Menu

Quote

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: It was discovered that a use-after-free in the compositor of Firefox can result in the execution of arbitrary code. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

security update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0592

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: A vulnerability in PLIB may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in BusyBox, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: It was discovered that there was an issue in the irssi IRC client where certain nick names could result in out-of-bounds access when printing theme strings.

LinuxSecurity.com: It was discovered that there was a heap corruption vulnerability in the net-snmp framework which exchanges server management information in a network.

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The package bchunk before version 1.2.2-4 is vulnerable to denial of service.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execution of arbitrary code.

LinuxSecurity.com: slf4j: Deserialisation vulnerability in EventData constructor can allow for arbitrary code execution (CVE-2018-8088) SL7 noarch slf4j-1.7.4-4.el7_4.noarch.rpm slf4j-javadoc-1.7.4-4.el7_4.noarch.rpm slf4j-manual-1.7.4-4.el7_4.noarch.rpm – Scientific Linux Development Team

LinuxSecurity.com: Bas van Schaik and Kevin Backhouse discovered a stack-based buffer overflow vulnerability in librelp, a library providing reliable event logging over the network, triggered while checking x509 certificates from a peer. A remote attacker able to connect to rsyslog can take

LinuxSecurity.com: An update for slf4j is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: The package thunderbird before version 52.7.0-1 is vulnerable to multiple issues including arbitrary code execution and access restriction bypass.

LinuxSecurity.com: An update for rh-ruby23-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby22-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-maven35-slf4j is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Daniel P. Berrange and Peter Krempa of Red Hat discovered a flaw in libvirt, a virtualization API. A lack of restriction for the amount of data read by QEMU Monitor socket can lead to a denial of service by exhaustion of memory resources.

security update

LinuxSecurity.com: Wojciech Regu?a discovered that Freeplane, a program for working with mind maps, was affected by a XML External Entity (XXE) vulnerability in its mindmap loader that could compromise a user’s machine by opening a specially crafted mind map file.

LinuxSecurity.com: Samba could be made to crash if it received specially crafted input.

LinuxSecurity.com: An update that solves 10 vulnerabilities and has 70 fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

security update

LinuxSecurity.com: Sharutils could be made to execute arbitrary code if it opened a specially crafted file.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: It was discovered that there was a server-side request forgery exploit in adminer, a web-based database administration tool. Adminer allowed unauthenticated connections to be initiated to arbitrary

LinuxSecurity.com: Cure53 discovered that in SimpleSAMLphp, in rare circumstances an invalid signature on the SAML 2.0 HTTP Redirect binding could be considered valid.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has four fixes is now available.

LinuxSecurity.com: Charles Duffy discovered that the Commandline class in the utilities for the Plexus framework performs insufficient quoting of double-encoded strings, which could result in the execution of arbitrary shell commands.

LinuxSecurity.com: Alfred Farrugia and Sandro Gauci discovered an off-by-one heap overflow in the Kamailio SIP server which could result in denial of service and potentially the execution of arbitrary code.

LinuxSecurity.com: Several vulnerabilities have been discovered in the ISC DHCP client, relay and server. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Huzaifa Sidhpurwala discovered that an out-of-bounds memory write in the codebook parsing code of the Libtremor multimedia library could result in the execution of arbitrary code if a malformed Vorbis file is opened.

security update

LinuxSecurity.com: Several vulnerabilities were discovered in PolarSSL, a lightweight crypto and SSL/TLS library, that allowed a remote attacker to either cause a denial-of-service by application crash, or execute arbitrary code.

LinuxSecurity.com: An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat JBoss BRMS. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: The package lib32-libvorbis before version 1.3.6-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: Gentoo’s collectd package contains multiple vulnerabilities, the worst of which may allow local attackers to escalate privileges.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has four fixes is now available.

security update

LinuxSecurity.com: Various issues were discovered in exempi, a library to parse XMP metadata that may cause a denial-of-service or may have other unspecified impact via crafted files.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0549

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0549

LinuxSecurity.com: An update for collectd is now available for RHEV 4.X RHEV-H and Agents for RHEL-7 and RHEV Engine version 4.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-mariadb101-mariadb and rh-mariadb101-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Paramiko could be made to run programs if it received speciallycrafted network traffic.

LinuxSecurity.com: Paramiko could be made to run programs if it received speciallycrafted network traffic.

LinuxSecurity.com: This update upgrades Firefox to version 52.7.2 ESR. * Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) (CVE-2018-5146) SL6 x86_64 firefox-52.7.2-1.el6_9.x86_64.rpm firefox-debuginfo-52.7.2-1.el6_9.x86_64.rpm firefox-52.7.2-1.el6_9.i686.rpm firefox-debuginfo-52.7.2-1.el6_9.i686.rpm i386 firefox-52.7.2-1.el6_9.i686.rpm firefox-debuginfo-52.7.2-1.el6 [More…]

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package libcurl-gnutls before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package libcurl-compat before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package lib32-curl before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: The package curl before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The package clamav before version 0.99.4-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has one errata is now available.

LinuxSecurity.com: The package firefox before version 59.0.1-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libvorbis before version 1.3.6-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple vulnerabilities have been found in KDE Plasma Workspaces, the worst of which allows local attackers to execute arbitrary commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Gentoo’s JabberD 2.x ebuild, the worst of which allows local attackers to escalate privileges. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JDK and JRE software suites, the worst of which may allow execution of arbitrary code. [More…]

LinuxSecurity.com: Multiple vulnerabilities were found in cURL, an URL transfer library: CVE-2018-1000120

LinuxSecurity.com: The package ntp before version 4.2.8.p11-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing and denial of service.

security update

security update

security update

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execution of arbitrary code.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Huzaifa Sidhpurwala discovered that an out-of-bounds memory write in the codebook parsing code of the Libtremor multimedia library could result in the execution of arbitrary code if a malformed Vorbis file is opened.

security update

LinuxSecurity.com: Richard Zhu discovered that an out-of-bounds memory write in the codeboook parsing code of the Libvorbis multimedia library could result in the execution of arbitrary code.

LinuxSecurity.com: Some vulnerabilities have been found in ClamAV, an open source antivirus engine:

LinuxSecurity.com: An update that fixes 27 vulnerabilities is now available.

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code, denial of service or information disclosure.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: This update upgrades Firefox to version 52.7.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7 (MFSA 2018-07) (CVE-2018-5125) * Mozilla: Buffer overflow manipulating SVG animatedPathSegList (MFSA 2018-07) (CVE-2018-5127) * Mozilla: Out-of-bounds write with malformed IPC messages (MFSA 2018-07) (CVE-2018-5129) * Mozilla: Mismatched RTP payload type can trigger memo […]