updated rabbitmq-server packages that fix two security issues are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rabbitmq-server security update Advisory ID: RHSA-2016:0368-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0368.html Issue date: 2016-03-08 […]
Posted by Anthony Pell Updated rabbitmq-server packages that fix two security issues are now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rabbitmq-server security and bugfix update Advisory ID: RHSA-2016:0367-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0367.html Issue […]
Posted by Anthony Pell Updated openstack-nova packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openstack-nova security update Advisory ID: RHSA-2016:0365-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0365.html Issue date: 2016-03-08 […]
Posted by Anthony Pell Updated openstack-nova packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openstack-nova security update Advisory ID: RHSA-2016:0366-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0366.html Issue date: 2016-03-08 […]
Posted by Anthony Pell Updated openstack-nova packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openstack-nova security update Advisory ID: RHSA-2016:0363-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0363.html Issue date: 2016-03-08 […]
Posted by Anthony Pell Updated openstack-nova packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: openstack-nova security update Advisory ID: RHSA-2016:0364-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0364.html Issue date: 2016-03-08 […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Gentoo: 201603-03 Roundcube: Multiple Vulnerabilities Red Hat: 2016:0371-01: nss: Critical Advisory Red Hat: 2016:0370-01: nss-util: Critical Advisory Red Hat: 2016:0369-01: rabbitmq-server: Moderate Advisory Red Hat: 2016:0368-01: rabbitmq-server: Moderate Advisory Red […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Gentoo: 201603-03 Roundcube: Multiple Vulnerabilities Red Hat: 2016:0371-01: nss: Critical Advisory Red Hat: 2016:0370-01: nss-util: Critical Advisory Red Hat: 2016:0369-01: rabbitmq-server: Moderate Advisory Red Hat: 2016:0368-01: rabbitmq-server: Moderate Advisory Red […]
Posted by Anthony Pell Several security issues were fixed in Thunderbird. ========================================================================== Ubuntu Security Notice USN-2904-1 March 08, 2016 thunderbird vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Thunderbird. Software Description: […]
Updated python-django packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 7.0 Operational Tools. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0360-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0360.html Issue date: 2016-03-08 CVE Names: CVE-2015-8213 ===================================================================== 1. Summary: Updated […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]
Several security issues were fixed in Squid. ========================================================================== Ubuntu Security Notice USN-2921-1 March 07, 2016 squid3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 15.10 – Ubuntu 14.04 LTS – Ubuntu 12.04 LTS Summary: Several security issues were fixed in Squid. Software Description: – squid3: Web proxy cache […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]
Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security [More…] ===================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:0359-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0359.html Issue date: […]
Posted by Anthony Pell Updated openstack-glance packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. [More…] ===================================================================== Red Hat Security Advisory Synopsis: Low: openstack-glance security update Advisory ID: RHSA-2016:0358-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://rhn.redhat.com/errata/RHSA-2016-0358.html Issue date: 2016-03-07 […]
x86: inconsistent cachability flags on guest mappings [XSA-154, CVE-2016-2270](#1309324) VMX: guest user mode may crash guest with non-canonical RIP [XSA-170,CVE-2016-2271] (#1309323) ——————————————————————————– Fedora Update Notification FEDORA-2016-f8121efdac 2016-03-06 19:17:26.629611 ——————————————————————————– Name : xen Product : Fedora 22 Version : 4.5.2 Release : 8.fc22 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : […]
Avoid possible XML entity expansion security issue. ——————————————————————————– Fedora Update Notification FEDORA-2016-ff39572e31 2016-03-06 19:17:26.629243 ——————————————————————————– Name : exiv2 Product : Fedora 22 Version : 0.24 Release : 5.fc22 URL : http://www.exiv2.org/ Summary : Exif and Iptc metadata manipulation library Description : A command line utility to access image metadata, allowing one to: * print the […]
Welcome! Sign up! EnGarde Community Login Polls What is the most important Linux security technology? SELinux grsecurity CIS Benchmark Bastille Linux iptables LIDS Advisories Ubuntu: 2904-1: Thunderbird vulnerabilities Red Hat: 2016:0360-01: python-django: Moderate Advisory Slackware: 2016-067-01: php: Security Update Ubuntu: 2915-3: Django regression Ubuntu: 2921-1: Squid vulnerabilities Ubuntu: 2915-2: Django regression Red Hat: 2016:0359-01: […]
GIMP is vulnerable to multiple buffer overflows which could result in the execution of arbitrary code or Denial of Service. – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – […]
Several vulnerabilities were discovered in JasPer, a library for manipulating JPEG-2000 files. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-1577 Jacob Baines discovered a double-free flaw in the jas_iccattrval_destroy function. A remote attacker could exploit this flaw to cause an application using the JasPer library to crash, or potentially, to execute arbitrary […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2015-8126 Joerg Bornemann discovered multiple buffer overflow issues in the libpng library. CVE-2016-1630 Mariusz Mlynski discovered a way to bypass the Same Origin Policy in Blink/Webkit. CVE-2016-1631 Mariusz Mlynski discovered a way to bypass the Same Origin Policy in the Pepper Plugin API. CVE-2016-1632 A […]
Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. For the oldstable distribution (wheezy), these problems have been fixed in version 6:0.8.17-2. For the stable distribution (jessie), libav has been updated to 11.6-1~deb8u1 which brings several further bugfixes as detailed in the upstream changelog: https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.6 We recommend that […]
Multiple vulnerabilities were discovered in the dissectors/parsers for Pcapng, NBAP, UMTS FP, DCOM, AllJoyn, T.38, SDP, NLM, DNS, BED, SCTP, 802.11, DIAMETER, VeriWave, RVSP, ANSi A, GSM A, Ascend, NBAP, ZigBee ZCL and Sniffer which could result in denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 1.8.2-5wheezy17. For […]
Alvaro Muñoz and Christian Schneider discovered that BeanShell, an embeddable Java source interpreter, could be leveraged to execute arbitrary commands: applications including BeanShell in their classpath are vulnerable to this flaw if they deserialize data from an untrusted source. For the oldstable distribution (wheezy), this problem has been fixed in version 2.0b4-12+deb7u1. For the stable […]
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service, information leak or data loss. CVE-2013-4312 Tetsuo Handa discovered that users can use pipes queued on local (Unix) sockets to allocate an unfair share of kernel memory, leading to denial-of-service (resource exhaustion). This issue was previously […]
Ralf Schlatterbeck discovered an information leak in roundup, a web-based issue tracking system. An authenticated attacker could use it to see sensitive details about other users, including their hashed password. After applying the update, which will fix the shipped templates, the site administrator should ensure the instanced versions (in /var/lib/roundup usually) are also updated, either […]
The update for linux issued as DSA-3426-1 and DSA-3434-1 to address CVE-2015-8543 uncovered a bug in ctdb, a clustered database to store temporary data, leading to broken clusters. Updated packages are now available to address this problem. For the oldstable distribution (wheezy), this problem has been fixed in version 1.12+git20120201-5. For the stable distribution (jessie), […]
Stephane Chazelas discovered a bug in the environment handling in Perl. Perl provides a Perl-space hash variable, %ENV, in which environment variables can be looked up. If a variable appears twice in envp, only the last value would appear in %ENV, but getenv would return the first. Perl’s taint security mechanism would be applied to […]
Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit. CVE-2016-0702 Yuval Yarom from the University of Adelaide and NICTA, Daniel Genkin from Technion and Tel Aviv University, and Nadia Heninger from the University of Pennsylvania discovered a side-channel attack which makes use of cache-bank conflicts on the Intel Sandy-Bridge microarchitecture. This could allow […]
Markus Krell discovered that xymon, a network- and applications-monitoring system, was vulnerable to the following security issues: CVE-2016-2054 The incorrect handling of user-supplied input in the config command can trigger a stack-based buffer overflow, resulting in denial of service (via application crash) or remote code execution. CVE-2016-2055 The incorrect handling of user-supplied input in the […]
Multiple security vulnerabilities have been found in Pillow, a Python imaging library, which may result in denial of service or the execution of arbitrary code if a malformed FLI, PCD or Tiff files is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 1.1.7-4+deb7u2 of the python-imaging source package. For the […]
Multiple security vulnerabilities have been found in the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/SA-CORE-2016-001 For the oldstable distribution (wheezy), this problem has been fixed in version 7.14-2+deb7u12. For the stable distribution (jessie), this problem has been fixed in version 7.32-1+deb8u6. For the unstable distribution (sid), this […]
It was discovered that php-horde, a flexible, modular, general-purpose web application framework written in PHP, is prone to a cross-site scripting vulnerability. For the stable distribution (jessie), this problem has been fixed in version 5.2.1+debian0-2+deb8u3. For the testing distribution (stretch), this problem has been fixed in version 5.2.9+debian0-1. For the unstable distribution (sid), this problem […]
It was discovered that php-horde-core, a set of classes providing the core functionality of the Horde Application Framework, is prone to a cross-site scripting vulnerability. For the stable distribution (jessie), this problem has been fixed in version 2.15.0+debian0-1+deb8u1. For the testing distribution (stretch), this problem has been fixed in version 2.22.4+debian0-1. For the unstable distribution […]
Two SQL injection vulnerabilities were discovered in cacti, a web interface for graphing of monitoring systems. Specially crafted input can be used by an attacker in parameters of the graphs_new.php script to execute arbitrary SQL commands on the database. For the oldstable distribution (wheezy), these problems have been fixed in version 0.8.8a+dfsg-5+deb7u8. For the stable […]
Gustavo Grieco discovered that xerces-c, a validating XML parser library for C++, mishandles certain kinds of malformed input documents, resulting in buffer overflows during processing and error reporting. These flaws could lead to a denial of service in applications using the xerces-c library, or potentially, to the execution of arbitrary code. For the oldstable distribution […]
Daniel Gultsch discovered a vulnerability in Gajim, an XMPP/jabber client. Gajim didn’t verify the origin of roster update, allowing an attacker to spoof them and potentially allowing her to intercept messages. For the oldstable distribution (wheezy), this problem has been fixed in version 0.15.1-4.1+deb7u1. For the stable distribution (jessie), this problem has been fixed in […]
Multiple security issues have been found in Icedove, Debian’s version of the Mozilla Thunderbird mail client: Multiple memory safety errors, integer overflows, buffer overflows and other implementation errors may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (wheezy), these problems have been fixed in version 38.6.0-1~deb7u1. For the […]
Jakub Palaczynski discovered that websvn, a web viewer for Subversion repositories, does not correctly sanitize user-supplied input, which allows a remote user to run reflected cross-site scripting attacks. For the oldstable distribution (wheezy), this problem has been fixed in version 2.3.3-1.1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 2.3.3-1.2+deb8u1. We […]
lighttpd, a small webserver, is vulnerable to the POODLE attack via the use of SSLv3. This protocol is now disabled by default. For the oldstable distribution (wheezy), this problem has been fixed in version 1.4.31-4+deb7u4. We recommend that you upgrade your lighttpd packages.
Aris Adamantiadis discovered that libssh, a tiny C SSH library, incorrectly generated a short ephemeral secret for the diffie-hellman-group1 and diffie-hellman-group14 key exchange methods. The resulting secret is 128 bits long, instead of the recommended sizes of 1024 and 2048 bits respectively. This flaw could allow an eavesdropper with enough resources to decrypt or intercept […]
Andreas Schneider reported that libssh2, a SSH2 client-side library, passes the number of bytes to a function that expects number of bits during the SSHv2 handshake when libssh2 is to get a suitable value for group order in the Diffie-Hellman negotiation. This weakens significantly the handshake security, potentially allowing an eavesdropper with enough resources to […]
Several vulnerabilities have been discovered in the chromium web browser. CVE-2016-1622 It was discovered that a maliciously crafted extension could bypass the Same Origin Policy. CVE-2016-1623 Mariusz Mlynski discovered a way to bypass the Same Origin Policy. CVE-2016-1624 lukezli discovered a buffer overflow issue in the Brotli library. CVE-2016-1625 Jann Horn discovered a way to […]
