(Aug 7) Fixes for CVE-2018-7032 (rhbz#1383312, rhbz#1383313)
Archive for August, 2018
(Aug 7) Update to 2.49.4 Based on the Firefox/Thunderbird ESR (extension support release) code version 52.9.1 Fixes various security issues, see https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/ and https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/ for more info.
Ubuntu 3732-2: Linux kernel (HWE) vulnerability
(Aug 6) The system could be made unavailable if it received specially craftednetwork traffic.
(Aug 7) GnuPG could be made to expose sensitive information.
Debian: DSA-4266-1: linux security update
(Aug 6) Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation or denial of service. CVE-2018-5390
Are all your sites mobile-friendly? Your mobile optimization checklist
Mobile users are a huge online traffic source, so you should optimize your sites for mobile. We have a mobile optimization checklist to tick off as you go.
The post Are all your sites mobile-friendly? Your mobile optimization checklist appeared first on Plesk.
Fedora 28: python-XStatic-jquery-ui Security Update
(Aug 3) Update Python 2 dependency declarations to new packaging standards
Debian: DSA-4261-1: vim-syntastic security update
(Aug 3) Enrico Zini discovered a vulnerability in Syntastic, an addon module for the Vim editor that runs a file through external checkers and displays any resulting errors. Config files were looked up in the current working directory which could result in arbitrary
(Aug 4) Update to 3.2.1 (CVE-2017-12627)
RedHat: RHSA-2018-2317:01 Moderate: xmlrpc security update
(Jul 31) An update for xmlrpc is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2018-2328:01 Important: rhvm-setup-plugins security, bug fix,
(Jul 31) An update for rhvm-setup-plugins is now available for Red Hat Virtualization Engine 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
How to get your team to adopt your coding standards
The staging environment vs test environment – what’s the difference? Learn which is which and why both are equally important for a website.
The post How to get your team to adopt your coding standards appeared first on Plesk.
Fedora 28: mingw-xerces-c Security Update
(Aug 4) Update to 3.2.1 (CVE-2017-12627)
Debian: DSA-4264-1: python-django security update
(Aug 5) Andreas Hug discovered an open redirect in Django, a Python web development framework, which is exploitable if django.middleware.common.CommonMiddleware is used and the APPEND_SLASH setting is enabled.
(Aug 4) Backport fix for CVE 2017-11548
RedHat: RHSA-2018-2309:01 Important: kernel security update
(Jul 31) An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact
RedHat: RHSA-2018-2308:01 Important: openslp security update
(Jul 31) An update for openslp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Debian: DSA-4265-1: xml-security-c security update
(Aug 5) It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.
Fedora 28: kernel-headers Security Update
(Aug 3) The 4.17.11 stable update contains a number of important fixes across the tree. Also of note, starting with this release, kernel-headers is built from a different srpm. The contents should be the same, but there were some benefits to breaking it from the kernel build. —- The 4.17.10 stable kernel update contains a number of important fixes across the tree.
Debian: DSA-4263-1: cgit security update
(Aug 4) Jann Horn discovered a directory traversal vulnerability in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of this flaw to retrieve arbitrary files via a specially crafted request, when ‘enable-http-clone=1’ (default) is not turned off.
(Aug 3) Sync with git (CVE-2017-14160, CVE-2018-10392, CVE-2018-10393, bz#1516379)
Debian: DSA-4262-1: symfony security update
(Aug 3) Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to open redirects, cross-site request forgery, information disclosure, session fixation or denial of service.
(Aug 2) Update to 2.26, fixes CVE-2018-9275
(Aug 2) Update to 2.26, fixes CVE-2018-9275
(Aug 2) Several security issues were fixed in ClamAV.
(Aug 2) Several security issues were fixed in ClamAV.
RedHat: RHSA-2018-2283:01 Moderate: java-1.7.0-openjdk security update
(Jul 30) An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2018-2286:01 Moderate: java-1.7.0-openjdk security update
(Jul 30) An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Debian: DSA-4260-1: libmspack security update
(Aug 2) Several vulnerabilities were discovered in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious CAB, CHM or KWAJ files and use these flaws to cause a denial of service via application crash, or potentially execute arbitrary code.
We are pleased to announce the immediate availability of WordPress 4.9.8. This maintenance release fixes 46 bugs, enhancements and blessed tasks, including updating the Twenty Seventeen bundled theme. Following are the highlights of what is now available. “Try Gutenberg” callout Most users will now be presented with a notice in their WordPress dashboard. This “Try Gutenberg” […]