(Oct 24) Several security issues were fixed in MySQL.
Archive for October, 2013
Debian: 2785-1: chromium-browser: Multiple vulnerabilities
(Oct 26) Several vulnerabilities have been discovered in the chromium web browser. CVE-2013-2906 [More…]
Debian: 2783-2: librack-ruby: Multiple vulnerabilities
(Oct 24) The update of librack-ruby in DSA-2783-1 also addressed CVE-2013-0183. The patch applied breaks rails applications like redmine (see Debian Bug #727187). Updated packages are available to address this problem. [More…]
WordPress 3.7.1 is now available! This maintenance release addresses 11 bugs in WordPress 3.7, including: Images with captions no longer appear broken in the visual editor. Allow some sites running on old or poorly configured servers to continue to check for updates from WordPress.org. Avoid fatal errors with certain plugins that were incorrectly calling some […]
The following feature has been added:
[+] Backup signing. Panel signs backup files when they are downloaded or exported to external FTP repositories. The signature lets administrators distinguish trustworthy backups in the list of backups available for restoration. Learn more at http://kb.parallels.com/118188.
The following bug has been fixed:
[-] Panel did not display images in text widgets on websites that were reverted from a snapshot made on another domain. (142049, PPPM-992)
(Oct 24) Suds could be made to overwrite files.
(Oct 24) Apport could be made to expose privileged information.
Debian: 2787-1: roundcube: design error
(Oct 27) It was discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, does not properly sanitize the _session parameter in steps/utils/save_pref.inc during saving preferences. The vulnerability can be exploited to overwrite configuration settings and [More…]
Debian: 2786-1: icu: Multiple vulnerabilities
(Oct 27) The Google Chrome Security Team discovered two issues (a race condition and a use-after-free issue) in the International Components for Unicode (ICU) library. [More…]
(Oct 23) Swift could cause the system to crash if it received specially craftedrequests over the network.
(Oct 23) Nova could be made to crash if it received specially crafted networkrequests.
Red Hat: 2013:1449-01: kernel: Moderate Advisory
(Oct 22) Updated kernel packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More…]
Case 69513 Summary World writable Logaholic directories allowed arbitrary code execution in varied contexts. Security Rating cPanel has assigned a Security Level of Important to this vulnerability. Description Multiple directories within /usr/local/cpanel/base/3rdparty/Logaholic were set world writable by default with permissions of 777. These directories contained, among other items, the global …
(Oct 23) Glance could be made to expose sensitive information over the networkunder certain circumstances.
Ubuntu: 2002-1: Keystone vulnerabilities
(Oct 23) Keystone would improperly grant access to invalid tokens under certaincircumstances.
Red Hat: 2013:1450-01: kernel: Important Advisory
(Oct 22) Updated kernel packages that fix three security issues and several bugs are now available for Red Hat Enterprise Linux 6.3 Extended Update Support. The Red Hat Security Response Team has rated this update as having [More…]
Red Hat: 2013:1457-01: libgcrypt: Moderate Advisory
(Oct 24) An updated libgcrypt package that fixes one security issue is now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Ubuntu: 2005-1: Cinder vulnerabilities
(Oct 23) Cinder could be made to crash or expose sensitive information.
Ubuntu: 2004-1: python-glanceclient vulnerability
(Oct 23) python-glanceclient could be made to expose sensitive information over thenetwork.
Red Hat: 2013:1458-01: gnupg: Moderate Advisory
(Oct 24) An updated gnupg package that fixes multiple security issues is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1459-01: gnupg2: Moderate Advisory
(Oct 24) An updated gnupg2 package that fixes three security issues is now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Version 3.7 of WordPress, named “Basie” in honor of Count Basie, is available for download or update in your WordPress dashboard. This release features some of the most important architectural updates we’ve made to date. Here are the big ones: Updates while you sleep: With WordPress 3.7, you don’t have to lift a finger to […]
The Joomla! Project is pleased to announce the availability of Joomla! CMS 3.2 Beta 2. Community members are asked to download and install the package in order to provide quality assurance for Joomla 3.2. Joomla 3.2 is scheduled for release on or around November 6th, 2013.
A big thank you goes out to everyone that contributed to Joomla 3.2! Joomla 3.2 will be our largest release ever, in terms of bug fixes and new features. Right now we’re at about 960 commits since 3.1.5’s release with 50 different people contributing to commits (not including testers and other non-coding activities). And best of all is that the new features are awesome!
The following feature has been added:
[+] Backup signing. Panel signs backup files when they are downloaded or exported to external FTP repositories. The signature lets administrators distinguish trustworthy backups in the list of backups available for restoration. Learn more at http://kb.parallels.com/118188.
PHP.net blocked by Google: False positive or not?
Rasmus Lerdorf – the creator of PHP – is currently trying to get Google to stop blocking the whole php.net website after it was suspected of containing malware. In a tweet earlier this morning, Rasmus posted a screenshot and suggested that the block was caused by a false positive.
The following features have been added:
The following issues have been fixed:
[-] Panel did not apply automatic updates to the Migration & Transfer Manager in some cases.
[-] Administrators could not change the ASP.NET version on a subscription by means of the ‘subscription’ command-line utility. (PPPM-974)
[-] Administrators could not create subscriptions by means of the ‘subscription’ command-line utility if the webmail software was not installed on the server. (142956)
[-] The Postfix mail queue contained messages with the value “Not Found” in the “From” field. (PPPM-968)
Debian: 2784-1: xorg-server: use-after-free
(Oct 22) Pedro Ribeiro discovered a use-after-free in the handling of ImageText requests in the Xorg Xserver, which could result in denial of service or privilege escalation. [More…]
Debian: 2781-1: python-crypto: PRNG not correctly reseeded
(Oct 18) A cryptographic vulnerability was discovered in the pseudo random number generator in python-crypto. In some situations, a race condition could prevent the reseeding of the [More…]
Ubuntu: 1992-1: Linux kernel vulnerability
(Oct 22) The system could be made to expose sensitive information to a local user.
Ubuntu: 1996-1: Linux kernel vulnerability
(Oct 22) The system could be made to expose sensitive information to a local user.