LinuxSecurity.com: This update upgrades Firefox to version 52.7.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7 (MFSA 2018-07) (CVE-2018-5125) * Mozilla: Buffer overflow manipulating SVG animatedPathSegList (MFSA 2018-07) (CVE-2018-5127) * Mozilla: Out-of-bounds write with malformed IPC messages (MFSA 2018-07) (CVE-2018-5129) * Mozilla: Mismatched RTP payload type can trigger memo […]
security update
security update
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0527
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0526
LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code or denial of service.
LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 3.0 for Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 3.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Updates for rh-dotnet20-dotnet, rh-dotnetcore10-dotnetcore, and rh-dotnetcore11-dotnetcore are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update for erlang is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update that fixes 14 vulnerabilities is now available.
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: Several vulnerabilities were discovered in mbed TLS, a lightweight crypto and SSL/TLS library, that allowed a remote attacker to either cause a denial-of-service by application crash, or execute arbitrary code.
LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available.
security update
LinuxSecurity.com: This update fixes CVE-2017-18196. —- This update backports security fixes for CVE-2018-3836, CVE-2018-7186 and CVE-2018-7247.
LinuxSecurity.com: This update fixes CVE-2017-18196. —- This update backports security fixes for CVE-2018-3836, CVE-2018-7186 and CVE-2018-7247.
LinuxSecurity.com: The package postgresql before version 10.3-1 is vulnerable to privilege escalation.
LinuxSecurity.com: The package calibre before version 3.19.0-1 is vulnerable to arbitrary command execution.
LinuxSecurity.com: The package dovecot before version 2.3.0.1-1 is vulnerable to multiple issues including information disclosure and denial of service.
LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.
LinuxSecurity.com: mailman: Cross-site scripting (XSS) vulnerability in web UI (CVE-2018-5950) SL6 x86_64 mailman-2.1.12-26.el6_9.3.x86_64.rpm mailman-debuginfo-2.1.12-26.el6_9.3.x86_64.rpm i386 mailman-2.1.12-26.el6_9.3.i686.rpm mailman-debuginfo-2.1.12-26.el6_9.3.i686.rpm – Scientific Linux Development Team
LinuxSecurity.com: mailman: Cross-site scripting (XSS) vulnerability in web UI (CVE-2018-5950) SL7 x86_64 mailman-2.1.15-26.el7_4.1.x86_64.rpm mailman-debuginfo-2.1.15-26.el7_4.1.x86_64.rpm – Scientific Linux Development Team
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for libreoffice is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:
security update
LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, and Red Hat Enterprise
LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.7, 3.6, 3.5, 3.4, and 3.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: dhcp: Buffer overflow in dhclient possibly allowing code execution triggered by malicious server (CVE-2018-5732) * dhcp: Reference count overflow in dhcpd allows denial of service (CVE-2018-5733) SL7 x86_64 dhclient-4.2.5-58.el7_4.3.x86_64.rpm dhcp-common-4.2.5-58.el7_4.3.x86_64.rpm dhcp-debuginfo-4.2.5-58.el7_4.3.i686.rpm dhcp-debuginfo-4.2.5-58.el7_4.3.x86_64.rpm dhcp [More…]
LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions, and Red Hat Enterprise Linux 7.3 Extended Update Support.
LinuxSecurity.com: Update to latest version. Security-Fixes TROVE-2018-001, TROVE-2018-002,
LinuxSecurity.com: An update for dhcp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: Updated Red Hat Enterprise Messaging, Realtime, and Grid (MRG) Realtime packages that fix multiple security issues and add one enhancement are now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having Moderate security
LinuxSecurity.com: An update that solves 8 vulnerabilities and has 14 fixes is now available.
security update
LinuxSecurity.com: **PHP version 7.1.15** (01 Mar 2018) **Apache2Handler:** * Fixed bug php#75882 (a simple way for segfaults in threadsafe php just with configuration). (Anatol) **Date:** * Fixed bug php#75857 (Timezone gets truncated when formatted). (carusogabriel) * Fixed bug php#75928 (Argument 2 for `DateTimeZone::listIdentifiers()` should accept `null`). (Pedro Lacerda) * Fixed
LinuxSecurity.com: Bjorn Bosselmann discovered that the umount bash completion from util-linux does not properly handle embedded shell commands in a mountpoint name. An attacker with rights to mount filesystems can take advantage of this flaw for privilege escalation if a user (in particular
LinuxSecurity.com: It was discovered that there were multiple vulnerabilities in the “zsh” shell: * CVE-2014-10070: Fix a privilege-elevation issue if the
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0378
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0377
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0414
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0406
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0418
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0395
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0469
LinuxSecurity.com: Several security issues were fixed in ClamAV.
LinuxSecurity.com: Several security issues were fixed in Zsh.
LinuxSecurity.com: An update for dhcp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: The system could be made to expose sensitive information.
LinuxSecurity.com: dhcp: Buffer overflow in dhclient possibly allowing code execution triggered by malicious server (CVE-2018-5732) * dhcp: Reference count overflow in dhcpd allows denial of service (CVE-2018-5733) SL6 x86_64 dhclient-4.1.1-53.P1.el6_9.3.x86_64.rpm dhcp-4.1.1-53.P1.el6_9.3.x86_64.rpm dhcp-common-4.1.1-53.P1.el6_9.3.x86_64.rpm dhcp-debuginfo-4.1.1-53.P1.el6_9.3.i686.rpm dh [More…]
LinuxSecurity.com: An update that solves 10 vulnerabilities and has four fixes is now available.
security update
LinuxSecurity.com: Several functions were extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in several regular expressions.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 6 and Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update is now available for Red Hat JBoss Web Server 3.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: Several vulnerabilities have been discovered in the ISC DHCP client, relay and server. The Common Vulnerabilities and Exposures project identifies the following issues:
LinuxSecurity.com: php: Buffer over-read from unitialized data in gdImageCreateFromGifCtx function (CVE-2017-7890) SL7 x86_64 php-5.4.16-43.el7_4.1.x86_64.rpm php-bcmath-5.4.16-43.el7_4.1.x86_64.rpm php-cli-5.4.16-43.el7_4.1.x86_64.rpm php-common-5.4.16-43.el7_4.1.x86_64.rpm php-dba-5.4.16-43.el7_4.1.x86_64.rpm php-debuginfo-5.4.16-43.el7_4.1.x86_64.rpm php-devel-5.4.16-43.el7_4.1. [More…]
LinuxSecurity.com: libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula (CVE-2018-6871) SL7 x86_64 libreoffice-base-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-calc-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-core-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-debuginfo-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-draw-5.0.6.2-15.el7_4.x86_64.rpm libreoffice-emailmerge-5.0.6. [More…]
LinuxSecurity.com: Kernel: KVM: MMU potential stack buffer overrun during page walks (CVE-2017-12188, Important) * Kernel: KVM: debug exception via syscall emulation (CVE-2017-7518, Moderate) SL7 x86_64 kernel-3.10.0-693.21.1.el7.x86_64.rpm kernel-debug-3.10.0-693.21.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-693.21.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-693.21.1.el7.x86_64.rpm ke [More…]
LinuxSecurity.com: 389-ds-base: remote Denial of Service (DoS) via search filters in SetUnicodeStringFromUTF_8 in collate.c (CVE-2018-1054) * 389-ds-base: Authentication bypass due to lack of size check in slapi_ct_memcmp function in ch_malloc.c (CVE-2017-15135) Bug Fix(es): * Previously, if an administrator configured an index for an attribute with a specific matching rule in the “nsMatchingRule” parameter, [More…]
LinuxSecurity.com: A vulnerability in Go might allow remote attackers to execute arbitrary commands during source code build.
LinuxSecurity.com: A vulnerability was discovered in util-linux, which could potentially lead to the execution of arbitrary code.
LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Different flaws have been found in leptonlib, an image processing library.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for libreoffice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for php is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
LinuxSecurity.com: The package python2-django before version 1.11.11-1 is vulnerable to denial of service.
LinuxSecurity.com: The package python2-django before version 1.11.11-1 is vulnerable to denial of service.
LinuxSecurity.com: The package python-django before version 1.11.11-1 is vulnerable to denial of service.
LinuxSecurity.com: Updated kernel packages that fix six bugs are now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: PostgreSQL could be made to execute arbitrary code.
LinuxSecurity.com: Twisted could be made to run programs if it received specially crafted network traffic.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.
LinuxSecurity.com: An update that solves 10 vulnerabilities and has two fixes is now available.
LinuxSecurity.com: The package mkinitcpio-busybox before version 1.28.1-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package busybox before version 1.28.1-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: It was discovered that there was a potential XML External Entity (XXE) attack in libjgraphx-java, a diagramming library for Java applications. For Debian 7 “Wheezy”, this issue has been fixed in libjgraphx-java version
security update
security update
security update
security update
security update
LinuxSecurity.com: Fix: Multiple vulnerabilities in RubyGems https://www.ruby- lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/
LinuxSecurity.com: The security update announced as DSA-4120-1 caused regressions on the powerpc kernel architecture (random programs segfault, data corruption). Updated packages are now available to correct this issue.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
