(Mar 21) Several security issues were fixed in ClamAV.
Archive for Other
Ubuntu: 1772-1: OpenStack Keystone vulnerability
(Mar 20) Under certain configurations, Keystone would allow unintended access overthe network.
Red Hat: 2013:0662-01: kernel: Important Advisory
(Mar 19) Updated kernel packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux 6.3 Extended Update Support. The Red Hat Security Response Team has rated this update as having [More…]
Debian: 2648-1: firebird2.5: Multiple vulnerabilities
(Mar 15) A buffer overflow was discovered in the Firebird database server, which could result in the execution of arbitrary code. In addition, a denial of service vulnerability was discovered in the TraceManager. [More…]
Debian: 2647-1: firebird2.1: buffer overflow
(Mar 15) A buffer overflow was discovered in the Firebird database server, which could result in the execution of arbitrary code. For the stable distribution (squeeze), this problem has been fixed in [More…]
(Mar 19) Perl could be made to stop responding if it received specially craftedinput.
Ubuntu: 1765-1: Apache HTTP Server vulnerabilities
(Mar 18) Several security issues were fixed in the Apache HTTP Server.
Red Hat: 2013:0661-01: kernel: Important Advisory
(Mar 19) Updated kernel packages that fix one security issue and one bug are now available for Red Hat Enterprise Linux 6.1 Extended Update Support. The Red Hat Security Response Team has rated this update as having [More…]
Red Hat: 2013:0663-01: sssd: Moderate Advisory
(Mar 19) Updated sssd packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Debian: 2649-1: lighttpd: fixed socket name in world-
(Mar 15) Stefan Bühler discovered that the Debian specific configuration file for lighttpd webserver FastCGI PHP support used a fixed socket name in the world-writable /tmp directory. A symlink attack or a race condition could be exploited by a malicious user on the same machine to take over the PHP control [More…]
Debian: 2646-1: typo3-src: Multiple vulnerabilities
(Mar 15) Typo3, a PHP-based content management system, was found vulnerable to several vulnerabilities. CVE-2013-1842 [More…]
Ubuntu: 1767-1: Linux kernel vulnerabilities
(Mar 18) Several security issues were fixed in the kernel.
Ubuntu: 1766-1: pam-xdg-support vulnerability
(Mar 18) pam-xdg-support could be made to run programs as an administrator.
Debian: 2650-2: libvirt: files and device nodes owne
(Mar 17) The recent security update for libvirt was found to cause a regression. The kvm/qemu processes weren’t run as the `kvm` user anymore in order to fix the file/device ownership changes, but the processes where not correctly configured to use the `kvm` group either. When the user would [More…]
Debian: 2650-1: libvirt-bin: files and device nodes owne
(Mar 15) Bastian Blank discovered that libvirtd, a daemon for management of virtual machines, network and storage, would change ownership of devices files so they would be owned by user `libvirt-qemu` and group `kvm`, which is a general purpose group not specific to libvirt, allowing unintended write access to [More…]
Ubuntu: 1769-1: Linux kernel vulnerabilities
(Mar 18) Several security issues were fixed in the kernel.
Ubuntu: 1768-1: Linux kernel (Quantal HWE) vulnerabilities
(Mar 18) Several security issues were fixed in the kernel.
Red Hat: 2013:0656-01: krb5: Moderate Advisory
(Mar 18) Updated krb5 packages that fix two security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Debian: 2644-1: wireshark: Multiple vulnerabilities
(Mar 14) Multiple vulnerabilities were discovered in the dissectors for the MS-MMS, RTPS, RTPS2, Mount, ACN, CIMD and DTLS protocols, which could result in denial of service or the execution of arbitrary code. [More…]
(Mar 14) An attacker could trick APT into installing altered packages.
(Mar 14) NSS could be made to expose sensitive information over the network.
Red Hat: 2013:0622-01: kernel-rt: Important Advisory
(Mar 11) Updated kernel-rt packages that fix several security issues and three bugs are now available for Red Hat Enterprise MRG 2.3. The Red Hat Security Response Team has rated this update as having [More…]
Red Hat: 2013:0627-01: thunderbird: Important Advisory
(Mar 11) An updated thunderbird package that fixes one security issue is now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having [More…]
Debian: 2645-1: inetutils: denial of service
(Mar 14) Ovidiu Mara reported in 2010 a vulnerability in the ping util, commonly used by system and network administrators. By carefully crafting ICMP responses, an attacker could make the ping command hangs. [More…]
Debian: 2640-1: zoneminder: several issues
(Mar 14) Multiple vulnerabilities were discovered in zoneminder, a Linux video camera security and surveillance solution. The Common Vulnerabilities and Exposures project identifies the following problems: [More…]
Ubuntu: 1764-1: OpenStack Glance vulnerability
(Mar 14) Glance could be made to expose sensitive information over the network.
(Mar 14) NSPR update to work with the new NSS.
Red Hat: 2013:0646-01: pidgin: Moderate Advisory
(Mar 14) Updated pidgin packages that fix three security issues are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate [More…]
Red Hat: 2013:0623-01: tomcat6: Important Advisory
(Mar 11) Updated tomcat6 packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More…]
(Mar 12) Several security issues were fixed in Puppet.