Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
xen: various flaws (#1518214) x86: infinite loop due to missing PoD error checking [XSA-246] Missing p2m error checking in PoD code [XSA-247]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-4bfcd57172 2017-12-10 03:53:15.787480 --------------------------------------------------------------------------------Name : xen Product : Fedora 27 Version : 4.9.1 Release : 2.fc27 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor --------------------------------------------------------------------------------Update Information: xen: various flaws (#1518214) x86: infinite loop due to missing PoD error checking [XSA-246] Missing p2m error checking in PoD code [XSA-247] --------------------------------------------------------------------------------References: [ 1 ] Bug #1513335 - CVE-2017-17044 xsa246 xen: x86: infinite loop due to missing PoD error checking (XSA-246) https://bugzilla.redhat.com/show_bug.cgi?id=1513335 [ 2 ] Bug #1513336 - CVE-2017-17045 xsa247 xen: Missing p2m error checking in PoD code (XSA-247) https://bugzilla.redhat.com/show_bug.cgi?id=1513336 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade xen' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-2829-1 December 04, 2015 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: It was discovered that the SCTP protocol implementation in the Linux kernel performed an incorrect sequence of protocol-initialization steps. A local attacker could use this to cause a denial of service (system crash). (CVE-2015-5283) Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted to garbage collect incompletely instantiated keys. A local unprivileged attacker could use this to cause a denial of service (system crash). (CVE-2015-7872) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: linux-image-3.19.0-39-generic 3.19.0-39.44 linux-image-3.19.0-39-generic-lpae 3.19.0-39.44 linux-image-3.19.0-39-lowlatency 3.19.0-39.44 linux-image-3.19.0-39-powerpc-e500mc 3.19.0-39.44 linux-image-3.19.0-39-powerpc-smp 3.19.0-39.44 linux-image-3.19.0-39-powerpc64-emb 3.19.0-39.44 linux-image-3.19.0-39-powerpc64-smp 3.19.0-39.44 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this aswell. References: CVE-2015-5283, CVE-2015-7872 Package Information: https://launchpad.net/ubuntu/+source/linux/3.19.0-39.44 . The latest Ubuntu security bulletin highlights significant kernel vulnerabilities, prompting users to apply necessary updates to safeguard their systems.. Ubuntu Kernel Updates, Linux Security Advisory, Denial of Service Risks, System Crash Fixes. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in PHP: CVE-2015-4025 / CVE-2015-4026 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3280-1
Port of freetype2 security fixes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-5644 2009-05-28 07:03:15 -------------------------------------------------------------------------------- Name : freetype1 Product : Fedora 11 Version : 1.4 Release : 0.8.pre.fc11 URL : https://freetype.org/ Summary : Free TrueType font rendering engine, compatibility version Description : The FreeType engine is a free and portable TrueType font rendering engine, developed to provide TrueType support for a variety of platforms and environments. FreeType is a library which can open and manages font files as well as efficiently load, hint and render individual glyphs. FreeType is not a font server or a complete text-rendering library. This package contains the obsolote version 1.x of FreeType for applications which still need this old version. New applications should use the more advanced FreeType 2.x library packaged as freetype. -------------------------------------------------------------------------------- Update Information: Port of freetype2 security fixes -------------------------------------------------------------------------------- ChangeLog: * Tue May 26 2009 Adam Jackson 1.4-0.8.pre - cve-2006-1861.patch, cve-2007-2754.patch: Port of freetype2 fixes. (#502565) -------------------------------------------------------------------------------- References: [ 1 ] Bug #502565 - CVE-2006-1861 CVE-2007-2754 Multiple freetype1 vulnerabilities [Fedora rawhide] https://bugzilla.redhat.com/show_bug.cgi?id=502565 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update freetype1' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
CVE-2009-1364 libwmf: embedded gd use-after-free error. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-5524 2009-05-27 01:31:24 -------------------------------------------------------------------------------- Name : libwmf Product : Fedora 10 Version : 0.2.8.4 Release : 18.1.fc10 URL : https://wvware.sourceforge.net/libwmf.html Summary : Windows MetaFile Library Description : A library for reading and converting Windows MetaFile vector graphics (WMF). -------------------------------------------------------------------------------- Update Information: CVE-2009-1364 libwmf: embedded gd use-after-free error -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- References: [ 1 ] Bug #496864 - CVE-2009-1364 libwmf: embedded gd use-after-free error https://bugzilla.redhat.com/show_bug.cgi?id=496864 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libwmf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.