Menu

Quote

LinuxSecurity.com: This update includes the changes in tzdata 2018i. Notable changes are: – Qyzylorda, Kazakhstan moved from +06 to +05 on 2018-12-21. A new

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: Fix CVEs as described in related RHBZ bug.

LinuxSecurity.com: Fix CVEs as described in related RHBZ bug.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by “j a v a s c r i p t:” in Internet Explorer (CVE-2018-19787).

LinuxSecurity.com: Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment. (CVE-2018-19149) References:

LinuxSecurity.com: Graphicsmagick has been updated to fix several bugs and security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=23157 – http://www.graphicsmagick.org/NEWS.html#november-17-2018

LinuxSecurity.com: Possible denial of service vulnerability due to a missing check in Lib/wave.py to verify that at least one channel is provided (CVE-2017-18207). Python’s elementtree C accelerator failed to initialise Expat’s hash

LinuxSecurity.com: debian-security-support, the Debian security support coverage checker, has been updated in jessie. The jessie relevant changes are: * Mark jasperreports as end-of-life in Jessie.

LinuxSecurity.com: It was discovered that there was a potential denial of service vulnerability in tar, the GNU version of the tar UNIX archiving utility.

LinuxSecurity.com: Updated to 3.3.4. Security fix by upstream: Anti-Phishing protection.. Server-provided text will not appear in user-facing GUI windows anymore. Server error messages are instead parsed and mapped to predefined strings.

LinuxSecurity.com: Multiple vulnerabilities have been found in Rust, the worst which may allow local attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in GKSu might allow attackers to execute arbitrary commands.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves four vulnerabilities and has 17 fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: This update fixes CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149.

LinuxSecurity.com: **Archive_Tar version 1.4.4** * Fix Bug #21058: Long symlinks are not supported [mrook] * Fix Bug #23782: Prevent phar:// files from being extracted [mrook] — **PEAR** * drop deprecated option used when running `pear run-tests`

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

LinuxSecurity.com: This update fixes CVE-2017-18267, CVE-2018-13988, CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: Security fix for CVE-2018-16869

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit

LinuxSecurity.com: Several vulnerabilities were discovered in libextractor, a library to extract arbitrary meta-data from files, which may lead to denial of service or memory disclosure if a malformed OLE file is processed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

security update

LinuxSecurity.com: A XML External Entity (XXE) vulnerability was discovered in c3p0, a library for JDBC connection pooling, that may be used to resolve information outside of the intended sphere of control.

LinuxSecurity.com: Multiple security issues were found in libarchive, a multi-format archive and compression library: Processing malformed RAR archives could result in denial of service or the execution of arbitrary code and malformed WARC, LHarc, ISO, Xar or CAB archives could result in denial of service.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer, which could result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: Some vulnerabilities were discovered in ghostscript, an interpreter for the PostScript language and for PDF.

LinuxSecurity.com: Fixed a stack-based buffer over-read in the print_prefix function (CVE-2018-19519). References: – https://bugs.mageia.org/show_bug.cgi?id=24077

LinuxSecurity.com: A flaw was found in the i18n gem before 0.8.0 for Ruby. The Hash#slice in lib/i18n/core_ext/hash.rb allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash (CVE-2014-10077).

LinuxSecurity.com: A possible regression was found in the recent security update for libphp-phpmailer, announced as DLA 1591-1. During backporting a new variable have accidentally introduced to a conditional statement from

LinuxSecurity.com: Update to new upstream version 1.5.5 (rhbz#1660413, rhbz#1660414)

LinuxSecurity.com: Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758

LinuxSecurity.com: The Shopify Application Security Team discovered that ruby-sanitize, a whitelist-based HTML sanitizer, is prone to a HTML injection vulnerability. A specially crafted HTML fragment can cause to allow non- whitelisted attributes to be used on a whitelisted HTML element.

LinuxSecurity.com: Kaspersky Lab discovered several vulnerabilities in libvncserver, a C library to implement VNC server/client functionalities.

LinuxSecurity.com: Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758

LinuxSecurity.com: Update to new upstream version 1.5.5 (rhbz#1660413, rhbz#1660414)

LinuxSecurity.com: A security issue fixed upstream in sqlite3 has been announced: https://www.openwall.com/lists/oss-security/2018/12/21/1 The issue is fixed in 3.25.3. References:

LinuxSecurity.com: There is a use-after-free in monit that shows up if you run it for a while on an active system with address sanitizer enabled. References: – https://bugs.mageia.org/show_bug.cgi?id=24049

LinuxSecurity.com: The updated packages fix several bugs and some security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=24041 – https://www.thunderbird.net/en-US/thunderbird/60.4.0/releasenotes/

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in libsndfile, the library for reading and writing files containing sampled sound. CVE-2017-8361

LinuxSecurity.com: – Fix double-free in CEmuopl::~CEmuopl() (#1635881, CVE-2018-17825)

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2018-5783, CVE-2018-11254, CVE-2018-11255, CVE-2018-11256, CVE-2018-12982, CVE-2018-14320, CVE-2018-19532

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2018-5783, CVE-2018-11254, CVE-2018-11255, CVE-2018-11256, CVE-2018-12982, CVE-2018-14320, CVE-2018-19532

LinuxSecurity.com: – Fix double-free in CEmuopl::~CEmuopl() (#1635881, CVE-2018-17825)

LinuxSecurity.com: Several issues were corrected in nagios3, a monitoring and management system for hosts, services and networks. CVE-2018-18245

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3833

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3831

LinuxSecurity.com: Version update + Security fix for CVE-2018-19131 and CVE-2018-19132

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: Fix low-severity CVE-2018-20217 (an authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request.)

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes is now available.

LinuxSecurity.com: **MariaDB C / C++ connector** Release notes: https://mariadb.com/kb/en/library/mariadb-connector-c-307-release-notes/ Maintainer notes: Marking as a security update, beacuse of fixed resource leaks. Moving libmariadb pkgconfig file to this package from mariadb- devel. Test with MariaDB-3:10.2.19-2

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in Go, the worst which could lead to the execution of arbitrary code.

LinuxSecurity.com: New netatalk packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: **MariaDB 10.3.11** Release notes: https://mariadb.com/kb/en/mariadb-10311-release-notes/ CVEs fixed: CVE-2018-3282 CVE-2016-9843 CVE-2018-3174 CVE-2018-3143 CVE-2018-3156 CVE-2018-3251 CVE-2018-3185 CVE-2018-3277 CVE-2018-3162 CVE-2018-3173 CVE-2018-3200 CVE-2018-3284

LinuxSecurity.com: Security experts at Tencent’s Blade security team have discovered a critical vulnerability in SQLite database software (nicknamed “Magellan”).

LinuxSecurity.com: Daniel Axtens discovered a double-free and use-after-free vulnerability in libarchive’s RAR decoder that can result in a denial-of-service (application crash) or may have other unspecified impact when a malformed RAR archive is processed.

LinuxSecurity.com: This kernel update is based on the upstream 4.14.89 and fixes atleast the following security issues: Cross-hyperthread Spectre v2 mitigation is now provided by the Single Thread Indirect Branch Predictors (STIBP) support. Note that STIBP also

security update

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit sqlite rebased to version 3.26.0 per: https://sqlite.org/releaselog/3_26_0.html spatialite-tools rebuilt for latest sqlite version

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit sqlite rebased to version 3.26.0 per: https://sqlite.org/releaselog/3_26_0.html spatialite-tools rebuilt for latest sqlite version

LinuxSecurity.com: Update to 4.2.5

LinuxSecurity.com: Upstream announcement: The phpMyAdmin team is pleased to announce the release of **phpMyAdmin version 4.8.4**. Among other bug fixes, this contains several important security fixes. The security fixes involve: * Local file inclusion (https://www.phpmyadmin.net/security/PMASA-2018-6/), * XSRF/CSRF vulnerabilities allowing a specially-crafted URL to perform harmful operations

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for netatalk fixes the following issues: Security issue fixed:

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. Description: Description: This update for keepalived to version 2.0.10 fixes the following issues: Security issues fixed (bsc#1015141): – CVE-2018-19044: Fixed a check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats – CVE-2018-19045: Fixed mode when […]

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. Description: Description: This update for keepalived to version 2.0.10 fixes the following issues: Security issues fixed (bsc#1015141): – CVE-2018-19044: Fixed a check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats – CVE-2018-19045: Fixed mode when […]

LinuxSecurity.com: Two more security issues have been corrected in the libav multimedia library. This is a follow-up announcement for DLA-1611-1. CVE-2015-6823

security update

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

security update