(Apr 25) This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.
Archive for Other
Fedora 26: perl-Module-CoreList Security Update
(Apr 25) This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.
Debian: DSA-4180-1: drupal7 security update
(Apr 25) A remote code execution vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-004
Debian: DSA-4175-1: freeplane security update
(Apr 18) Wojciech Regula discovered an XML External Entity vulnerability in the XML Parser of the mindmap loader in freeplane, a Java program for working with mind maps, resulting in potential information disclosure if a malicious mind map file is opened.
RedHat: RHSA-2018-1252:01 Important: kernel security and bug fix update
(Apr 25) An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
RedHat: RHSA-2018-1251:01 Important: Red Hat JBoss Enterprise Application
(Apr 25) Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2, fixes several bugs, and adds various enhancements are now available for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact
(Apr 25) Several security issues were fixed in MySQL.
Ubuntu 3630-2: Linux kernel (HWE) vulnerability
(Apr 24) The system could be made to crash under certain conditions.
Debian: DSA-4176-1: mysql-5.5 security update
(Apr 20) Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.60, which includes additional changes. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for
Fedora 27: mingw-libid3tag Security Update
(Apr 23) Fix CVE-2017-11550 and CVE-2004-2779
Debian: DSA-4179-1: linux-tools security update
(Apr 24) This update doesn’t fix a vulnerability in linux-tools, but provides support for building Linux kernel modules with the “retpoline” mitigation for CVE-2017-5715 (Spectre variant 2).
Fedora 27: java-1.8.0-openjdk Security Update
(Apr 23) Update security update jdk8u171-b10
Fedora 26: java-1.8.0-openjdk Security Update
(Apr 22) Updated to securityupdate u171
Debian: DSA-4177-1: libsdl2-image security update
(Apr 20) Multiple vulnerabilities have been discovered in the image loading library for Simple DirectMedia Layer 2, which could result in denial of service or the execution of arbitrary code if malformed image files are opened.
(Apr 22) Security fix for CVE-2018-1000115, which disables the UDP port by default.
RedHat: RHSA-2018-1223:01 Critical: librelp security update
(Apr 24) An update for librelp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2018-1216:01 Important: kernel security and bug fix update
(Apr 24) An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.
Ubuntu 3631-1: Linux kernel vulnerabilities
(Apr 24) Several security issues were fixed in the Linux kernel.
Ubuntu 3631-2: Linux kernel (Xenial HWE) vulnerabilities
(Apr 24) Several security issues were fixed in the Linux kernel.
Debian: DSA-4178-1: libreoffice security update
(Apr 20) Two vulnerabilities were discovered in LibreOffice’s code to parse MS Word and Structured Storage files, which could result in denial of service and potentially the execution of arbitrary code if a malformed file is opened.
RedHat: RHSA-2018-1225:01 Critical: librelp security update
(Apr 24) An update for librelp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2018-1224:01 Moderate: PackageKit security update
(Apr 24) An update for PackageKit is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Ubuntu 3633-1: Linux kernel (Intel Euclid) vulnerability
(Apr 24) The system could be made to crash or run programs as an administrator.
Ubuntu 3632-1: Linux kernel (Azure) vulnerabilities
(Apr 24) Several security issues were fixed in the Linux kernel.
Debian: DSA-4136-1: curl security update
(Mar 14) Multiple vulnerabilities were discovered in cURL, an URL transfer library. CVE-2018-1000120
Debian: DSA-4143-1: firefox-esr security update
(Mar 17) Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execution of arbitrary code.
(Mar 13) nx-libs 3.5.0.33: – Don’t allow overriding of X.Org Server UNIX sockets via TEMP/NX_TEMP environment variables. Fixes problems on machines that use pam_tempdir.so. – Fix CVE-2017-2624 (timingsafe_memcmp) by Ulrich Sibiller. – Potentially improve LAN- and WAN-type connection speed settings scenarios. Includes a regression fix for VPN connections by Simon Matter. – Fix problems in
(Mar 13) nx-libs 3.5.0.33: – Don’t allow overriding of X.Org Server UNIX sockets via TEMP/NX_TEMP environment variables. Fixes problems on machines that use pam_tempdir.so. – Fix CVE-2017-2624 (timingsafe_memcmp) by Ulrich Sibiller. – Potentially improve LAN- and WAN-type connection speed settings scenarios. Includes a regression fix for VPN connections by Simon Matter. – Fix problems in
RedHat: RHSA-2018-0520:01 Critical: flash-plugin security update
(Mar 14) An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2018-0526:01 Critical: firefox security update
(Mar 15) An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from