(Jan 31) Several security issues were fixed in Avahi.
Archive for Other
RedHat: RHSA-2019-0230:01 Important: polkit security update
(Jan 31) An update for polkit is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
RedHat: RHSA-2019-0237:01 Moderate: etcd security, bug fix,
(Jan 31) An update for etcd is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Fedora 29: docker-latest Security Update
(Jan 31) – Resolves: #1666565, #1667625 – CVE-2018-20699 – Resolves: #1663068, #1667626 – umount all procfs and sysfs with –no-pivot – built docker @projectatomic/docker-1.13.1 commit 1185cfd – built docker-runc @projectatomic/docker-1.13.1 commit e4ffe43
Debian: DSA-4377-1: rssh security update
(Jan 30) The ESnet security team discovered a vulnerability in rssh, a restricted shell that allows users to perform only scp, sftp, cvs, svnserve (Subversion), rdist and/or rsync operations. Missing validation in the scp support could result in the bypass of this restriction, allowing the
Debian: DSA-4378-1: php-pear security update
(Jan 30) Fariskhi Vidyan discovered that the PEAR Archive_Tar package for handling tar files in PHP is prone to a PHP object injection vulnerability, potentially allowing a remote attacker to execute arbitrary code.
(Jan 31) Multiple CVE fixes.
RedHat: RHSA-2019-0219:01 Critical: firefox security update
(Jan 30) An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2019-0218:01 Critical: firefox security update
(Jan 30) An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
(Jan 30) Java applets or applications could be made to expose sensitiveinformation.
Ubuntu 3874-1: Firefox vulnerabilities
(Jan 30) Firefox could be made to crash or run programs as your login if it opened a malicious website.
(Jan 30) Security fix for CVE-2019-6706.
Debian: DSA-4375-1: spice security update
(Jan 29) Christophe Fergeau discovered an out-of-bounds read vulnerability in spice, a SPICE protocol client and server library, which might result in denial of service (spice server crash), or possibly, execution of arbitrary code.
Fedora 29: mingw-qt5-qtxmlpatterns Security Update
(Jan 30) Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.
Ubuntu 3872-1: Linux kernel (HWE) vulnerabilities
(Jan 29) Several security issues were fixed in the Linux kernel.
Ubuntu 3871-1: Linux kernel vulnerabilities
(Jan 29) Several security issues were fixed in the Linux kernel.
RedHat: RHSA-2019-0162:01 Moderate: kernel-alt security, bug fix,
(Jan 29) An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2019-0194:01 Moderate: bind security update
(Jan 29) An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Debian: DSA-4374-1: qtbase-opensource-src security update
(Jan 28) Several issues were discovered in qtbase-opensource-src, a cross-platform C++ application framework, which could lead to denial-of-service via application crash. Additionally, this update fixes a problem affecting vlc, where it would start without a GUI.
Debian: DSA-4373-1: coturn security update
(Jan 28) Multiple vulnerabilities were discovered in coTURN, a TURN and STUN server for VoIP. CVE-2018-4056
(Jan 28) Spice could be made to crash or run programs if it received specially crafted network traffic.
Debian: DSA-4372-1: ghostscript security update
(Jan 26) Tavis Ormandy discovered a vulnerability in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).
(Jan 22) An attacker could trick APT into installing altered packages.
(Jan 24) Security fix for CVE-2019-5010 in Python. Anaconda is joined because an unrelated fix was done there that allowed to remove a workaround in Python.
(Jan 23) Several security issues were fixed in NTP.
(Jan 22) An attacker could trick APT into installing altered packages.
RedHat: RHSA-2019-0131:01 Moderate: Red Hat JBoss Web Server 3.1 Service
(Jan 22) An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 6 and Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2019-0130:01 Moderate: Red Hat JBoss Web Server 3.1 Service
(Jan 22) An update is now available for Red Hat JBoss Web Server 3.1. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
(Jan 25) New Version
(Jan 25) New Version