SUMMARY The PHP development team announces the immediate availability of PHP 5.4.19 and PHP 5.5.3. These releases fix a bug in the patch for CVE-2013-4248 in the OpenSSL module and a compile failure with ZTS enabled in PHP 5.4. All PHP users are encouraged to upgrade to either PHP 5.5.3 …
Posts Tagged CVE
Debian: 2741-1: chromium-browser: Multiple vulnerabilities
(Aug 25) Several vulnerabilities have been discovered in the Chromium web browser. CVE-2013-2887 [More…]
SUMMARY The PHP development team has announced the immediate availability of PHP 5.5.2. This release contains approximately 20 bug fixes, including a security issue in the OpenSSL module (CVE-2013-4248) and a session fixation problem (CVE-2011-4718). All users of PHP are encouraged to upgrade to this release. cPanel has released EasyApache …
SUMMARY The PHP development team announces the immediate availability of PHP 5.4.18. About 30 bugs were fixed, including security issues CVE-2013-4113 and CVE-2013-4248. All users of PHP are encouraged to upgrade to this release. cPanel has released EasyApache 3.22.5 with this updated version of PHP 5.4.18 to address this issue. …
Debian: 2732-1: chromium-browser: Multiple vulnerabilities
(Aug 2) Several vulnerabilities have been discovered in the Chromium web browser. CVE-2013-2881 [More…]
The following issues have been fixed:
[-] (Windows only) Security fix: BIND has been updated to version 9.8.5-P2, that also fixes CVE-2013-4854
[-] Security improvements. We would like to thank Rack911.com for their help in investigating a number of security issues.
The following issues have been fixed:
[-] (Windows only) Security fix: BIND has been updated to version 9.9.3-P2, that also fixes CVE-2013-4854
[-] Security improvements. We would like to thank Rack911.com for their help in investigating a number of security issues.
[-] Plesk provisioning through Parallels Automation may not work after upgrade from older Plesk versions (140589)
SUMMARY The Apache HTTPD Server Project have released httpd-2.2.25 and httpd-2.4.6 to correct multiple vulnerabilities that were issues CVE’s. Apache HTTP Server 2.2.25 CVE-2013-1896 mod_dav: Sending a MERGE request against a URI handled by mod_dav_svn with the source href (sent as part of the request body as XML) pointing to …
Debian: 2725-1: tomcat6: Multiple vulnerabilities
(Jul 18) Two security issues have been found in the Tomcat servlet and JSP engine: CVE-2012-3544 [More…]
Debian: 2724-1: chromium-browser: Multiple vulnerabilities
(Jul 18) Several vulnerabilities have been discovered in the Chromium web browser. CVE-2013-2853 [More…]
Debian: 2719-1: poppler: several vulnerabilities
(Jul 10) Multiple vulnerabilities were discovered in the poppler PDF rendering library. CVE-2013-1788 [More…]
Debian: 2717-1: xml-security-c: heap overflow
(Jun 28) Jon Erickson of iSIGHT Partners Labs discovered a heap overflow in xml-security-c, an implementation of the XML Digital Security specification. The fix to address CVE-2013-2154 introduced the possibility of a heap overflow in the processing of malformed XPointer [More…]
Debian: 2711-1: haproxy: Multiple vulnerabilities
(Jun 19) Multiple security issues have been found in HAProxy, a load-balancing reverse proxy: CVE-2012-2942 [More…]
(Jun 18) Multiple issues were discovered in the TIFF tools, a set of utilities for TIFF image file manipulation and conversion. CVE-2013-1960 [More…]
Debian: 2706-1: chromium-browser: Multiple vulnerabilities
(Jun 10) Several vulnerabilities have been discovered in the chromium web browser. CVE-2013-2855 [More…]
The following bug has been fixed:
[-] Fixed moderate security issue with privilege escalation.
More details in article Public issues VU#310500 and CVE-2013-0132, CVE-2013-0133
This MU is recommended for all Parallels Plesk Panel users.
The following bug has been fixed:
[-] Fixed moderate security issue with privilege escalation.
More details in article Public issues VU#310500 and CVE-2013-0132, CVE-2013-0133
This MU is recommended for all Parallels Plesk Panel users.
The following bug has been fixed:
[-] Fixed moderate security issue with privilege escalation.
More details in article Public issues VU#310500 and CVE-2013-0132, CVE-2013-0133
This MU is recommended for all Parallels Plesk Panel users.
The following bug has been fixed:
[-] Fixed moderate security issue with privilege escalation.
More details in article Public issues VU#310500 and CVE-2013-0132, CVE-2013-0133
This MU is recommended for all Parallels Plesk Panel users.
The following bug has been fixed:
[-] Fixed moderate security issue with privilege escalation. Parallels Plesk Panel versions 9.x-11.x with Apache web server running mod_php, mod_perl, mod_python, etc. is vulnerable to authenticated user privilege escalation. Authenticated users are users that have login to Parallels Plesk Panel (such as f.e. your customers, resellers, or your employees).
Parallels Plesk Panel instances with Apache web server configured with Fast CGI (PHP, perl, python, etc) or CGI (PHP, perl, python, etc) are NOT vulnerable.
More details in article Public issues VU#310500 and CVE-2013-0132, CVE-2013-0133
This MU is recommended for all Parallels Plesk Panel users.
The following bug has been fixed:
[-] Fixed moderate security issue with privilege escalation. Parallels Plesk Panel versions 9.x-11.x with Apache web server running mod_php, mod_perl, mod_python, etc. is vulnerable to authenticated user privilege escalation. Authenticated users are users that have login to Parallels Plesk Panel (such as f.e. your customers, resellers, or your employees).
Parallels Plesk Panel instances with Apache web server configured with Fast CGI (PHP, perl, python, etc) or CGI (PHP, perl, python, etc) are NOT vulnerable.
More details in article Public issues VU#310500 and CVE-2013-0132, CVE-2013-0133
This MU is recommended for all Parallels Plesk Panel users.
The following bug has been fixed:
[-] Fixed moderate security issue with privilege escalation. Parallels Plesk Panel versions 9.x-11.x with Apache web server running mod_php, mod_perl, mod_python, etc. is vulnerable to authenticated user privilege escalation. Authenticated users are users that have login to Parallels Plesk Panel (such as f.e. your customers, resellers, or your employees).
Parallels Plesk Panel instances with Apache web server configured with Fast CGI (PHP, perl, python, etc) or CGI (PHP, perl, python, etc) are NOT vulnerable.
More details in article Public issues VU#310500 and CVE-2013-0132, CVE-2013-0133
This MU is recommended for all Parallels Plesk Panel users.
Debian: 2658-1: postgresql-9.1: Multiple vulnerabilities
(Apr 4) Several vulnerabilities were discovered in PostgreSQL database server. CVE-2013-1899 [More…]
Debian: 2646-1: typo3-src: Multiple vulnerabilities
(Mar 15) Typo3, a PHP-based content management system, was found vulnerable to several vulnerabilities. CVE-2013-1842 [More…]
Debian: 2643-1: puppet: Multiple vulnerabilities
(Mar 12) Multiple vulnerabilities were discovered in Puppet, a centralized configuration management system. CVE-2013-1640 [More…]
(Mar 4) Several vulnerabilities have been found in the Apache HTTPD server. CVE-2012-3499 [More…]
Debian: 2629-1: openjpeg: several issues
(Feb 25) CVE-2009-5030 Heap memory corruption leading to invalid free when processing certain Gray16 TIFF images. [More…]
Debian: 2626-1: lighttpd: several issues
(Feb 17) Several vulnerabilities were discovered in the TLS/SSL protocol. This update addresses these protocol vulnerabilities in lighttpd. CVE-2009-3555 [More…]
Debian: 2621-1: openssl: Multiple vulnerabilities
(Feb 13) Multiple vulnerabilities have been found in OpenSSL. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-0166 [More…]
Debian: 2622-1: polarssl: Multiple vulnerabilities
(Feb 13) Multiple vulnerabilities have been found in OpenSSL. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-0169 [More…]