Secure Encrypted Virtualization (SEV) on Advanced Micro Devices(AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation. This update provides Amd SEV Firmware to 0.17 build 22 (CVE-2019-9836). . MGASA-2019-0207 - Updated microcode package fixes security vulnerability Publication date: 10 Jul 2019 URL: https://advisories.mageia.org/MGASA-2019-0207.html Type: security Affected Mageia releases: 6, 7 CVE: CVE-2019-9836 Secure Encrypted Virtualization (SEV) on Advanced Micro Devices(AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation. This update provides Amd SEV Firmware to 0.17 build 22 (CVE-2019-9836). It also updates the Intel Microcode for the following: * SNB-E/EN/EP C1/M0 6-2d-6/6d 0000061d-> 0000061f Xeon E3/E5, Core X * SNB-E/EN/EP C2/M1 6-2d-7/6d 00000714-> 00000718 Xeon E3/E5, Core X References: - https://bugs.mageia.org/show_bug.cgi?id=25053 - https://www.cve.org/CVERecord?id=CVE-2019-9836 SRPMS: - 6/nonfree/microcode-0.20190618-1.mga6.nonfree - 7/nonfree/microcode-0.20190618-1.mga7.nonfree . MGASA-2019-0207 - Updated microcode package fixes security vulnerability Publication date: 10 Jul 20. secure, encrypted, virtualization, (sev), advanced, micro, devices(amd), platform, security, processor. . LinuxSecurity.com Team
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in privilege escalation, denial of service, newline injection in SMTP or use of insecure cryptography. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3858-1
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in breakouts of the Java sandbox, information disclosur, denial of service and insecure cryptography. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3458-1
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in the execution of arbitrary code, breakouts of the Java sandbox, information disclosure, denial of service or insecure cryptography. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3339-1
Get the latest Linux and open source security news straight to your inbox.