Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
98

Red Hat Enterprise Linux 6 RHSA-2018:3000-01 Critical: Java Update DoS

An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Critical: java-1.7.0-oracle security update Advisory ID: RHSA-2018:3000-01 Product: Oracle Java for Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:3000 Issue date: 2018-10-24 CVE Names: CVE-2018-3136 CVE-2018-3139 CVE-2018-3149 CVE-2018-3169 CVE-2018-3180 CVE-2018-3214 CVE-2018-13785 ==================================================================== 1. Summary: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Oracle Java for Red Hat Enterprise Linux Desktop 6 - i386, x86_64 Oracle Java for Red Hat Enterprise Linux HPC Node 6 - x86_64 Oracle Java for Red Hat Enterprise Linux Server 6 - i386, x86_64 Oracle Java for Red Hat Enterprise Linux Workstation 6 - i386, x86_64 3. Description: Oracle Java SE version 7 includes the Oracle Java Runtime Environment and the Oracle Java Software Development Kit. This update upgrades Oracle Java SE 7 to version 7 Update 201. Security Fix(es): * OpenJDK: Improper field access checks (Hotspot, 8199226) (CVE-2018-3169) * OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177) (CVE-2018-3149) * OpenJDK: Incorrect handling of unsigned attributes in signedJar manifests (Security, 8194534) (CVE-2018-3136) * OpenJDK: Leak of sensitive header data via HTTP redirect (Networking, 8196902) (CVE-2018-3139) * OpenJDK: Missing endpoint identification algorithm check during TLS session resumption (JSSE, 8202613) (CVE-2018-3180) * OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361) (CVE-2018-3214) * libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service (CVE-2018-13785) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Oracle Java must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1599943 - CVE-2018-13785 libpng: Integer overflow and resultant divide-by-zero in pngrutil.c:png_check_chunk_length() allows for denial of service 1639293 - CVE-2018-3169 OpenJDK: Improper field access checks (Hotspot, 8199226) 1639301 - CVE-2018-3214 OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361) 1639442 - CVE-2018-3139 OpenJDK: Leak of sensitive header data via HTTP redirect (Networking, 8196902) 1639484 - CVE-2018-3180 OpenJDK: Missing endpoint identification algorithm check during TLS session resumption (JSSE, 8202613) 1639755 - CVE-2018-3136 OpenJDK: Incorrect handling of unsigned attributes in signed Jar manifests (Security, 8194534) 1639834 - CVE-2018-3149 OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177) 6. Package List: Oracle Java for Red Hat Enterprise Linux Desktop6: i386: java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-javafx-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-jdbc-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-plugin-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-src-1.7.0.201-1jpp.1.el6.i686.rpm x86_64: java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-javafx-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-jdbc-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-plugin-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-src-1.7.0.201-1jpp.1.el6.x86_64.rpm Oracle Java for Red Hat Enterprise Linux HPC Node 6: x86_64: java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-javafx-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-jdbc-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-plugin-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-src-1.7.0.201-1jpp.1.el6.x86_64.rpm Oracle Java for Red Hat Enterprise Linux Server6: i386: java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-javafx-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-jdbc-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-plugin-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-src-1.7.0.201-1jpp.1.el6.i686.rpm x86_64: java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-javafx-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-jdbc-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-plugin-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-src-1.7.0.201-1jpp.1.el6.x86_64.rpm Oracle Java for Red Hat Enterprise Linux Workstation 6: i386: java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-javafx-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-jdbc-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-plugin-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-src-1.7.0.201-1jpp.1.el6.i686.rpm x86_64: java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.i686.rpm java-1.7.0-oracle-devel-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-javafx-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-jdbc-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-plugin-1.7.0.201-1jpp.1.el6.x86_64.rpm java-1.7.0-oracle-src-1.7.0.201-1jpp.1.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2018-3136 https://access.redhat.com/security/cve/CVE-2018-3139 https://access.redhat.com/security/cve/CVE-2018-3149 https://access.redhat.com/security/cve/CVE-2018-3169 https://access.redhat.com/security/cve/CVE-2018-3180 https://access.redhat.com/security/cve/CVE-2018-3214 https://access.redhat.com/security/cve/CVE-2018-13785 https://access.redhat.com/security/updates/classification/#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBW9DtDdzjgjWX9erEAQhVSRAAkA/3YRf3BtIzZ+QHlWPB++MaADIQBRnY GhQkRbEgrsnlgIpwTCUuDRTwSfI+yx3kPpBJAn2vSZ4+WNkeY0/B9Ea2AmfzZoDY h5uCaquHS3jMLbSzITR47SYjn3VNjppBu9STr1xfZPR55UDV8P9qflhdrAiqiwfZ IxS/IHya04zNw9OoM86xzQpMGikLNtFuDZWvjgmatfsYoh64HtsQ93WEyi6XpGq3 cHd8on7LZK3+CDd/M1j4/7u+LV3GL+whXvf7w+QrAz/B16lnikkRSqEBkld8MJ1N EbtD9J49LcqnyafYj2Z7ZaDZL2FHvJ+OVc4z9SaUz6Fj8NLA2oiTB8xmIiczZxZl HpihevB2UyfVBBQnFfg1RxhjNIDKkEwR6Fxwf7Der2g2v8KRhYWqGqL+Pvlyl/Ck estne9yXDWS/O0GMYpMkm7HXa51noJG3eoG6wjPG6DeVef06JC8XjJoA6sQJmaQs LxcW9EKGNeY8dlseOzmc/1ZQjqnbg5AmLfxDxv9jzvVqab9UdgGPwwozQ6eaEhQO B2QsNzsVhvnJ8qvvJAGYMy+OI/rw3AeSDEZA9EKH2fu2o7Uo6qDKRD/m3lBICiWI PER9HZAwiAaCegRk2HniQVWSvsUfXvGZ7pyVYCaZ86edeNpJhDIvFLtl9DJRUel4 6YUGUCWMTfw=P/Bz -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Essential patch for java-1.7.0-oracle on Red Hat Enterprise Linux addressing important security vulnerabilities.. Red Hat Updates, Oracle Java Security, Critical Patch, Enterprise Linux Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 24, 2018 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here