(Aug 22) Pango could be made to crash if it opened a specially crafted file.
Archive for Other
Debian: DSA-4279-2: linux regression update
(Aug 22) The security update announced as DSA 4279-1 caused regressions on the ARM architectures (boot failures on some systems). Updated packages are now available to correct this issue.
Ubuntu 3749-1: Spidermonkey vulnerabilities
(Aug 22) Several security issues were fixed in Spidermonkey.
Ubuntu 3742-3: Linux kernel (Trusty HWE) regressions
(Aug 21) USN-3742-2 introduced regressions in the Linux Hardware Enablement(HWE) kernel for Ubuntu 12.04 ESM.
RedHat: RHSA-2018-2533:01 Important: openstack-keystone security update
(Aug 21) An update for openstack-keystone is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Debian: DSA-4280-1: openssh security update
(Aug 22) Dariusz Tytko, Michal Sajdak and Qualys Security discovered that OpenSSH, an implementation of the SSH protocol suite, was prone to a user enumeration vulnerability. This would allow a remote attacker to check whether a specific user account existed on the target server.
Ubuntu 3748-1: base-files vulnerability
(Aug 21) base-files could be made to hang or overwrite files as the administrator.
Ubuntu 3747-1: OpenJDK 10 vulnerabilities
(Aug 21) Several security issues were fixed in OpenJDK 10.
RedHat: RHSA-2018-2526:01 Important: mutt security update
(Aug 20) An update for mutt is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2018-2511:01 Important: rh-postgresql95-postgresql security
(Aug 20) An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Debian: DSA-4278-1: jetty9 security update
(Aug 19) Multiple vulnerabilities were discovered in Jetty, a Java servlet engine and webserver which could result in HTTP request smuggling. For the stable distribution (stretch), these problems have been fixed in
Debian: DSA-4279-1: linux security update
(Aug 20) Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read
RedHat: RHSA-2018-2523:01 Important: openstack-keystone security and bug
(Aug 20) An update for openstack-keystone is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2018-2524:01 Moderate: openvswitch security and bug fix update
(Aug 20) An update for openvswitch is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Fedora 28: yubico-piv-tool Security Update
(Aug 19) New upstream release fixing YSA-2018-03 (#1613863)
Debian: DSA-4273-1: intel-microcode security update
(Aug 16) This update ships updated CPU microcode for some types of Intel CPUs and provides SSBD support (needed to address “Spectre v4”) and fixes for “Spectre v3a”.
Fedora 27: yubico-piv-tool Security Update
(Aug 19) New upstream release fixing YSA-2018-03 (#1613863)
Ubuntu 3741-3: Linux kernel regressions
(Aug 17) Several security issues were fixed in the Linux kernel.
Ubuntu 0042-1: Linux kernel vulnerability
(Aug 14) On August 14, fixes for CVE-2018-3620 and CVE-2018-3646 were released into theUbuntu Xenial and Bionic kernels. These CVEs are security vulnerabilities caused by flaws in the design of speculative execution hardware in the computer’s CPU. Researchers discovered that memory present in the L1 datacache of an Intel CPU core may be visible to other processes running on the [More…]
RedHat: RHSA-2018-2462:01 Important: qemu-kvm security and bug fix update
(Aug 16) An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
RedHat: RHSA-2018-2439:01 Moderate: mariadb security and bug fix update
(Aug 16) An update for mariadb is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Ubuntu 3740-1: Linux kernel vulnerabilities
(Aug 14) Several security issues were fixed in the Linux kernel.
Ubuntu 3740-2: Linux kernel (HWE) vulnerabilities
(Aug 14) Several security issues were fixed in the Linux kernel.
RedHat: RHSA-2018-2469:01 Important: Red Hat JBoss Web Server 3.1.0 Service
(Aug 16) An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 6 and Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2018-2470:01 Important: Red Hat JBoss Web Server 3.1.0 Service
(Aug 16) An update is now available for Red Hat JBoss Web Server 3.1. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Debian: DSA-4274-1: xen security update
(Aug 16) This update provides mitigations for the “L1 Terminal Fault” vulnerability affecting a range of Intel CPUs. For additional information please refer to
Debian: DSA-4277-1: mutt security update
(Aug 17) Several vulnerabilities were discovered in Mutt, a text-based mailreader supporting MIME, GPG, PGP and threading, potentially leading to code execution, denial of service or information disclosure when connecting to a malicious mail/NNTP server.
(Aug 16) – units_cur: validate rate data from server (#1598913)
(Aug 16) rebase to 8.37.0 ———————- – few fixes and enhancements handling journal input – now requires librelp at least 1.2.16, adding support for setting address to bind – various other rsyslog core bugfixes and stability fixes
Debian: DSA-4275-1: keystone security update
(Aug 16) Kristi Nikolla discovered an information leak in Keystone, the OpenStack identity service, if running in a federated setup. For the stable distribution (stretch), this problem has been fixed in