Explore top 10 tips to secure your open-source projects now. Read More
×fix possible issue reported by OSH 2.4.16 (fedora#2417970) rebuild due binutils bug (fedora#2418285) fix division by zero crash in pstops (fedora#2415396). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c09b980696 2025-12-18 01:10:20.380944+00:00 -------------------------------------------------------------------------------- Name : cups Product : Fedora 42 Version : 2.4.16 Release : 4.fc42 URL : https://openprinting.github.io/cups/ Summary : CUPS printing system Description : CUPS printing system provides a portable printing layer for UNIX operating systems. It has been developed by Apple Inc. to promote a standard printing solution for all UNIX vendors and users. CUPS provides the System V and Berkeley command-line interfaces. -------------------------------------------------------------------------------- Update Information: fix possible issue reported by OSH 2.4.16 (fedora#2417970) rebuild due binutils bug (fedora#2418285) fix division by zero crash in pstops (fedora#2415396) -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 12 2025 Zdenek Dohnal - 1:2.4.16-4 - fix possible issue reported by OSH * Fri Dec 5 2025 Zdenek Dohnal - 1:2.4.16-3 - rebuilt without reverted commit (upgrade script for PeerCred is not needed) * Thu Dec 4 2025 Zdenek Dohnal - 1:2.4.16-1 - 2.4.16 (fedora#2417970) - rebuild due binutils bug (fedora#2418285) - fix division by zero crash in pstops (fedora#2415396) * Fri Nov 28 2025 Zdenek Dohnal - 1:2.4.15-1 - 2.4.15 - fixes for CVE-2025-61915 and CVE-2025-58436 * Fri Nov 28 2025 Than Ngo - 1:2.4.14-4 - Rebuilt with new binutils in rawhide due to rhbz#2415824 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2420911 - CVE-2025-61915 cups: Local denial-of-service via cupsd.conf update and related issues [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2420911 [ 2 ] Bug #2420913 - CVE-2025-58436 cups: Slow client communication leads to a possible DoS attack [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2420913 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c09b980696' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . CUPS Fedora 42 update fixes local DoS issues and related crashes. Stay secure with this essential fix.. CUPS fixing,dos issues,Fedora updates,linux security. . Severity: Critical. LinuxSecurity.com Team
Several security vulnerabilities have been corrected in unbound, a validating, recursive, caching DNS resolver. Support for the unbound DNS server has been resumed, the sources can be found in the unbound1.9 source package. . -------------------------------------------------------------------------Debian LTS Advisory DLA-2556-1
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for xrdp ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2142-1 Rating: important References: #1173580 Cross-References: CVE-2020-4044 Affected Products: SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for xrdp fixes the following issues: - Update to version 0.9.13.1 + This is a security fix release that includes fixes for the following local buffer overflow vulnerability (bsc#1173580): CVE-2020-4044 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-2142=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libpainter0-0.9.13.1-4.3.1 libpainter0-debuginfo-0.9.13.1-4.3.1 librfxencode0-0.9.13.1-4.3.1 librfxencode0-debuginfo-0.9.13.1-4.3.1 xrdp-0.9.13.1-4.3.1 xrdp-debuginfo-0.9.13.1-4.3.1 xrdp-debugsource-0.9.13.1-4.3.1 xrdp-devel-0.9.13.1-4.3.1 References: https://www.suse.com/security/cve/CVE-2020-4044.html https://bugzilla.suse.com/1173580 _______________________________________________ sle-security-updates mailing list
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 5 for SLE 12 SP3) ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2248-1 Rating: important References: #1090338 #1096740 Cross-References: CVE-2018-3665 Affected Products: SUSE Linux Enterprise Live Patching 12-SP3 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for the Linux Kernel 4.4.92-6_30 fixes several issues. The following security issue was fixed: - CVE-2018-3665: System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially have allowed a local process to infer data from another process via a speculative execution side channel (bsc#1090338, bsc#1096740). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12-SP3: zypper in -t patch SUSE-SLE-Live-Patching-12-SP3-2018-1520=1 Package List: - SUSE Linux Enterprise Live Patching 12-SP3 (ppc64le x86_64): kgraft-patch-4_4_92-6_30-default-7-2.5 kgraft-patch-4_4_92-6_30-default-debuginfo-7-2.5 References: https://www.suse.com/security/cve/CVE-2018-3665.html https://bugzilla.suse.com/1090338 https://bugzilla.suse.com/1096740 . Crucial Red Hat Security Patch tackles a significant flaw in the Linux Kernel to improve overall system reliability and efficiency.. Linux Kernel Patch, SUSE Security Update, Important Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for util-linux ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2066-1 Rating: moderate References: #1084300 Cross-References: CVE-2018-7738 Affected Products: SUSE Linux Enterprise Module for Server Applications 15 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for util-linux fixes the following security issue: - CVE-2018-7738: Fix local vulnerability using embedded shell commands in a mountpoint name (bsc#1084300) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-2018-1397=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1397=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15 (aarch64 ppc64le s390x x86_64): util-linux-systemd-debuginfo-2.31.1-9.3.1 util-linux-systemd-debugsource-2.31.1-9.3.1 uuidd-2.31.1-9.3.1 uuidd-debuginfo-2.31.1-9.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): libblkid-devel-2.31.1-9.3.1 libblkid-devel-static-2.31.1-9.3.1 libblkid1-2.31.1-9.3.1 libblkid1-debuginfo-2.31.1-9.3.1 libfdisk-devel-2.31.1-9.3.1 libfdisk1-2.31.1-9.3.1 libfdisk1-debuginfo-2.31.1-9.3.1 libmount-devel-2.31.1-9.3.1 libmount1-2.31.1-9.3.1 libmount1-debuginfo-2.31.1-9.3.1 libsmartcols-devel-2.31.1-9.3.1 libsmartcols1-2.31.1-9.3.1 libsmartcols1-debuginfo-2.31.1-9.3.1 libuuid-devel-2.31.1-9.3.1 libuuid-devel-static-2.31.1-9.3.1 libuuid1-2.31.1-9.3.1 libuuid1-debuginfo-2.31.1-9.3.1 util-linux-2.31.1-9.3.1 util-linux-debuginfo-2.31.1-9.3.1 util-linux-debugsource-2.31.1-9.3.1 util-linux-systemd-2.31.1-9.3.1 util-linux-systemd-debuginfo-2.31.1-9.3.1 util-linux-systemd-debugsource-2.31.1-9.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (x86_64): libblkid1-32bit-2.31.1-9.3.1 libblkid1-32bit-debuginfo-2.31.1-9.3.1 libmount1-32bit-2.31.1-9.3.1 libmount1-32bit-debuginfo-2.31.1-9.3.1 libuuid1-32bit-2.31.1-9.3.1 libuuid1-32bit-debuginfo-2.31.1-9.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (noarch): util-linux-lang-2.31.1-9.3.1 References: https://www.suse.com/security/cve/CVE-2018-7738.html https://bugzilla.suse.com/1084300 . SUSE releases a security patch for util-linux, fixing a local vulnerability rated as moderate. Update is advised.. Linux Enterprise Module Update, SUSE Security Patch, Util-linux Vulnerability Fix. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for ffmpeg ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:0243-1 Rating: important References: #961937 Cross-References: CVE-2016-1897 CVE-2016-1898 Affected Products: openSUSE Leap 42.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update to ffmpeg 2.8.5 fixes the following issues: * CVE-2016-1897: Cross-origin issue in URL processing (concat) - local file disclosure (boo#961937) * CVE-2016-1898: Cross-origin issue in URL processing (subfile) - local file disclosure (boo#961937) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.1: zypper in -t patch openSUSE-2016-94=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.1 (i586 x86_64): ffmpeg-2.8.5-12.1 ffmpeg-debuginfo-2.8.5-12.1 ffmpeg-debugsource-2.8.5-12.1 ffmpeg-devel-2.8.5-12.1 libavcodec-devel-2.8.5-12.1 libavcodec56-2.8.5-12.1 libavcodec56-debuginfo-2.8.5-12.1 libavdevice-devel-2.8.5-12.1 libavdevice56-2.8.5-12.1 libavdevice56-debuginfo-2.8.5-12.1 libavfilter-devel-2.8.5-12.1 libavfilter5-2.8.5-12.1 libavfilter5-debuginfo-2.8.5-12.1 libavformat-devel-2.8.5-12.1 libavformat56-2.8.5-12.1 libavformat56-debuginfo-2.8.5-12.1 libavresample-devel-2.8.5-12.1 libavresample2-2.8.5-12.1 libavresample2-debuginfo-2.8.5-12.1 libavutil-devel-2.8.5-12.1 libavutil54-2.8.5-12.1 libavutil54-debuginfo-2.8.5-12.1 libpostproc-devel-2.8.5-12.1 libpostproc53-2.8.5-12.1 libpostproc53-debuginfo-2.8.5-12.1 libswresample-devel-2.8.5-12.1 libswresample1-2.8.5-12.1 libswresample1-debuginfo-2.8.5-12.1 libswscale-devel-2.8.5-12.1 libswscale3-2.8.5-12.1 libswscale3-debuginfo-2.8.5-12.1 - openSUSE Leap 42.1 (x86_64): libavcodec56-32bit-2.8.5-12.1 libavcodec56-debuginfo-32bit-2.8.5-12.1 libavdevice56-32bit-2.8.5-12.1 libavdevice56-debuginfo-32bit-2.8.5-12.1 libavfilter5-32bit-2.8.5-12.1 libavfilter5-debuginfo-32bit-2.8.5-12.1 libavformat56-32bit-2.8.5-12.1 libavformat56-debuginfo-32bit-2.8.5-12.1 libavresample2-32bit-2.8.5-12.1 libavresample2-debuginfo-32bit-2.8.5-12.1 libavutil54-32bit-2.8.5-12.1 libavutil54-debuginfo-32bit-2.8.5-12.1 libpostproc53-32bit-2.8.5-12.1 libpostproc53-debuginfo-32bit-2.8.5-12.1 libswresample1-32bit-2.8.5-12.1 libswresample1-debuginfo-32bit-2.8.5-12.1 libswscale3-32bit-2.8.5-12.1 libswscale3-debuginfo-32bit-2.8.5-12.1 References: https://www.suse.com/security/cve/CVE-2016-1897.html https://www.suse.com/security/cve/CVE-2016-1898.html https://bugzilla.suse.com/show_bug.cgi?id=961937 . openSUSE 42.1: Critical patch for ffmpeg addressing significant local file exposure vulnerabilities.. openSUSE Security Update, ffmpeg Patch, Local File Issue. . Severity: Important. LinuxSecurity.com Team
An updated libXfont package that fixes three security issues is now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Important security [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: libXfont security update Advisory ID: RHSA-2015:1708-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:1708.html Issue date: 2015-09-03 CVE Names: CVE-2015-1802 CVE-2015-1803 CVE-2015-1804 ==================================================================== 1. Summary: An updated libXfont package that fixes three security issues is now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 RedHat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The libXfont package provides the X.Org libXfont runtime library. X.Org is an open source implementation of the X Window System. An integer overflow flaw was found in the way libXfont processed certain Glyph Bitmap Distribution Format (BDF) fonts. A malicious, local user could use this flaw to crash the X.Org server or, potentially, execute arbitrary code with the privileges of the X.Org server. (CVE-2015-1802) An integer truncation flaw was discovered in the way libXfont processed certain Glyph Bitmap Distribution Format (BDF) fonts. A malicious, local user could use this flaw to crash the X.Org server or, potentially, execute arbitrary code with the privileges of the X.Org server. (CVE-2015-1804) A NULL pointer dereference flaw was discovered in the way libXfont processed certain Glyph Bitmap Distribution Format (BDF) fonts. A malicious, local user could use this flaw to crash the X.Org server. (CVE-2015-1803) All libXfont users are advised to upgrade to this updated package, which contains backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1203715 - CVE-2015-1802 libXfont: missing range check in bdfReadProperties 1203718 - CVE-2015-1803 libXfont: crash on invalid read in bdfReadCharacters1203719 - CVE-2015-1804 libXfont: out-of-bounds memory access in bdfReadCharacters 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: libXfont-1.4.5-5.el6_7.src.rpm i386: libXfont-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm x86_64: libXfont-1.4.5-5.el6_7.x86_64.rpm libXfont-debuginfo-1.4.5-5.el6_7.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v.6): i386: libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm libXfont-devel-1.4.5-5.el6_7.i686.rpm x86_64: libXfont-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.x86_64.rpm libXfont-devel-1.4.5-5.el6_7.i686.rpm libXfont-devel-1.4.5-5.el6_7.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: libXfont-1.4.5-5.el6_7.src.rpm x86_64: libXfont-1.4.5-5.el6_7.x86_64.rpm libXfont-debuginfo-1.4.5-5.el6_7.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): x86_64: libXfont-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.x86_64.rpm libXfont-devel-1.4.5-5.el6_7.i686.rpm libXfont-devel-1.4.5-5.el6_7.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: libXfont-1.4.5-5.el6_7.src.rpm i386: libXfont-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm ppc64: libXfont-1.4.5-5.el6_7.ppc64.rpm libXfont-debuginfo-1.4.5-5.el6_7.ppc64.rpm s390x: libXfont-1.4.5-5.el6_7.s390x.rpm libXfont-debuginfo-1.4.5-5.el6_7.s390x.rpm x86_64: libXfont-1.4.5-5.el6_7.x86_64.rpm libXfont-debuginfo-1.4.5-5.el6_7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): i386: libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm libXfont-devel-1.4.5-5.el6_7.i686.rpm ppc64: libXfont-1.4.5-5.el6_7.ppc.rpm libXfont-debuginfo-1.4.5-5.el6_7.ppc.rpm libXfont-debuginfo-1.4.5-5.el6_7.ppc64.rpm libXfont-devel-1.4.5-5.el6_7.ppc.rpm libXfont-devel-1.4.5-5.el6_7.ppc64.rpm s390x: libXfont-1.4.5-5.el6_7.s390.rpm libXfont-debuginfo-1.4.5-5.el6_7.s390.rpm libXfont-debuginfo-1.4.5-5.el6_7.s390x.rpm libXfont-devel-1.4.5-5.el6_7.s390.rpm libXfont-devel-1.4.5-5.el6_7.s390x.rpm x86_64: libXfont-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.x86_64.rpm libXfont-devel-1.4.5-5.el6_7.i686.rpm libXfont-devel-1.4.5-5.el6_7.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: libXfont-1.4.5-5.el6_7.src.rpm i386: libXfont-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm x86_64: libXfont-1.4.5-5.el6_7.x86_64.rpm libXfont-debuginfo-1.4.5-5.el6_7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): i386: libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm libXfont-devel-1.4.5-5.el6_7.i686.rpm x86_64: libXfont-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.i686.rpm libXfont-debuginfo-1.4.5-5.el6_7.x86_64.rpm libXfont-devel-1.4.5-5.el6_7.i686.rpm libXfont-devel-1.4.5-5.el6_7.x86_64.rpm Red Hat Enterprise Linux Client (v. 7): Source: libXfont-1.4.7-3.el7_1.src.rpm x86_64: libXfont-1.4.7-3.el7_1.i686.rpm libXfont-1.4.7-3.el7_1.x86_64.rpm libXfont-debuginfo-1.4.7-3.el7_1.i686.rpm libXfont-debuginfo-1.4.7-3.el7_1.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: libXfont-debuginfo-1.4.7-3.el7_1.i686.rpm libXfont-debuginfo-1.4.7-3.el7_1.x86_64.rpm libXfont-devel-1.4.7-3.el7_1.i686.rpm libXfont-devel-1.4.7-3.el7_1.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: libXfont-1.4.7-3.el7_1.src.rpm x86_64: libXfont-1.4.7-3.el7_1.i686.rpm libXfont-1.4.7-3.el7_1.x86_64.rpm libXfont-debuginfo-1.4.7-3.el7_1.i686.rpm libXfont-debuginfo-1.4.7-3.el7_1.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: libXfont-debuginfo-1.4.7-3.el7_1.i686.rpm libXfont-debuginfo-1.4.7-3.el7_1.x86_64.rpm libXfont-devel-1.4.7-3.el7_1.i686.rpm libXfont-devel-1.4.7-3.el7_1.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: libXfont-1.4.7-3.el7_1.src.rpm ppc64: libXfont-1.4.7-3.el7_1.ppc.rpm libXfont-1.4.7-3.el7_1.ppc64.rpm libXfont-debuginfo-1.4.7-3.el7_1.ppc.rpm libXfont-debuginfo-1.4.7-3.el7_1.ppc64.rpm s390x: libXfont-1.4.7-3.el7_1.s390.rpm libXfont-1.4.7-3.el7_1.s390x.rpm libXfont-debuginfo-1.4.7-3.el7_1.s390.rpm libXfont-debuginfo-1.4.7-3.el7_1.s390x.rpm x86_64: libXfont-1.4.7-3.el7_1.i686.rpm libXfont-1.4.7-3.el7_1.x86_64.rpm libXfont-debuginfo-1.4.7-3.el7_1.i686.rpm libXfont-debuginfo-1.4.7-3.el7_1.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: libXfont-1.4.7-3.ael7b_1.src.rpm ppc64le: libXfont-1.4.7-3.ael7b_1.ppc64le.rpm libXfont-debuginfo-1.4.7-3.ael7b_1.ppc64le.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: libXfont-debuginfo-1.4.7-3.el7_1.ppc.rpm libXfont-debuginfo-1.4.7-3.el7_1.ppc64.rpm libXfont-devel-1.4.7-3.el7_1.ppc.rpm libXfont-devel-1.4.7-3.el7_1.ppc64.rpm s390x: libXfont-debuginfo-1.4.7-3.el7_1.s390.rpm libXfont-debuginfo-1.4.7-3.el7_1.s390x.rpm libXfont-devel-1.4.7-3.el7_1.s390.rpm libXfont-devel-1.4.7-3.el7_1.s390x.rpm x86_64: libXfont-debuginfo-1.4.7-3.el7_1.i686.rpm libXfont-debuginfo-1.4.7-3.el7_1.x86_64.rpm libXfont-devel-1.4.7-3.el7_1.i686.rpm libXfont-devel-1.4.7-3.el7_1.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64le: libXfont-debuginfo-1.4.7-3.ael7b_1.ppc64le.rpm libXfont-devel-1.4.7-3.ael7b_1.ppc64le.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: libXfont-1.4.7-3.el7_1.src.rpm x86_64: libXfont-1.4.7-3.el7_1.i686.rpm libXfont-1.4.7-3.el7_1.x86_64.rpm libXfont-debuginfo-1.4.7-3.el7_1.i686.rpm libXfont-debuginfo-1.4.7-3.el7_1.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: libXfont-debuginfo-1.4.7-3.el7_1.i686.rpm libXfont-debuginfo-1.4.7-3.el7_1.x86_64.rpm libXfont-devel-1.4.7-3.el7_1.i686.rpm libXfont-devel-1.4.7-3.el7_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-1802 https://access.redhat.com/security/cve/CVE-2015-1803 https://access.redhat.com/security/cve/CVE-2015-1804 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. . Crucial advisory for Red Hat’s libXfont addresses three security flaws, affecting users on versions 6 and 7.. Red Hat Enterprise Linux,System Update,Security Fix. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-2666-1 July 07, 2015 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: A race condition was discovered in the Linux kernel's file_handle size verification. A local user could exploit this flaw to read potentially sensative memory locations. (CVE-2015-1420) A underflow error was discovered in the Linux kernel's Ozmo Devices USB over WiFi host controller driver. A remote attacker could exploit this flaw to cause a denial of service (system crash) or potentially execute arbitrary code via a specially crafted packet. (CVE-2015-4001) A bounds check error was discovered in the Linux kernel's Ozmo Devices USB over WiFi host controller driver. A remote attacker could exploit this flaw to cause a denial of service (system crash) or potentially execute arbitrary code via a specially crafted packet. (CVE-2015-4002) A division by zero error was discovered in the Linux kernel's Ozmo Devices USB over WiFi host controller driver. A remote attacker could exploit this flaw to cause a denial of service (system crash). (CVE-2015-4003) Carl H Lunde discovered missing sanity checks in the the Linux kernel's UDF file system (CONFIG_UDF_FS). A local attacker could exploit this flaw to cause a denial of service (system crash) by using a corrupted file system image. (CVE-2015-4167) Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter JIT optimization. A local attacker could exploit this flaw to cause a denial of service (system crash). (CVE-2015-4700) Update instructions: The problem can be corrected by updating your system to the following packageversions: Ubuntu 14.10: linux-image-3.16.0-43-generic 3.16.0-43.58 linux-image-3.16.0-43-generic-lpae 3.16.0-43.58 linux-image-3.16.0-43-lowlatency 3.16.0-43.58 linux-image-3.16.0-43-powerpc-e500mc 3.16.0-43.58 linux-image-3.16.0-43-powerpc-smp 3.16.0-43.58 linux-image-3.16.0-43-powerpc64-emb 3.16.0-43.58 linux-image-3.16.0-43-powerpc64-smp 3.16.0-43.58 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-2666-1 CVE-2015-1420, CVE-2015-4001, CVE-2015-4002, CVE-2015-4003, CVE-2015-4167, CVE-2015-4700 Package Information: https://launchpad.net/ubuntu/+source/linux/3.16.0-43.58 . Kernel updates for Ubuntu 14.10 address multiple security issues with detailed update instructions included for users.. Kernel Security, Ubuntu Exploits, Linux Patch Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.