(Nov 27) Several security issues were fixed in Ruby.
Archive for November, 2013
Debian: 2806-1: nbd: privilege escalation
(Nov 29) It was discovered that nbd-server, the server for the Network Block Device protocol, did incorrect parsing of the access control lists, allowing access to any hosts with an IP address sharing a prefix with an allowed address. [More…]
Debian: 2805-1: sup-mail: command injection
(Nov 27) joernchen of Phenoelit discovered two command injection flaws in Sup, a console-based email client. An attacker might execute arbitrary command if the user opens a maliciously crafted email. [More…]
(Nov 25) Andrew Tinits reported a potentially exploitable buffer overflow in the Mozilla Network Security Service library (nss). With a specially crafted request a remote attacker could cause a denial of service or possibly execute arbitrary code. [More…]
Red Hat: 2013:1767-01: ruby: Critical Advisory
(Nov 26) Updated ruby packages that fix one security issue are now available for Red Hat Enterprise Linux 6.2, 6.3, and 6.4 Extended Update Support. The Red Hat Security Response Team has rated this update as having critical [More…]
[-] Domains were suspended due to mailbox quota overuse. (PPPM-1018)
[-] Plesk Panel showed the 502 Bad Gateway error page when users opened directories containing a large number of files in File Manager. (PPPM-785)
[-] Users were unable to back up sites if their vhost.conf files contained umlauts in comments. (PPPM-1094)
[-] Transfer of IDN domains failed. (PPPM-1090)
[-] Users were unable to restore data from password-protected backups by means of command-line tools. They encountered the error “Unable to decrypt backup by specified key”. (PPPM-1051)
Ubuntu: 2034-1: OpenStack Keystone vulnerability
(Nov 25) Keystone would improperly remove roles when it was configured to use theLDAP backend.
Debian: 2803-1: quagga: Multiple vulnerabilities
(Nov 26) Multiple vulnerabilities were discovered in Quagga, a BGP/OSPF/RIP routing daemon: CVE-2013-2236 [More…]
Debian: 2804-1: drupal7: Multiple vulnerabilities
(Nov 26) Multiple vulnerabilities have been discovered in Drupal, a fully-featured content management framework: Cross-site request forgery, insecure pseudo random number generation, code execution, incorrect security token validation and cross-site scripting. [More…]
Red Hat: 2013:1764-01: ruby: Critical Advisory
(Nov 25) Updated ruby packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having critical [More…]
Red Hat: 2013:1605-02: glibc: Moderate Advisory
(Nov 20) Updated glibc packages that fix three security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1635-02: pacemaker: Low Advisory
(Nov 20) Updated pacemaker packages that fix one security issue, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having low [More…]
Red Hat: 2013:1652-02: coreutils: Low Advisory
(Nov 20) Updated coreutils packages that fix three security issues, several bugs, and add two enhancements are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having low [More…]
Red Hat: 2013:1615-02: php: Moderate Advisory
(Nov 20) Updated php packages that fix three security issues, several bugs, and add one enhancement are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:1620-02: xorg-x11-server: Low Advisory
(Nov 20) Updated xorg-x11-server packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having low [More…]
Red Hat: 2013:1674-02: dracut: Moderate Advisory
(Nov 21) Updated dracut packages that fix one security issue, several bugs, and add two enhancements are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Ubuntu: 2033-1: OpenJDK 6 vulnerabilities
(Nov 21) Several security issues were fixed in OpenJDK 6.
Debian: 2802-1: nginx: restriction bypass
(Nov 21) Ivan Fratric of the Google Security Team discovered a bug in nginx, a web server, which might allow an attacker to bypass security restrictions by using a specially crafted request. [More…]
Debian: 2801-1: libhttp-body-perl: design error
(Nov 21) Jonathan Dolle reported a design error in HTTP::Body, a Perl module for processing data from HTTP POST requests. The HTTP body multipart parser creates temporary files which preserve the suffix of the uploaded file. An attacker able to upload files to a service that uses [More…]
Red Hat: 2013:1732-02: busybox: Low Advisory
(Nov 21) Updated busybox packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having low [More…]
Red Hat: 2013:1701-02: sudo: Low Advisory
(Nov 21) An updated sudo package that fixes two security issues, several bugs, and adds two enhancements is now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having low [More…]
Ubuntu: 2031-1: Firefox vulnerabilities
(Nov 20) Several security issues were fixed in Firefox.
Ubuntu: 2032-1: Thunderbird vulnerabilities
(Nov 21) Several security issues were fixed in Thunderbird.
Debian: 2798-2: curl: unchecked ssl certificate h
(Nov 20) The update for curl in DSA-2798-1 uncovered a regression affecting the curl command line tool behaviour (#729965). This update disables host verification too when using the –insecure option. [More…]
Red Hat: 2013:1661-02: RDMA stack: Moderate Advisory
(Nov 21) Updated rdma, libibverbs, libmlx4, librdmacm, qperf, perftest, openmpi, compat-openmpi, infinipath-psm, mpitests, and rds-tools packages that fix two security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. [More…]
Red Hat: 2013:1752-01: 389-ds-base: Important Advisory
(Nov 21) Updated 389-ds-base packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More…]
GoDaddy Offers cPanel & CloudLinux In Web Hosting Overhaul
SCOTTSDALE, Ariz. (Nov. 20, 2013) – GoDaddy, the world’s largest Web hosting provider, has revamped its Linux Web hosting lineup, with the addition of cPanel & WHM, the popular Web hosting management software. In addition, customers are also benefitting from a new Web hosting architecture that provides a fast and …
The following features were added:
[+] (Windows) BIND DNS server was updated to version 9.9.4-P1, CVE-2013-6230 vulnerability is closed.
[+] (Windows) Horde webmail was updated to version 5.1.5, CVE-2013-6275 vulnerability is closed.
The following issues were resolved:
[-] The piped logging feature did not write access_logs for add-on domains and subdomains.
[-] Plesk could not register PHP handlers because of wrong directives in php.ini or if running php -v returned exit code 1. (PPPM-808, PPPM-885)
[-] Chained SSL certificates no longer worked with nginx after upgrade.
[-] During upgrade to Plesk 11.5, the directories of add-on domains were incorrectly relocated in the new structure of virtual hosts.
Red Hat: 2013:1524-01: openstack-keystone: Moderate Advisory
(Nov 18) Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat OpenStack 3.0. The Red Hat Security Response Team has rated this update as having moderate [More…]
The first beta of the 3.8 is now available, and the next dates to watch out for are code freeze on December 5th and a final release on December 12th. 3.8 brings together several of the features as plugins projects and while this isn’t our first rodeo, expect this to be more beta than usual. […]