Explore top 10 tips to secure your open-source projects now. Read More
×
Two security issues were found in pgpool-II, the connection pool server and replication proxy for PostgreSQL, which could result in authentication bypass and exposure of sensitive information. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5974-1
It was discovered that Awstats, a web server log analyzer, was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution. The previous fix did not fully address the issue when the default . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2506-1
It was found that samba did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man- in-the-middle attack and retrieve information in plain-text. (CVE-2017-12150) * A flaw was found in the way samba client used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS re [More...]. Synopsis: Moderate: samba security update Advisory ID: SLSA-2017:2790-1 Issue Date: 2017-09-21 CVE Numbers: CVE-2017-12150 CVE-2017-12163 CVE-2017-12151 -- Security Fix(es): * It was found that samba did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man- in-the-middle attack and retrieve information in plain-text. (CVE-2017-12150) * A flaw was found in the way samba client used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack. (CVE-2017-12151) * An information leak flaw was found in the way SMB1 protocol was implemented by Samba. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker. (CVE-2017-12163) -- SL7 x86_64 libsmbclient-4.6.2-11.el7_4.i686.rpm libsmbclient-4.6.2-11.el7_4.x86_64.rpm libwbclient-4.6.2-11.el7_4.i686.rpm libwbclient-4.6.2-11.el7_4.x86_64.rpm samba-client-4.6.2-11.el7_4.x86_64.rpm samba-client-libs-4.6.2-11.el7_4.i686.rpm samba-client-libs-4.6.2-11.el7_4.x86_64.rpm samba-common-libs-4.6.2-11.el7_4.x86_64.rpm samba-common-tools-4.6.2-11.el7_4.x86_64.rpm samba-debuginfo-4.6.2-11.el7_4.i686.rpm samba-debuginfo-4.6.2-11.el7_4.x86_64.rpm samba-krb5-printing-4.6.2-11.el7_4.x86_64.rpm samba-libs-4.6.2-11.el7_4.i686.rpm samba-libs-4.6.2-11.el7_4.x86_64.rpm samba-winbind-4.6.2-11.el7_4.x86_64.rpm samba-winbind-clients-4.6.2-11.el7_4.x86_64.rpm samba-winbind-modules-4.6.2-11.el7_4.i686.rpm samba-winbind-modules-4.6.2-11.el7_4.x86_64.rpm libsmbclient-devel-4.6.2-11.el7_4.i686.rpm libsmbclient-devel-4.6.2-11.el7_4.x86_64.rpm libwbclient-devel-4.6.2-11.el7_4.i686.rpm libwbclient-devel-4.6.2-11.el7_4.x86_64.rpm samba-4.6.2-11.el7_4.x86_64.rpm samba-dc-4.6.2-11.el7_4.x86_64.rpm samba-dc-libs-4.6.2-11.el7_4.x86_64.rpm samba-devel-4.6.2-11.el7_4.i686.rpm samba-devel-4.6.2-11.el7_4.x86_64.rpm samba-python-4.6.2-11.el7_4.x86_64.rpm samba-test-4.6.2-11.el7_4.x86_64.rpm samba-test-libs-4.6.2-11.el7_4.i686.rpm samba-test-libs-4.6.2-11.el7_4.x86_64.rpm samba-vfs-glusterfs-4.6.2-11.el7_4.x86_64.rpm samba-winbind-krb5-locator-4.6.2-11.el7_4.x86_64.rpm noarch samba-common-4.6.2-11.el7_4.noarch.rpm samba-pidl-4.6.2-11.el7_4.noarch.rpm - Scientific Linux Development Team . Samba security patch notification concerns intermediate risks in SL7.x related to SMB authentication and ciphering weaknesses.. Samba Security, SL7 Network, SA Update, Moderate Threats, SMB Protocol. . LinuxSecurity.com Team
Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS (the Mozilla Network Security Service library, embedded in Wheezy's Iceweasel package), was parsing ASN.1 data used in signatures, making it vulnerable to a signature forgery attack. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3034-1
Several vulnerabilities were discovered in Postfix, a mail transfer agent. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2233-1
Get the latest Linux and open source security news straight to your inbox.