LinuxSecurity.com: Multiple vulnerabilities were discovered in Ceph, a distributed storage and file system: The cephx authentication protocol was suspectible to replay attacks and calculated signatures incorrectly, “ceph mon” did not validate capabilities for pool operations (resulting in potential
LinuxSecurity.com: Multiple vulnerabilities were found in Spamassassin, which could lead to Remote Code Execution and Denial of Service attacks under certain circumstances.
LinuxSecurity.com: A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: New Red Hat Single Sign-On 7.2.5 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: New Red Hat Single Sign-On 7.2.5 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Several security issues were fixed in systemd.
LinuxSecurity.com: gettext could be made to execute arbitrary code if it received a specially crafted message.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.
LinuxSecurity.com: Several security issues were fixed in ClamAV.
LinuxSecurity.com: A security update is now available for Red Hat JBoss BRMS 5.3.1. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for httpd24-httpd, httpd24-nghttp2, and httpd24-curl is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Several vulnerabilities have been discovered in the firmware for Broadcom BCM43xx wifi chips that may lead to a privilege escalation or loss of confidentiality.
LinuxSecurity.com: CVE-2018-18025 Fix for heap-based buffer over-read which can result in a denial of service via a crafted file.
security update
LinuxSecurity.com: gettext could be made to execute arbitrary code if it received a specially crafted message.
LinuxSecurity.com: It was discovered that there was a potential SSH passphrase disclosure vulnerability in the ansible configuration management system, The “User” module leaked data that was passed as a parameter to the
LinuxSecurity.com: An update for rh-git29-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Multiple security issues have been found in Thunderbird: Multiple memory safety errors and use-after-frees may lead to the execution of arbitrary code or denial of service.
LinuxSecurity.com: Dulwich, when an SSH subprocess is used, allowed remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname (CVE-2017-16228). References:
LinuxSecurity.com: A flaw was found in iniparser version prior to 4.1. A stack buffer underflow in the function iniparser_load() in iniparser.c file which can be triggered by parsing a file that containing a zero-byte. This vulnerability may allow an attacker to cause a Denial of Service (DoS).
LinuxSecurity.com: A NULL pointer dereference in modules/ModuleState.cpp:ModuleState::setup() allows for denial of service via crafted file (CVE-2018-13440). A Heap-based buffer overflow was found in Expand3To4Module::run when running sfconvert (CVE-2018-17095).
LinuxSecurity.com: It was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker’s control, allowing to run arbitrary code as a result (CVE-2018-10874). It was found that ansible.cfg is being read from the current working
LinuxSecurity.com: It was discovered that opencc contained an out of bounds pointer in BinaryDict.cpp which could lead to segment fault and a Denial of Service (CVE-2018-16982). References:
LinuxSecurity.com: An out-of-bounds read during parsing of a malformed manifest entry (CVE-2018-17983). References: – https://bugs.mageia.org/show_bug.cgi?id=23763
LinuxSecurity.com: An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c. (CVE-2018-18661) References:
LinuxSecurity.com: The package systemd before version 239.300-1 is vulnerable to multiple issues including arbitrary code execution and privilege escalation.
security update
LinuxSecurity.com: Several vulnerabilities were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service, disclosure of existence and size of arbitrary files, or the execution of arbitrary code if a malformed Postscript file is processed (despite the
LinuxSecurity.com: The package lib32-libcurl-compat before version 7.62.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-curl before version 7.62.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.62.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package libcurl-compat before version 7.62.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package libcurl-gnutls before version 7.62.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: Multiple security issues have been found in Thunderbird: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service.
LinuxSecurity.com: The package curl before version 7.62.0-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.
LinuxSecurity.com: Multiple vulnerabilities have been found in libde265, the worst of which allows remote attackers to execute arbitrary code.
LinuxSecurity.com: A vulnerability in Pango could result in a Denial of Service condition.
LinuxSecurity.com: Okular is vulnerable to a directory traversal attack.
LinuxSecurity.com: A vulnerability in Icecast might allow remote attackers to execute arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in PHProjekt due to embedded Zend Framework, the worst of which could allow attackers to remotely execute arbitrary commands. [More…]
LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.
LinuxSecurity.com: An update that solves 13 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that contains security fixes can now be installed.
LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
security update
security update
LinuxSecurity.com: It was discovered that there was a denial of service (DoS) vulnerability in the nginx web/proxy server. As there was no validation for the size of a 64-bit atom in an MP4 file,
LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: A buffer overflow in Python might allow remote attackers to cause a Denial of Service condition.
LinuxSecurity.com: A vulnerability in OpenSSL might allow remote attackers to cause a Denial of Service condition.
LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been found in X.Org X11 library, the worst of which could allow for remote code execution.
LinuxSecurity.com: Three vulnerabilities were discovered in Nginx, a high-performance web and reverse proxy server, which could in denial of service in processing HTTP/2 (via excessive memory/CPU usage) or server memory disclosure in the ngx_http_mp4_module module (used for server-side MP4 streaming).
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3403
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3406
LinuxSecurity.com: Several security issues were fixed in nginx.
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: An update for spice-server is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: The previous update of libdatetime-timezone-perl to tzdata version 2018g was incomplete due to a newly introduced rule type that this version of libdatetime-timezone-perl could not parse.
LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could result in the execution of arbitrary code, privilege escalation or information disclosure.
LinuxSecurity.com: An update that solves 5 vulnerabilities and has 86 fixes is now available.
LinuxSecurity.com: Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.37. Please see the MariaDB 10.0 Release Notes for further details:
LinuxSecurity.com: This update includes the changes in tzdata 2018g for the Perl bindings. For the list of changes, see DLA-1363-1. For Debian 8 “Jessie”, this problem has been fixed in version
LinuxSecurity.com: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Several security issues were fixed in SpamAssassin.
LinuxSecurity.com: ppp could be made to crash or bypass authentication if it received specially crafted network traffic.
LinuxSecurity.com: An update for xerces-c is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Several security issues were fixed in libxkbcommon.
LinuxSecurity.com: An update for xerces-c is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Security Advisory 2. Description: Red Hat Ansible Tower 3.3.1 is now available and contains the following bug fixes:
LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update is now available for Red Hat JBoss SOA Platform 5.3.1. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: The package ghostscript before version 9.25-4 is vulnerable to sandbox escape.
LinuxSecurity.com: Several vulnerabilities were discovered in cURL, an URL transfer library. CVE-2016-7141
LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.62, which includes additional changes. Please see the MySQL
LinuxSecurity.com: CVE-2018-18718 – CWE-415: Double Free The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
LinuxSecurity.com: NetworkManager could be made to crash or run programs if it received specially crafted network traffic.
LinuxSecurity.com: systemd-networkd could be made to crash or run programs if it received specially crafted network traffic.
LinuxSecurity.com: An update for openvswitch is now available for Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: Several security issues were fixed in Ruby.
security update
security update
LinuxSecurity.com: Multiple security vulnerabilities were discovered in GlusterFS, a clustered file system. Buffer overflows and path traversal issues may lead to information disclosure, denial-of-service or the execution of arbitrary code.
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
