Joe Vennix discovered an authentication bypass vulnerability in dbus, an asynchronous inter-process communication system. The implementation of the DBUS_COOKIE_SHA1 authentication mechanism was susceptible to a symbolic link attack. A local attacker could take advantage of this flaw
Archive for June, 2019
RedHat: RHSA-2019-1467:01 Important: python security update
An update for python is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Acronis and ZNetLive join forces to offer new security solution
The post Acronis and ZNetLive join forces to offer new security solution appeared first on Plesk.
1717503 – Security issue: patch 8.1.1365: source command doesn’t check for the sandbox
Resolves: rhbz#1718986 Updated to 3.29 for CVE-2019-10155 —- Updated to 3.28 (many imported bugfixes)
Fedora 30: containernetworking-plugins Security Update
Resolves: #1715758 – CVE-2019-9946
Fedora 30: python-urllib3 Security Update
Update to v1.24.3
Debian: DSA-4460-1: mediawiki security update
Multiple security vulnerabilities have been discovered in MediaWiki, a website engine for collaborative work, which may result in authentication bypass, denial of service, cross-site scripting, information disclosure and bypass of anti-spam measures.
Multiple security issues were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed file/stream is processed.
Debian: DSA-4461-1: zookeeper security update
Harrison Neil discovered that the getACL() command in Zookeeper, a service for maintaining configuration information, did not validate permissions, which could result in information disclosure.
Joomla 3.9.8 is now available. This is a bug fix release for the 3.x series of Joomla which addresses one bug introduced into 3.9.7 which affects web sites using the French Help Server.
RedHat: RHSA-2019-1456:01 Moderate: Red Hat Single Sign-On 7.3.2 security
A security update is now available for Red Hat Single Sign-On 7.3 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2019-1455:01 Important: Advanced Virtualization security update
The updated Advanced Virtualization module is now available for Red Hat Enterprise Linux 8.0 Advanced Virtualization. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Joomla 3.9.7 is now available. This is a security fix release for the 3.x series of Joomla which addresses three security vulnerabilities and contains over 40 bug fixes and improvements.
RedHat: RHSA-2019-1436:01 Moderate: rh-haproxy18-haproxy security, bug fix,
An update for rh-haproxy18-haproxy is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2019-1429:01 Important: CloudForms 4.7.5 security,
An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
[20190603] – Core – ACL hardening of com_joomlaupdate
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Versions: 3.8.13 through 3.9.6
- Exploit type: Incorrect Access Control
- Reported Date: 2019-April-10
- Fixed Date: 2019-June-11
- CVE Number: CVE-2019-12764
Description
The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.
Affected Installs
Joomla! CMS versions 3.8.13 through 3.9.6
Solution
Upgrade to version 3.9.7
Contact
The JSST at the Joomla! Security Centre.
[20190602] – Core – XSS in subform field
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 3.6.0 through 3.9.6
- Exploit type: XSS
- Reported Date: 2019-January-01
- Fixed Date: 2019-June-11
- CVE Number: CVE-2019-12766
Description
The subform fieldtype does not sufficiently filter or validate input of subfields, this leads to XSS attack vectors.
Affected Installs
Joomla! CMS versions 3.6.0 through 3.9.6
Solution
Upgrade to version 3.9.7
Contact
The JSST at the Joomla! Security Centre.
[20190601] – Core – CSV injection in com_actionlogs
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Versions: 3.9.0 through 3.9.6
- Exploit type: CSV Injection
- Reported Date: 2019-April-29
- Fixed Date: 2019-June-11
- CVE Number: CVE-2019-12765
Description
The CSV export of com_actionslogs is vulnerable to CSV injection.
Affected Installs
Joomla! CMS versions 3.9.0 through 3.9.6
Solution
Upgrade to version 3.9.7
Contact
The JSST at the Joomla! Security Centre.
RedHat: RHSA-2019-1423:01 Important: Red Hat OpenShift Container Platform
An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2019-1422:01 Moderate: OpenShift Container Platform 3.11
An update for atomic-openshift-web-console is now available for Red Hat Openshift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2019-1424:01 Moderate: Red Hat JBoss Enterprise Application
An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2019-1420:01 Moderate: Red Hat JBoss Enterprise Application
An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
The post The WordPress Toolkit 4.1 Update appeared first on Plesk.
Debian: DSA-4458-1: cyrus-imapd security update
A flaw was discovered in the CalDAV feature in httpd of the Cyrus IMAP server, leading to denial of service or potentially the execution of arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
1717503 – Security issue: patch 8.1.1365: source command doesn’t check for the sandbox
Update to version 3.0.10, which fixes a security issue (a buffer overrun vulnerability in the httpd daemon, CVE-2019-11356).
Debian: DSA-4457-1: evolution security update
Hanno Böck discovered that Evolution was vulnerable to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security bar with encryption and signature information above the message
Update to version 2.8 from upstream, Security fix for [CVE-2019-11555]
Update to version 3.0.10, which fixes a security issue (a buffer overrun vulnerability in the httpd daemon, CVE-2019-11356).