(Jun 16) Update to latest nodejs-uri-js for CVE fix
Archive for Other
(Jun 16) Update to latest nodejs-uri-js for CVE fix
(Jun 15) – Fix CVE-2018-11396/CVE-2018-12016 (#795740) – Allow Ctrl+T in app mode again due to unintended consequences (#796204) – Don’t remember passwords when the setting is disabled (#796219) – Fix password manager crash on chase.com (GitLab #11)
(Jun 15) – doc Remove documentation for future option faked sys – build Don’t use dev srandom on OpenBSD – Do not use C99 feature – g10 Fix regexp sanitization – g10 Push compress filter only if compressed – gpg Sanitize diagnostic with the original file name [CVE-2018-12020]
(Jun 14) Several security issues were fixed in Ruby.
Ubuntu 3677-2: Linux kernel (HWE) vulnerabilities
(Jun 12) Several security issues were fixed in the Linux kernel.
Fedora 28: plexus-archiver Security Update
(Jun 14) Security fix: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file (CVE-2018-1002200) A path traversal vulnerability has been discovered in plexus-archiver when extracting a carefully crafted zip file which holds path traversal file names. A remote attacker could use this vulnerability to write files outside the target directory and overwrite
(Jun 15) GnuPG 2 could be made to present validity information incorrectly.
Ubuntu 3678-4: Linux kernel (Raspberry Pi 2) vulnerabilities
(Jun 15) Several security issues were fixed in the Linux kernel.
RedHat: RHSA-2018-1852:01 Moderate: kernel security update
(Jun 14) An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2018-1833:01 Important: Red Hat JBoss Data Grid 7.2.1 security
(Jun 12) An update for Red Hat JBoss Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Fedora 27: plexus-archiver Security Update
(Jun 14) Security fix: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file (CVE-2018-1002200) A path traversal vulnerability has been discovered in plexus-archiver when extracting a carefully crafted zip file which holds path traversal file names. A remote attacker could use this vulnerability to write files outside the target directory and overwrite
(Jun 14) Several vulnerabilities were found in SPIP, a website engine for publishing, resulting in cross-site scripting and PHP injection. For the oldstable distribution (jessie), this problem has been fixed
(Jun 13) – Upstream released new version – Fix a bunch of CVE’s
RedHat: RHSA-2018-1826:01 Important: kernel security, bug fix,
(Jun 12) An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
(Jun 13) Perl could be made to overwrite arbitrary files if it received a specially crafted archive file.
(Jun 13) Perl could be made to overwrite arbitrary files if it received a specially crafted archive file.
RedHat: RHSA-2018-1843:01 Important: Red Hat JBoss Core Services Apache
(Jun 13) An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
RedHat: RHSA-2018-1837:01 Important: rh-maven33-plexus-archiver and
(Jun 12) An update for rh-maven33-plexus-archiver and rh-maven35-plexus-archiver is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2018-1836:01 Important: plexus-archiver security update
(Jun 12) An update for plexus-archiver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Ubuntu 3678-3: Linux kernel (Azure) vulnerabilities
(Jun 12) Several security issues were fixed in the Linux kernel.
Ubuntu 3677-1: Linux kernel vulnerabilities
(Jun 12) Several security issues were fixed in the Linux kernel.
Debian: DSA-4227-1: plexus-archiver security update
(Jun 12) Danny Grander discovered a directory traversal flaw in plexus-archiver, an Archiver plugin for the Plexus compiler system, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted Zip archive.
Ubuntu 3678-1: Linux kernel vulnerabilities
(Jun 12) Several security issues were fixed in the Linux kernel.
Ubuntu 3678-2: Linux kernel (Azure) vulnerabilities
(Jun 12) Several security issues were fixed in the Linux kernel.
Debian: DSA-4219-1: jruby security update
(Jun 8) Several vulnerabilities were discovered in jruby, a Java implementation of the Ruby programming language. They would allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop,
RedHat: RHSA-2018-1825:01 Important: chromium-browser security update
(Jun 11) An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2018-1827:01 Critical: flash-plugin security update
(Jun 11) An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
(Jun 12) Jakub Wilk discovered a directory traversal flaw in the Archive::Tar module, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted tar archive.
Fedora 27: java-1.8.0-openjdk-aarch32 Security Update
(Jun 7) 8u171 update