Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
98

Red Hat 8.4 RHSA-2023-4500-01 Critical: Thunderbird Security Flaw

An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2023:4500-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4500 Issue date: 2023-08-07 CVE Names: CVE-2023-3417 CVE-2023-4045 CVE-2023-4046 CVE-2023-4047 CVE-2023-4048 CVE-2023-4049 CVE-2023-4050 CVE-2023-4055 CVE-2023-4056 CVE-2023-4057 ===================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream AUS (v.8.4) - x86_64 Red Hat Enterprise Linux AppStream E4S (v.8.4) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream TUS (v.8.4) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 102.14.0. Security Fix(es): * Mozilla: Offscreen Canvas could have bypassed cross-origin restrictions (CVE-2023-4045) * Mozilla: Incorrect value used during WASM compilation(CVE-2023-4046) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2023-4047) * Mozilla: Crash in DOMParser due to out-of-memory conditions (CVE-2023-4048) * Mozilla: Fix potential race conditions when releasing platform objects (CVE-2023-4049) * Mozilla: Stack buffer overflow in StorageManager (CVE-2023-4050) * Mozilla: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 (CVE-2023-4056) * Mozilla: Memory safety bugs fixed in Firefox ESR 115.1, and Thunderbird 115.1 (CVE-2023-4057) * thunderbird: File Extension Spoofing using the Text Direction Override Character (CVE-2023-3417) * Mozilla: Cookie jar overflow caused unexpected cookie jar state (CVE-2023-4055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restarted for the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2225325 - CVE-2023-3417 thunderbird: File Extension Spoofing using the Text Direction Override Character 2228360 - CVE-2023-4045 Mozilla: Offscreen Canvas could have bypassed cross-origin restrictions 2228361 - CVE-2023-4046 Mozilla: Incorrect value used during WASM compilation 2228362 - CVE-2023-4047 Mozilla: Potential permissions request bypass via clickjacking 2228363 - CVE-2023-4048 Mozilla: Crash in DOMParser due to out-of-memory conditions 2228364 - CVE-2023-4049 Mozilla: Fix potential race conditions when releasing platform objects 2228365 - CVE-2023-4050 Mozilla: Stack buffer overflow in StorageManager 2228367 - CVE-2023-4055 Mozilla: Cookie jar overflow caused unexpected cookie jar state 2228370 - CVE-2023-4056 Mozilla: Memory safety bugs fixed in Firefox 116, Firefox ESR115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 2228371 - CVE-2023-4057 Mozilla: Memory safety bugs fixed in Firefox ESR 115.1, and Thunderbird 115.1 6. Package List: Red Hat Enterprise Linux AppStream AUS (v.8.4): Source: thunderbird-102.14.0-1.el8_4.src.rpm x86_64: thunderbird-102.14.0-1.el8_4.x86_64.rpm thunderbird-debuginfo-102.14.0-1.el8_4.x86_64.rpm thunderbird-debugsource-102.14.0-1.el8_4.x86_64.rpm Red Hat Enterprise Linux AppStream E4S (v.8.4): Source: thunderbird-102.14.0-1.el8_4.src.rpm aarch64: thunderbird-102.14.0-1.el8_4.aarch64.rpm thunderbird-debuginfo-102.14.0-1.el8_4.aarch64.rpm thunderbird-debugsource-102.14.0-1.el8_4.aarch64.rpm ppc64le: thunderbird-102.14.0-1.el8_4.ppc64le.rpm thunderbird-debuginfo-102.14.0-1.el8_4.ppc64le.rpm thunderbird-debugsource-102.14.0-1.el8_4.ppc64le.rpm s390x: thunderbird-102.14.0-1.el8_4.s390x.rpm thunderbird-debuginfo-102.14.0-1.el8_4.s390x.rpm thunderbird-debugsource-102.14.0-1.el8_4.s390x.rpm x86_64: thunderbird-102.14.0-1.el8_4.x86_64.rpm thunderbird-debuginfo-102.14.0-1.el8_4.x86_64.rpm thunderbird-debugsource-102.14.0-1.el8_4.x86_64.rpm Red Hat Enterprise Linux AppStream TUS (v.8.4): Source: thunderbird-102.14.0-1.el8_4.src.rpm aarch64: thunderbird-102.14.0-1.el8_4.aarch64.rpm thunderbird-debuginfo-102.14.0-1.el8_4.aarch64.rpm thunderbird-debugsource-102.14.0-1.el8_4.aarch64.rpm ppc64le: thunderbird-102.14.0-1.el8_4.ppc64le.rpm thunderbird-debuginfo-102.14.0-1.el8_4.ppc64le.rpm thunderbird-debugsource-102.14.0-1.el8_4.ppc64le.rpm s390x: thunderbird-102.14.0-1.el8_4.s390x.rpm thunderbird-debuginfo-102.14.0-1.el8_4.s390x.rpm thunderbird-debugsource-102.14.0-1.el8_4.s390x.rpm x86_64: thunderbird-102.14.0-1.el8_4.x86_64.rpm thunderbird-debuginfo-102.14.0-1.el8_4.x86_64.rpm thunderbird-debugsource-102.14.0-1.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2023-3417 https://access.redhat.com/security/cve/CVE-2023-4045 https://access.redhat.com/security/cve/CVE-2023-4046 https://access.redhat.com/security/cve/CVE-2023-4047 https://access.redhat.com/security/cve/CVE-2023-4048 https://access.redhat.com/security/cve/CVE-2023-4049 https://access.redhat.com/security/cve/CVE-2023-4050 https://access.redhat.com/security/cve/CVE-2023-4055 https://access.redhat.com/security/cve/CVE-2023-4056 https://access.redhat.com/security/cve/CVE-2023-4057 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJk0P3gAAoJENzjgjWX9erEeH0P/1M0cfMSwsEYmKb2lAnc4XuD LBA+/ACSx0pmBMqAoG6KMGyv9pLGL4afyTkuUdwrqebX++yxZFK/EZCMa5/vrQei NRNx0sCjAdqVlCbqosM5QJUPkHWvt1vLLttJFkbPwDeA/N5/6zOkrjQUNXwH5bOZ qUsWXVfJQra6PHQ1wQa5UrrjdPD3eaZkpwKyDNek41bRMcCYRPS10HKeTBj0rWfQ bXAGieb7zO3O3EqvJMZ7G21MV80r27Hip+ydP07sJVxz3Za/i/cGtyHzU9Kp0xMp 7SUkc+LMksNcNCw1/o6yhZdTdRyMgGwEriP0hT9sy7OKHyV3yvkZAQ1OpIINOZ1m 6H/yFDy18Uhg3mj4LoO72M4VmJAoL9Zd6LjC89mNmWuGXD/TTlHrnBSATz+W3mBA ZKZAN+xByw31s/Q1CMsIU/t+VpJev3EIOCrIAkf3jIq4yUb04AShlJk4JAmCNmW8 xuUQne6bfAw4lZiDqx/JyaV6pulqmGAPFOU2klZNO0EByzv5yeoC8A17oEYzahQq EvJDhg8/fTDHxZwtQm0OupZQY9CvfQaxaCz5OJrH43rQnfK8mDWrEW4IkZz4fLNo Nn4U+x4kNTMj7T0RSdewWD4qyS3juWeTXRSkSCyv1ksVpGtQWG2AJh7dypCHg51X 07ioqq8PHwK2s5ytPmja =MOUN -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial patch released for Thunderbird on RHEL 8.4 to mitigate severe security flaws.. Thunderbird Update, Red Hat Advisory, Security Patches, Enterprise Linux Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 07, 2023 Important Red Hat
89

Fedora 28: Critical Mediainfo Security Update for Multiple Flaws

Update to 19.04.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-7155125125 2019-05-25 01:10:26.463302 --------------------------------------------------------------------------------Name : mediainfo Product : Fedora 28 Version : 19.04 Release : 1.fc28 URL : https://mediaarea.net/en/MediaInfo Summary : Supplies technical and tag information about a video or audio file (CLI) Description : MediaInfo CLI (Command Line Interface). What information can I get from MediaInfo? * General: title, author, director, album, track number, date, duration... * Video: codec, aspect, fps, bitrate... * Audio: codec, sample rate, channels, language, bitrate... * Text: language of subtitle * Chapters: number of chapters, list of chapters DivX, XviD, H263, H.263, H264, x264, ASP, AVC, iTunes, MPEG-1, MPEG1, MPEG-2, MPEG2, MPEG-4, MPEG4, MP4, M4A, M4V, QuickTime, RealVideo, RealAudio, RA, RM, MSMPEG4v1, MSMPEG4v2, MSMPEG4v3, VOB, DVD, WMA, VMW, ASF, 3GP, 3GPP, 3GP2 What format (container) does MediaInfo support? * Video: MKV, OGM, AVI, DivX, WMV, QuickTime, Real, MPEG-1, MPEG-2, MPEG-4, DVD (VOB) (Codecs: DivX, XviD, MSMPEG4, ASP, H.264, AVC...) * Audio: OGG, MP3, WAV, RA, AC3, DTS, AAC, M4A, AU, AIFF * Subtitles: SRT, SSA, ASS, S-MI --------------------------------------------------------------------------------Update Information: Update to 19.04. --------------------------------------------------------------------------------ChangeLog: * Wed Apr 24 2019 Vasiliy N. Glazov - 19.04-1 - Update to 19.04 * Fri Feb 1 2019 Fedora Release Engineering - 18.12-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Thu Dec 13 2018 Vasiliy N. Glazov - 18.12-1 - Update to 18.12 * Tue Sep 11 2018 Vasiliy N. Glazov - 18.08.1-1 - Update to 18.08.1 * Mon Sep 3 2018 Vasiliy N. Glazov - 18.08-1 - Update to 18.08 * Fri Jul 13 2018 Fedora Release Engineering -18.05-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Tue Jul 10 2018 Scott Talbert - 18.05-2 - Rebuild with wxWidgets 3.0 * Thu May 10 2018 Vasiliy N. Glazov - 18.05-1 - Update to 18.05 --------------------------------------------------------------------------------References: [ 1 ] Bug #1701845 - CVE-2019-11372 CVE-2019-11373 mediainfo: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1701845 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-7155125125' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . --------------------------------------------------------------------------------Fedora Update Notifi. update, --------------------------------------------------------------------------------fed. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 24, 2019 Critical Fedora
98

Red Hat E.L. 6 RHSA-2015:1912-01 Important: Chromium Code Execution Threat

Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2015:1912-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2015:1912.html Issue date: 2015-10-15 CVE Names: CVE-2015-6755 CVE-2015-6756 CVE-2015-6757 CVE-2015-6758 CVE-2015-6759 CVE-2015-6760 CVE-2015-6761 CVE-2015-6762 CVE-2015-6763 ==================================================================== 1. Summary: Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: Chromium is an open-source web browser, powered by WebKit (Blink). Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information when visited by the victim. (CVE-2015-6755, CVE-2015-6756, CVE-2015-6757, CVE-2015-6758, CVE-2015-6759, CVE-2015-6760, CVE-2015-6761, CVE-2015-6762, CVE-2015-6763) All Chromium users should upgrade to these updated packages, which contain Chromium version46.0.2490.71, which corrects these issues. After installing the update, Chromium must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1271480 - CVE-2015-6755 chromium-browser: cross-origin bypass in Blink 1271483 - CVE-2015-6756 chromium-browser: use-after-free in PDFium 1271553 - CVE-2015-6757 chromium-browser: Use-after-free in ServiceWorker 1271554 - CVE-2015-6758 chromium-browser: Bad-cast in PDFium 1271555 - CVE-2015-6759 chromium-browser: Information leakage in LocalStorage 1271556 - CVE-2015-6760 chromium-browser: Improper error handling in libANGLE 1271557 - CVE-2015-6761 chromium-browser: Memory corruption in FFMpeg 1271558 - CVE-2015-6762 chromium-browser: CORS bypass in CSS fonts 1271559 - CVE-2015-6763 chromium-browser: various fixes from internal audits 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: chromium-browser-46.0.2490.71-1.el6.i686.rpm chromium-browser-debuginfo-46.0.2490.71-1.el6.i686.rpm x86_64: chromium-browser-46.0.2490.71-1.el6.x86_64.rpm chromium-browser-debuginfo-46.0.2490.71-1.el6.x86_64.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: chromium-browser-46.0.2490.71-1.el6.i686.rpm chromium-browser-debuginfo-46.0.2490.71-1.el6.i686.rpm x86_64: chromium-browser-46.0.2490.71-1.el6.x86_64.rpm chromium-browser-debuginfo-46.0.2490.71-1.el6.x86_64.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: chromium-browser-46.0.2490.71-1.el6.i686.rpm chromium-browser-debuginfo-46.0.2490.71-1.el6.i686.rpm x86_64: chromium-browser-46.0.2490.71-1.el6.x86_64.rpm chromium-browser-debuginfo-46.0.2490.71-1.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2015-6755 https://access.redhat.com/security/cve/CVE-2015-6756 https://access.redhat.com/security/cve/CVE-2015-6757 https://access.redhat.com/security/cve/CVE-2015-6758 https://access.redhat.com/security/cve/CVE-2015-6759 https://access.redhat.com/security/cve/CVE-2015-6760 https://access.redhat.com/security/cve/CVE-2015-6761 https://access.redhat.com/security/cve/CVE-2015-6762 https://access.redhat.com/security/cve/CVE-2015-6763 https://access.redhat.com/security/updates/classification#important https://chromereleases.googleblog.com/2015/10/stable-channel-update.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2015 Red Hat, Inc. . Critical news for Red Hat Enterprise Linux 6 customers addresses several security flaws in chromium-browser. Keep your system safe!. Red Hat Enterprise Linux, Chromium Security Update, Software Maintenance. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 14, 2017 Important Red Hat
200

Scientific Linux: 2016:1551-1 Critical: firefox Update for Security Issues

Critical: firefox security update. Date: Wed, 3 Aug 2016 17:08:57 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Critical: firefox on SL5.x, SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Critical: firefox security update Advisory ID: SLSA-2016:1551-1 Issue Date: 2016-08-03 CVE Numbers: CVE-2016-2830 CVE-2016-2836 CVE-2016-2838 CVE-2016-5252 CVE-2016-5254 CVE-2016-5258 CVE-2016-5259 CVE-2016-5262 CVE-2016-2837 CVE-2016-5263 CVE-2016-5264 CVE-2016-5265 -- This update upgrades Firefox to version 45.3.0 ESR. Security Fix(es): * Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2016-2836, CVE-2016-5258, CVE-2016-5259, CVE-2016-5252, CVE-2016-5263, CVE-2016-2830, CVE-2016-2838, CVE-2016-5254, CVE-2016-5262, CVE-2016-5264, CVE-2016-5265, CVE-2016-2837) -- SL5 x86_64 firefox-45.3.0-1.el5_11.i386.rpm firefox-45.3.0-1.el5_11.x86_64.rpm firefox-debuginfo-45.3.0-1.el5_11.i386.rpm firefox-debuginfo-45.3.0-1.el5_11.x86_64.rpm i386 firefox-45.3.0-1.el5_11.i386.rpm firefox-debuginfo-45.3.0-1.el5_11.i386.rpm SL6 x86_64 firefox-45.3.0-1.el6_8.x86_64.rpm firefox-debuginfo-45.3.0-1.el6_8.x86_64.rpm firefox-45.3.0-1.el6_8.i686.rpm firefox-debuginfo-45.3.0-1.el6_8.i686.rpm i386 firefox-45.3.0-1.el6_8.i686.rpm firefox-debuginfo-45.3.0-1.el6_8.i686.rpm SL7 x86_64 firefox-45.3.0-1.el7_2.x86_64.rpm firefox-debuginfo-45.3.0-1.el7_2.x86_64.rpm firefox-45.3.0-1.el7_2.i686.rpm firefox-debuginfo-45.3.0-1.el7_2.i686.rpm - Scientific Linux Development Team . Critical security notice for Scientific Linux users regarding the latest Firefox update addressing multiple vulnerabilities and threats.. Scientific Linux Security, Firefox Update, Critical Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 03, 2016 Critical Scientific Linux
200

Scientific Linux SL7: SLSA-2016:0006-1 Moderate: Samba DoS and Access Flaws

Moderate: samba security update. Date: Fri, 8 Jan 2016 14:31:52 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: samba on SL7.x x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: samba security update Advisory ID: SLSA-2016:0006-1 Issue Date: 2016-01-07 CVE Numbers: CVE-2015-5299 CVE-2015-5252 CVE-2015-5296 CVE-2015-5330 CVE-2015-7540 -- A denial of service flaw was found in the LDAP server provided by the AD DC in the Samba process daemon. A remote attacker could exploit this flaw by sending a specially crafted packet, which could cause the server to consume an excessive amount of memory and crash. (CVE-2015-7540) Multiple buffer over-read flaws were found in the way Samba handled malformed inputs in certain encodings. An authenticated, remote attacker could possibly use these flaws to disclose portions of the server memory. (CVE-2015-5330) A man-in-the-middle vulnerability was found in the way "connection signing" was implemented by Samba. A remote attacker could use this flaw to downgrade an existing Samba client connection and force the use of plain text. (CVE-2015-5296) A missing access control flaw was found in Samba. A remote, authenticated attacker could use this flaw to view the current snapshot on a Samba share, despite not having DIRECTORY_LIST access rights. (CVE-2015-5299) An access flaw was found in the way Samba verified symbolic links when creating new files on a Samba share. A remote attacker could exploit this flaw to gain access to files outside of Samba's share path. (CVE-2015-5252) After installing this update, the smb service will be restarted automatically. -- SL7 x86_64 libsmbclient-4.2.3-11.el7_2.i686.rpm libsmbclient-4.2.3-11.el7_2.x86_64.rpm libwbclient-4.2.3-11.el7_2.i686.rpm libwbclient-4.2.3-11.el7_2.x86_64.rpm samba-client-4.2.3-11.el7_2.x86_64.rpm samba-client-libs-4.2.3-11.el7_2.i686.rpm samba-client-libs-4.2.3-11.el7_2.x86_64.rpm samba-common-libs-4.2.3-11.el7_2.x86_64.rpm samba-common-tools-4.2.3-11.el7_2.x86_64.rpm samba-debuginfo-4.2.3-11.el7_2.i686.rpm samba-debuginfo-4.2.3-11.el7_2.x86_64.rpm samba-libs-4.2.3-11.el7_2.i686.rpm samba-libs-4.2.3-11.el7_2.x86_64.rpm samba-winbind-4.2.3-11.el7_2.x86_64.rpm samba-winbind-clients-4.2.3-11.el7_2.x86_64.rpm samba-winbind-modules-4.2.3-11.el7_2.i686.rpm samba-winbind-modules-4.2.3-11.el7_2.x86_64.rpm libsmbclient-devel-4.2.3-11.el7_2.i686.rpm libsmbclient-devel-4.2.3-11.el7_2.x86_64.rpm libwbclient-devel-4.2.3-11.el7_2.i686.rpm libwbclient-devel-4.2.3-11.el7_2.x86_64.rpm samba-4.2.3-11.el7_2.x86_64.rpm samba-dc-4.2.3-11.el7_2.x86_64.rpm samba-dc-libs-4.2.3-11.el7_2.x86_64.rpm samba-devel-4.2.3-11.el7_2.i686.rpm samba-devel-4.2.3-11.el7_2.x86_64.rpm samba-python-4.2.3-11.el7_2.x86_64.rpm samba-test-4.2.3-11.el7_2.x86_64.rpm samba-test-devel-4.2.3-11.el7_2.x86_64.rpm samba-test-libs-4.2.3-11.el7_2.i686.rpm samba-test-libs-4.2.3-11.el7_2.x86_64.rpm samba-vfs-glusterfs-4.2.3-11.el7_2.x86_64.rpm samba-winbind-krb5-locator-4.2.3-11.el7_2.x86_64.rpm noarch samba-common-4.2.3-11.el7_2.noarch.rpm samba-pidl-4.2.3-11.el7_2.noarch.rpm - Scientific Linux Development Team . Critical samba patch released for Fedora rectifies various vulnerabilities, encompassing service disruption and permission problems.. samba update, Scientific Linux, security advisory, access control, network threat. . LinuxSecurity.com Team

Calendar%202 Jan 08, 2016 Scientific Linux
172

Ubuntu 14.10 USN-2472-1 moderate: unzip Code Execution Threat

unzip could be made to crash or run programs if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-2472-1 January 14, 2015 unzip vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: unzip could be made to crash or run programs if it opened a specially crafted file. Software Description: - unzip: De-archiver for .zip files Details: Wolfgang Ettlinger discovered that unzip incorrectly handled certain malformed zip archives. If a user or automated system were tricked into processing a specially crafted zip archive, an attacker could possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: unzip 6.0-12ubuntu1.1 Ubuntu 14.04 LTS: unzip 6.0-9ubuntu1.1 Ubuntu 12.04 LTS: unzip 6.0-4ubuntu2.1 Ubuntu 10.04 LTS: unzip 6.0-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2472-1 CVE-2014-8139, CVE-2014-8140, CVE-2014-8141 Package Information: https://launchpad.net/ubuntu/+source/unzip/6.0-12ubuntu1.1 https://launchpad.net/ubuntu/+source/unzip/6.0-9ubuntu1.1 https://launchpad.net/ubuntu/+source/unzip/6.0-4ubuntu2.1 https://launchpad.net/ubuntu/+source/unzip/6.0-1ubuntu0.1 . Identifying weaknesses in unzip that may lead to system crashes or remote code execution on Ubuntu platforms. Patching solutions released.. unzip vulnerabilities, Ubuntu security, code execution threat. . LinuxSecurity.com Team

Calendar%202 Jan 14, 2015 Ubuntu
98

Red Hat Enterprise Linux Security Update: RHSA-2014:0741-01 for Firefox

Updated firefox packages that fix several security issues are now available for Red Hat Enterprise Linux 5, 6, and 7. The Red Hat Security Response Team has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Critical: firefox security update Advisory ID: RHSA-2014:0741-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:0741.html Issue date: 2014-06-10 CVE Names: CVE-2014-1533 CVE-2014-1538 CVE-2014-1541 ==================================================================== 1. Summary: Updated firefox packages that fix several security issues are now available for Red Hat Enterprise Linux 5, 6, and 7. The Red Hat Security Response Team has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3.Description: Mozilla Firefox is an open source web browser. XULRunner provides the XUL Runtime environment for Mozilla Firefox. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541) Red Hat would like to thank the Mozilla project for reporting these issues. Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey, Abhishek Arya, and Nils as the original reporters of these issues. For technical details regarding these flaws, refer to the Mozilla security advisories for Firefox 24.6.0 ESR. You can find a link to the Mozilla advisories in the References section of this erratum. All Firefox users should upgrade to these updated packages, which contain Firefox version 24.6.0 ESR, which corrects these issues. After installing the update, Firefox must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1107399 - CVE-2014-1533 Mozilla: Miscellaneous memory safety hazards (rv:24.6) (MFSA 2014-48) 1107421 - CVE-2014-1538 Mozilla: Use-after-free and out of bounds issues found using Address Sanitizer (MFSA 2014-49) 1107424 - CVE-2014-1541 Mozilla: Use-after-free with SMIL Animation Controller (MFSA 2014-52) 6. Package List: Red Hat Enterprise Linux Desktop (v. 5client): Source: firefox-24.6.0-1.el5_10.src.rpm i386: firefox-24.6.0-1.el5_10.i386.rpm firefox-debuginfo-24.6.0-1.el5_10.i386.rpm x86_64: firefox-24.6.0-1.el5_10.i386.rpm firefox-24.6.0-1.el5_10.x86_64.rpm firefox-debuginfo-24.6.0-1.el5_10.i386.rpm firefox-debuginfo-24.6.0-1.el5_10.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: firefox-24.6.0-1.el5_10.src.rpm i386: firefox-24.6.0-1.el5_10.i386.rpm firefox-debuginfo-24.6.0-1.el5_10.i386.rpm ia64: firefox-24.6.0-1.el5_10.ia64.rpm firefox-debuginfo-24.6.0-1.el5_10.ia64.rpm ppc: firefox-24.6.0-1.el5_10.ppc.rpm firefox-debuginfo-24.6.0-1.el5_10.ppc.rpm s390x: firefox-24.6.0-1.el5_10.s390.rpm firefox-24.6.0-1.el5_10.s390x.rpm firefox-debuginfo-24.6.0-1.el5_10.s390.rpm firefox-debuginfo-24.6.0-1.el5_10.s390x.rpm x86_64: firefox-24.6.0-1.el5_10.i386.rpm firefox-24.6.0-1.el5_10.x86_64.rpm firefox-debuginfo-24.6.0-1.el5_10.i386.rpm firefox-debuginfo-24.6.0-1.el5_10.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 6): Source: firefox-24.6.0-1.el6_5.src.rpm i386: firefox-24.6.0-1.el6_5.i686.rpm firefox-debuginfo-24.6.0-1.el6_5.i686.rpm x86_64: firefox-24.6.0-1.el6_5.i686.rpm firefox-24.6.0-1.el6_5.x86_64.rpm firefox-debuginfo-24.6.0-1.el6_5.i686.rpm firefox-debuginfo-24.6.0-1.el6_5.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: firefox-24.6.0-1.el6_5.src.rpm x86_64: firefox-24.6.0-1.el6_5.i686.rpm firefox-24.6.0-1.el6_5.x86_64.rpm firefox-debuginfo-24.6.0-1.el6_5.i686.rpm firefox-debuginfo-24.6.0-1.el6_5.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: firefox-24.6.0-1.el6_5.src.rpm i386: firefox-24.6.0-1.el6_5.i686.rpm firefox-debuginfo-24.6.0-1.el6_5.i686.rpm ppc64: firefox-24.6.0-1.el6_5.ppc.rpm firefox-24.6.0-1.el6_5.ppc64.rpm firefox-debuginfo-24.6.0-1.el6_5.ppc.rpm firefox-debuginfo-24.6.0-1.el6_5.ppc64.rpm s390x: firefox-24.6.0-1.el6_5.s390.rpm firefox-24.6.0-1.el6_5.s390x.rpm firefox-debuginfo-24.6.0-1.el6_5.s390.rpm firefox-debuginfo-24.6.0-1.el6_5.s390x.rpm x86_64: firefox-24.6.0-1.el6_5.i686.rpm firefox-24.6.0-1.el6_5.x86_64.rpm firefox-debuginfo-24.6.0-1.el6_5.i686.rpm firefox-debuginfo-24.6.0-1.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: firefox-24.6.0-1.el6_5.src.rpm i386: firefox-24.6.0-1.el6_5.i686.rpm firefox-debuginfo-24.6.0-1.el6_5.i686.rpm x86_64: firefox-24.6.0-1.el6_5.i686.rpm firefox-24.6.0-1.el6_5.x86_64.rpm firefox-debuginfo-24.6.0-1.el6_5.i686.rpm firefox-debuginfo-24.6.0-1.el6_5.x86_64.rpm Red Hat Enterprise Linux Client (v. 7): Source: firefox-24.6.0-1.el7_0.src.rpm xulrunner-24.6.0-1.el7_0.src.rpm x86_64: firefox-24.6.0-1.el7_0.x86_64.rpm firefox-debuginfo-24.6.0-1.el7_0.x86_64.rpm xulrunner-24.6.0-1.el7_0.i686.rpm xulrunner-24.6.0-1.el7_0.x86_64.rpm xulrunner-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: firefox-24.6.0-1.el7_0.i686.rpm firefox-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.x86_64.rpm xulrunner-devel-24.6.0-1.el7_0.i686.rpm xulrunner-devel-24.6.0-1.el7_0.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): Source: xulrunner-24.6.0-1.el7_0.src.rpm x86_64: xulrunner-24.6.0-1.el7_0.i686.rpm xulrunner-24.6.0-1.el7_0.x86_64.rpm xulrunner-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.x86_64.rpm xulrunner-devel-24.6.0-1.el7_0.i686.rpm xulrunner-devel-24.6.0-1.el7_0.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: firefox-24.6.0-1.el7_0.src.rpm xulrunner-24.6.0-1.el7_0.src.rpm ppc64: firefox-24.6.0-1.el7_0.ppc64.rpm firefox-debuginfo-24.6.0-1.el7_0.ppc64.rpm xulrunner-24.6.0-1.el7_0.ppc.rpm xulrunner-24.6.0-1.el7_0.ppc64.rpm xulrunner-debuginfo-24.6.0-1.el7_0.ppc.rpm xulrunner-debuginfo-24.6.0-1.el7_0.ppc64.rpm s390x: firefox-24.6.0-1.el7_0.s390x.rpm firefox-debuginfo-24.6.0-1.el7_0.s390x.rpm x86_64: firefox-24.6.0-1.el7_0.x86_64.rpm firefox-debuginfo-24.6.0-1.el7_0.x86_64.rpm xulrunner-24.6.0-1.el7_0.i686.rpm xulrunner-24.6.0-1.el7_0.x86_64.rpm xulrunner-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): Source: xulrunner-24.6.0-1.el7_0.src.rpm ppc64: firefox-24.6.0-1.el7_0.ppc.rpm firefox-debuginfo-24.6.0-1.el7_0.ppc.rpm xulrunner-debuginfo-24.6.0-1.el7_0.ppc.rpm xulrunner-debuginfo-24.6.0-1.el7_0.ppc64.rpm xulrunner-devel-24.6.0-1.el7_0.ppc.rpm xulrunner-devel-24.6.0-1.el7_0.ppc64.rpm s390x: firefox-24.6.0-1.el7_0.s390.rpm firefox-debuginfo-24.6.0-1.el7_0.s390.rpm xulrunner-24.6.0-1.el7_0.s390.rpm xulrunner-24.6.0-1.el7_0.s390x.rpm xulrunner-debuginfo-24.6.0-1.el7_0.s390.rpm xulrunner-debuginfo-24.6.0-1.el7_0.s390x.rpm xulrunner-devel-24.6.0-1.el7_0.s390.rpm xulrunner-devel-24.6.0-1.el7_0.s390x.rpm x86_64: firefox-24.6.0-1.el7_0.i686.rpm firefox-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.x86_64.rpm xulrunner-devel-24.6.0-1.el7_0.i686.rpm xulrunner-devel-24.6.0-1.el7_0.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: firefox-24.6.0-1.el7_0.src.rpm xulrunner-24.6.0-1.el7_0.src.rpm x86_64: firefox-24.6.0-1.el7_0.x86_64.rpm firefox-debuginfo-24.6.0-1.el7_0.x86_64.rpm xulrunner-24.6.0-1.el7_0.i686.rpm xulrunner-24.6.0-1.el7_0.x86_64.rpm xulrunner-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.7): x86_64: firefox-24.6.0-1.el7_0.i686.rpm firefox-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.i686.rpm xulrunner-debuginfo-24.6.0-1.el7_0.x86_64.rpm xulrunner-devel-24.6.0-1.el7_0.i686.rpm xulrunner-devel-24.6.0-1.el7_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2014-1533 https://access.redhat.com/security/cve/CVE-2014-1538 https://access.redhat.com/security/cve/CVE-2014-1541 https://access.redhat.com/security/updates/classification/#critical https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFTl30hXlSAg2UNWIIRArYPAKC1l7FXM395K4R1cFjeprO5JVYwqgCfTmZd ATGYqQtRgsoSMHmVNBn/EKY=riOh -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important announcement regarding Red Hat Enterprise Linux’s Firefox version, correcting several vulnerabilities. Urgent update suggested.. Red Hat Advisory, Firefox Update, Critical Security Fix, Security Flaws. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 10, 2014 Critical Red Hat
98

Red Hat: 2012:0011-01 Critical: Acroread Security Issue

Updated acroread packages that fix two security issues are now available for Red Hat Enterprise Linux 4 Extras and Red Hat Enterprise Linux 5 and 6 Supplementary. [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Critical: acroread security update Advisory ID: RHSA-2012:0011-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2012:0011.html Issue date: 2012-01-10 CVE Names: CVE-2011-2462 CVE-2011-4369 ==================================================================== 1. Summary: Updated acroread packages that fix two security issues are now available for Red Hat Enterprise Linux 4 Extras and Red Hat Enterprise Linux 5 and 6 Supplementary. The Red Hat Security Response Team has rated this update as having critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Desktop version 4 Extras - i386, x86_64 Red Hat Enterprise Linux AS version 4 Extras - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux ES version 4 Extras - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 5) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux WS version 4 Extras - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: Adobe Reader allows users to view and print documents in Portable Document Format (PDF). This update fixes two security flaws in Adobe Reader. These flaws are detailed on the Adobe security page APSB11-30, listed in the References section. A specially-crafted PDF file could cause Adobe Reader to crashor, potentially, execute arbitrary code as the user running Adobe Reader when opened. (CVE-2011-2462, CVE-2011-4369) All Adobe Reader users should install these updated packages. They contain Adobe Reader version 9.4.7, which is not vulnerable to these issues. All running instances of Adobe Reader must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 760908 - CVE-2011-2462 acroread: U3D memory corruption vulnerability (APSB11-30) 768517 - CVE-2011-4369 acroread: unspecified vulnerability in PRC component (APSB11-30) 6. Package List: Red Hat Enterprise Linux AS version 4 Extras: i386: acroread-9.4.7-1.el4.i386.rpm acroread-plugin-9.4.7-1.el4.i386.rpm x86_64: acroread-9.4.7-1.el4.i386.rpm Red Hat Desktop version 4 Extras: i386: acroread-9.4.7-1.el4.i386.rpm acroread-plugin-9.4.7-1.el4.i386.rpm x86_64: acroread-9.4.7-1.el4.i386.rpm Red Hat Enterprise Linux ES version 4 Extras: i386: acroread-9.4.7-1.el4.i386.rpm acroread-plugin-9.4.7-1.el4.i386.rpm x86_64: acroread-9.4.7-1.el4.i386.rpm Red Hat Enterprise Linux WS version 4 Extras: i386: acroread-9.4.7-1.el4.i386.rpm acroread-plugin-9.4.7-1.el4.i386.rpm x86_64: acroread-9.4.7-1.el4.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v. 5): i386: acroread-9.4.7-1.el5.i386.rpm acroread-plugin-9.4.7-1.el5.i386.rpm x86_64: acroread-9.4.7-1.el5.i386.rpm acroread-plugin-9.4.7-1.el5.i386.rpm Red Hat Enterprise Linux Server Supplementary (v. 5): i386: acroread-9.4.7-1.el5.i386.rpm acroread-plugin-9.4.7-1.el5.i386.rpm x86_64: acroread-9.4.7-1.el5.i386.rpm acroread-plugin-9.4.7-1.el5.i386.rpm Red Hat Enterprise Linux Desktop Supplementary (v.6): i386: acroread-9.4.7-1.el6.i686.rpm acroread-plugin-9.4.7-1.el6.i686.rpm x86_64: acroread-9.4.7-1.el6.i686.rpm acroread-plugin-9.4.7-1.el6.i686.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: acroread-9.4.7-1.el6.i686.rpm acroread-plugin-9.4.7-1.el6.i686.rpm x86_64: acroread-9.4.7-1.el6.i686.rpm acroread-plugin-9.4.7-1.el6.i686.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: acroread-9.4.7-1.el6.i686.rpm acroread-plugin-9.4.7-1.el6.i686.rpm x86_64: acroread-9.4.7-1.el6.i686.rpm acroread-plugin-9.4.7-1.el6.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2011-2462 https://access.redhat.com/security/cve/CVE-2011-4369 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2012 Red Hat, Inc. . Newly released acroread updates for Red Hat address severe security vulnerabilities impacting multiple distributions. Apply them immediately!. acroread update, security advisory, Red Hat packages, critical fix, software update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 10, 2012 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200