(Jul 29) Fix for CVE-2018-13785: the libpng10 library was vulnerable to an integer overflow and resultant divide-by-zero in the pngrutil.c:png_check_chunk_length() function. An attacker could exploit this to cause a denial of service via a crafted PNG file.
Archive for July 29th, 2018
Fedora 28: java-1.8.0-openjdk Security Update
(Jul 29) Security critical patch update for OpenJDK (July CPU). See http://www.oracle.com/technetwork/security- advisory/cpujul2018-4258247.html#AppendixJAVA
RedHat: RHSA-2018-2268:01 Important: procps security update
(Jul 26) An update for procps is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact
RedHat: RHSA-2018-2274:01 Moderate: Red Hat Ceph Storage 2.5 security,
(Jul 26) An update for ceph is now available for Red Hat Ceph Storage 2.5 for Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Debian: DSA-4257-1: fuse security update
(Jul 28) Jann Horn discovered that FUSE, a Filesystem in USErspace, allows the bypass of the ‘user_allow_other’ restriction when SELinux is active (including in permissive mode). A local user can take advantage of this flaw in the fusermount utility to bypass the system configuration and