Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
198

Arch Linux: 201603-2 High: OpenSSL Multiple Threats And Issues

The package openssl before version 1.0.2.g-3 is vulnerable to multiple issues including but not limited to private key extraction, denial of service, arbitrary code execution, resource consumption and cross-protocol attacks leading to cipher text decryption. . Arch Linux Security Advisory ASA-201603-2 ======================================== Severity: High Date : 2016-03-07 CVE-ID : CVE-2016-0702 CVE-2016-0705 CVE-2016-0797 CVE-2016-0798 CVE-2016-0799 CVE-2016-0800 Package : openssl Type : multiple issues Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package openssl before version 1.0.2.g-3 is vulnerable to multiple issues including but not limited to private key extraction, denial of service, arbitrary code execution, resource consumption and cross-protocol attacks leading to cipher text decryption. Resolution ========= Upgrade to 1.0.2.g-3. # pacman -Syu "openssl> =1.0.2.g-3" The problems have been fixed upstream in version 1.0.2.g-3. Workaround ========= None. Description ========== - CVE-2016-0702 (private key extraction) A side-channel attack was found that makes use of cache-bank conflicts on the Intel Sandy-Bridge microarchitecture. An attacker who has the ability to control code in a thread running on the same hyper-threaded core as the victim's thread that is performing decryption, could use this flaw to recover RSA private keys. - CVE-2016-0705 (denial of service) A double-free flaw was found in the way OpenSSL parsed certain malformed DSA (Digital Signature Algorithm) private keys. An attacker could create specially crafted DSA private keys that, when processed by an application compiled against OpenSSL, could cause the application to crash. - CVE-2016-0797 (arbitrary code execution) An integer overflow flaw, leading to a NULL pointer dereference or a heap-based memory corruption, was found in the way some BIGNUM functions of OpenSSL were implemented. Applications that use these functionswith large untrusted input could crash or, potentially, execute arbitrary code. - CVE-2016-0798 (resource consumption) A memory leak flaw was found in the way OpenSSL performed SRP user database look-ups using the SRP_VBASE_get_by_user() function. A remote attacker connecting to certain SRP servers with an invalid user name could leak approximately 300 bytes of the server's memory per connection. - CVE-2016-0799 (denial of service) The fmtstr function in crypto/bio/b_print.c improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842. - CVE-2016-0800 (cross-protocol attack) A padding oracle flaw was found in the Secure Sockets Layer version 2.0 (SSLv2) protocol. An attacker can potentially use this flaw to decrypt RSA-encrypted cipher text from a connection using a newer SSL/TLS protocol version, allowing them to decrypt such connections. This cross-protocol attack is publicly referred to as DROWN. Impact ===== A remote attacker is able to use multiple issues to perform a denial of service attack, trigger a memory leak resulting in resource consumption, use a cross-protocol attack that is leading to cipher text decryption or possibly execute arbitrary code under certain circumstances. Furthermore a local attacker may be able to extract the RSA private key by running code in a thread that is running on the same hyper-threaded core as the victim's thread that is performingdecryption. References ========= https://openssl-library.org/news/secadv/20160301.txt https://access.redhat.com/security/cve/CVE-2016-0702 https://access.redhat.com/security/cve/CVE-2016-0705 https://access.redhat.com/security/cve/CVE-2016-0797 https://access.redhat.com/security/cve/CVE-2016-0798 https://access.redhat.com/security/cve/CVE-2016-0799 https://access.redhat.com/security/cve/CVE-2016-0800 . Critical vulnerabilities detected in the Arch Linux openssl package necessitate an urgent update to address potential security risks.. Arch Linux, OpenSSL Issues, Remote Attack, Security Risks. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2016 ArchLinux
202

openSUSE 13.2: 2015:0285-1 Important: Clamav DoS Threats and Fixes

An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for clamav ______________________________________________________________________________ Announcement ID: openSUSE-SU-2015:0285-1 Rating: important References: #915512 #916214 #916215 #916217 Cross-References: CVE-2014-9328 CVE-2015-1461 CVE-2015-1462 CVE-2015-1463 Affected Products: openSUSE 13.2 openSUSE 13.1 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: clamav was updated to version 0.98.6 that fixes bugs and several security issues: * bsc#916217, CVE-2015-1461: Remote attackers can have unspecified impact via Yoda's crypter or mew packer files. * bsc#916214, CVE-2015-1462: Unspecified impact via acrafted upx packer file. * bsc#916215, CVE-2015-1463: Remote attackers can cause a denial of service via a crafted petite packer file. * bsc#915512, CVE-2014-9328: heap out of bounds condition with crafted upack packer files. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2015-147=1 - openSUSE 13.1: zypper in -t patch openSUSE-2015-147=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (i586 x86_64): clamav-0.98.6-2.13.1 clamav-debuginfo-0.98.6-2.13.1 clamav-debugsource-0.98.6-2.13.1 - openSUSE 13.1 (i586 x86_64): clamav-0.98.6-30.1 clamav-debuginfo-0.98.6-30.1 clamav-debugsource-0.98.6-30.1 References: https://www.suse.com/security/cve/CVE-2014-9328.html https://www.suse.com/security/cve/CVE-2015-1461.html https://www.suse.com/security/cve/CVE-2015-1462.html https://www.suse.com/security/cve/CVE-2015-1463.html https://bugzilla.suse.com/show_bug.cgi?id=915512 https://bugzilla.suse.com/show_bug.cgi?id=916214 https://bugzilla.suse.com/show_bug.cgi?id=916215 https://bugzilla.suse.com/show_bug.cgi?id=916217 . This critical update report highlights various enhancements for clamav on openSUSE, safeguarding the system's security.. clamav security, software update, openSUSE patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 13, 2015 Important OpenSUSE
98

Red Hat RHSA-2014:1767-01 Urgent: PHP Remote Security Vulnerabilities

Updated php packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: php security update Advisory ID: RHSA-2014:1767-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:1767.html Issue date: 2014-10-30 CVE Names: CVE-2014-3668 CVE-2014-3669 CVE-2014-3670 CVE-2014-3710 ==================================================================== 1. Summary: Updated php packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v.7) - x86_64 3. Description: PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A buffer overflow flaw was found in the Exif extension. A specially crafted JPEG or TIFF file could cause a PHP application using the exif_thumbnail() function to crash or, possibly, execute arbitrary code with the privileges of the user running that PHP application. (CVE-2014-3670) An integer overflow flaw was found in the way custom objects were unserialized. Specially crafted input processed by the unserialize() function could cause a PHP application to crash. (CVE-2014-3669) An out-of-bounds read flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted ELF file. (CVE-2014-3710) An out of bounds read flaw was found in the way the xmlrpc extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC request or response could possibly cause a PHP application to crash. (CVE-2014-3668) The CVE-2014-3710 issue was discovered by Francisco Alonso of Red Hat Product Security. All php users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the httpd daemon must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1154500 - CVE-2014-3669 php: integer overflow in unserialize() 1154502 - CVE-2014-3670 php: heap corruption issue in exif_thumbnail() 1154503 - CVE-2014-3668 php: xmlrpc ISO8601 date format parsing out-of-bounds read in mkgmtime() 1155071 - CVE-2014-3710 file: out-of-bounds read in elfnote headers 6. Package List: Red Hat Enterprise Linux Desktop Optional (v.6): Source: php-5.3.3-40.el6_6.src.rpm i386: php-5.3.3-40.el6_6.i686.rpm php-bcmath-5.3.3-40.el6_6.i686.rpm php-cli-5.3.3-40.el6_6.i686.rpm php-common-5.3.3-40.el6_6.i686.rpm php-dba-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-devel-5.3.3-40.el6_6.i686.rpm php-embedded-5.3.3-40.el6_6.i686.rpm php-enchant-5.3.3-40.el6_6.i686.rpm php-fpm-5.3.3-40.el6_6.i686.rpm php-gd-5.3.3-40.el6_6.i686.rpm php-imap-5.3.3-40.el6_6.i686.rpm php-intl-5.3.3-40.el6_6.i686.rpm php-ldap-5.3.3-40.el6_6.i686.rpm php-mbstring-5.3.3-40.el6_6.i686.rpm php-mysql-5.3.3-40.el6_6.i686.rpm php-odbc-5.3.3-40.el6_6.i686.rpm php-pdo-5.3.3-40.el6_6.i686.rpm php-pgsql-5.3.3-40.el6_6.i686.rpm php-process-5.3.3-40.el6_6.i686.rpm php-pspell-5.3.3-40.el6_6.i686.rpm php-recode-5.3.3-40.el6_6.i686.rpm php-snmp-5.3.3-40.el6_6.i686.rpm php-soap-5.3.3-40.el6_6.i686.rpm php-tidy-5.3.3-40.el6_6.i686.rpm php-xml-5.3.3-40.el6_6.i686.rpm php-xmlrpc-5.3.3-40.el6_6.i686.rpm php-zts-5.3.3-40.el6_6.i686.rpm x86_64: php-5.3.3-40.el6_6.x86_64.rpm php-bcmath-5.3.3-40.el6_6.x86_64.rpm php-cli-5.3.3-40.el6_6.x86_64.rpm php-common-5.3.3-40.el6_6.x86_64.rpm php-dba-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-devel-5.3.3-40.el6_6.x86_64.rpm php-embedded-5.3.3-40.el6_6.x86_64.rpm php-enchant-5.3.3-40.el6_6.x86_64.rpm php-fpm-5.3.3-40.el6_6.x86_64.rpm php-gd-5.3.3-40.el6_6.x86_64.rpm php-imap-5.3.3-40.el6_6.x86_64.rpm php-intl-5.3.3-40.el6_6.x86_64.rpm php-ldap-5.3.3-40.el6_6.x86_64.rpm php-mbstring-5.3.3-40.el6_6.x86_64.rpm php-mysql-5.3.3-40.el6_6.x86_64.rpm php-odbc-5.3.3-40.el6_6.x86_64.rpm php-pdo-5.3.3-40.el6_6.x86_64.rpm php-pgsql-5.3.3-40.el6_6.x86_64.rpm php-process-5.3.3-40.el6_6.x86_64.rpm php-pspell-5.3.3-40.el6_6.x86_64.rpm php-recode-5.3.3-40.el6_6.x86_64.rpm php-snmp-5.3.3-40.el6_6.x86_64.rpm php-soap-5.3.3-40.el6_6.x86_64.rpm php-tidy-5.3.3-40.el6_6.x86_64.rpm php-xml-5.3.3-40.el6_6.x86_64.rpm php-xmlrpc-5.3.3-40.el6_6.x86_64.rpm php-zts-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux HPC Node (v.6): Source: php-5.3.3-40.el6_6.src.rpm x86_64: php-cli-5.3.3-40.el6_6.x86_64.rpm php-common-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): x86_64: php-5.3.3-40.el6_6.x86_64.rpm php-bcmath-5.3.3-40.el6_6.x86_64.rpm php-dba-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-devel-5.3.3-40.el6_6.x86_64.rpm php-embedded-5.3.3-40.el6_6.x86_64.rpm php-enchant-5.3.3-40.el6_6.x86_64.rpm php-fpm-5.3.3-40.el6_6.x86_64.rpm php-gd-5.3.3-40.el6_6.x86_64.rpm php-imap-5.3.3-40.el6_6.x86_64.rpm php-intl-5.3.3-40.el6_6.x86_64.rpm php-ldap-5.3.3-40.el6_6.x86_64.rpm php-mbstring-5.3.3-40.el6_6.x86_64.rpm php-mysql-5.3.3-40.el6_6.x86_64.rpm php-odbc-5.3.3-40.el6_6.x86_64.rpm php-pdo-5.3.3-40.el6_6.x86_64.rpm php-pgsql-5.3.3-40.el6_6.x86_64.rpm php-process-5.3.3-40.el6_6.x86_64.rpm php-pspell-5.3.3-40.el6_6.x86_64.rpm php-recode-5.3.3-40.el6_6.x86_64.rpm php-snmp-5.3.3-40.el6_6.x86_64.rpm php-soap-5.3.3-40.el6_6.x86_64.rpm php-tidy-5.3.3-40.el6_6.x86_64.rpm php-xml-5.3.3-40.el6_6.x86_64.rpm php-xmlrpc-5.3.3-40.el6_6.x86_64.rpm php-zts-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: php-5.3.3-40.el6_6.src.rpm i386: php-5.3.3-40.el6_6.i686.rpm php-cli-5.3.3-40.el6_6.i686.rpm php-common-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-gd-5.3.3-40.el6_6.i686.rpm php-ldap-5.3.3-40.el6_6.i686.rpm php-mysql-5.3.3-40.el6_6.i686.rpm php-odbc-5.3.3-40.el6_6.i686.rpm php-pdo-5.3.3-40.el6_6.i686.rpm php-pgsql-5.3.3-40.el6_6.i686.rpm php-soap-5.3.3-40.el6_6.i686.rpm php-xml-5.3.3-40.el6_6.i686.rpm php-xmlrpc-5.3.3-40.el6_6.i686.rpm ppc64: php-5.3.3-40.el6_6.ppc64.rpm php-cli-5.3.3-40.el6_6.ppc64.rpm php-common-5.3.3-40.el6_6.ppc64.rpm php-debuginfo-5.3.3-40.el6_6.ppc64.rpm php-gd-5.3.3-40.el6_6.ppc64.rpm php-ldap-5.3.3-40.el6_6.ppc64.rpm php-mysql-5.3.3-40.el6_6.ppc64.rpm php-odbc-5.3.3-40.el6_6.ppc64.rpm php-pdo-5.3.3-40.el6_6.ppc64.rpm php-pgsql-5.3.3-40.el6_6.ppc64.rpm php-soap-5.3.3-40.el6_6.ppc64.rpm php-xml-5.3.3-40.el6_6.ppc64.rpm php-xmlrpc-5.3.3-40.el6_6.ppc64.rpm s390x: php-5.3.3-40.el6_6.s390x.rpm php-cli-5.3.3-40.el6_6.s390x.rpm php-common-5.3.3-40.el6_6.s390x.rpm php-debuginfo-5.3.3-40.el6_6.s390x.rpm php-gd-5.3.3-40.el6_6.s390x.rpm php-ldap-5.3.3-40.el6_6.s390x.rpm php-mysql-5.3.3-40.el6_6.s390x.rpm php-odbc-5.3.3-40.el6_6.s390x.rpm php-pdo-5.3.3-40.el6_6.s390x.rpm php-pgsql-5.3.3-40.el6_6.s390x.rpm php-soap-5.3.3-40.el6_6.s390x.rpm php-xml-5.3.3-40.el6_6.s390x.rpm php-xmlrpc-5.3.3-40.el6_6.s390x.rpm x86_64: php-5.3.3-40.el6_6.x86_64.rpm php-cli-5.3.3-40.el6_6.x86_64.rpm php-common-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-gd-5.3.3-40.el6_6.x86_64.rpm php-ldap-5.3.3-40.el6_6.x86_64.rpm php-mysql-5.3.3-40.el6_6.x86_64.rpm php-odbc-5.3.3-40.el6_6.x86_64.rpm php-pdo-5.3.3-40.el6_6.x86_64.rpm php-pgsql-5.3.3-40.el6_6.x86_64.rpm php-soap-5.3.3-40.el6_6.x86_64.rpm php-xml-5.3.3-40.el6_6.x86_64.rpm php-xmlrpc-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): i386: php-bcmath-5.3.3-40.el6_6.i686.rpm php-dba-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-devel-5.3.3-40.el6_6.i686.rpm php-embedded-5.3.3-40.el6_6.i686.rpm php-enchant-5.3.3-40.el6_6.i686.rpm php-fpm-5.3.3-40.el6_6.i686.rpm php-imap-5.3.3-40.el6_6.i686.rpm php-intl-5.3.3-40.el6_6.i686.rpm php-mbstring-5.3.3-40.el6_6.i686.rpm php-process-5.3.3-40.el6_6.i686.rpm php-pspell-5.3.3-40.el6_6.i686.rpm php-recode-5.3.3-40.el6_6.i686.rpm php-snmp-5.3.3-40.el6_6.i686.rpm php-tidy-5.3.3-40.el6_6.i686.rpm php-zts-5.3.3-40.el6_6.i686.rpm ppc64: php-bcmath-5.3.3-40.el6_6.ppc64.rpm php-dba-5.3.3-40.el6_6.ppc64.rpm php-debuginfo-5.3.3-40.el6_6.ppc64.rpm php-devel-5.3.3-40.el6_6.ppc64.rpm php-embedded-5.3.3-40.el6_6.ppc64.rpm php-enchant-5.3.3-40.el6_6.ppc64.rpm php-fpm-5.3.3-40.el6_6.ppc64.rpm php-imap-5.3.3-40.el6_6.ppc64.rpm php-intl-5.3.3-40.el6_6.ppc64.rpm php-mbstring-5.3.3-40.el6_6.ppc64.rpm php-process-5.3.3-40.el6_6.ppc64.rpm php-pspell-5.3.3-40.el6_6.ppc64.rpm php-recode-5.3.3-40.el6_6.ppc64.rpm php-snmp-5.3.3-40.el6_6.ppc64.rpm php-tidy-5.3.3-40.el6_6.ppc64.rpm php-zts-5.3.3-40.el6_6.ppc64.rpm s390x: php-bcmath-5.3.3-40.el6_6.s390x.rpm php-dba-5.3.3-40.el6_6.s390x.rpm php-debuginfo-5.3.3-40.el6_6.s390x.rpm php-devel-5.3.3-40.el6_6.s390x.rpm php-embedded-5.3.3-40.el6_6.s390x.rpm php-enchant-5.3.3-40.el6_6.s390x.rpm php-fpm-5.3.3-40.el6_6.s390x.rpm php-imap-5.3.3-40.el6_6.s390x.rpm php-intl-5.3.3-40.el6_6.s390x.rpm php-mbstring-5.3.3-40.el6_6.s390x.rpm php-process-5.3.3-40.el6_6.s390x.rpm php-pspell-5.3.3-40.el6_6.s390x.rpm php-recode-5.3.3-40.el6_6.s390x.rpm php-snmp-5.3.3-40.el6_6.s390x.rpm php-tidy-5.3.3-40.el6_6.s390x.rpm php-zts-5.3.3-40.el6_6.s390x.rpm x86_64: php-bcmath-5.3.3-40.el6_6.x86_64.rpm php-dba-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-devel-5.3.3-40.el6_6.x86_64.rpm php-embedded-5.3.3-40.el6_6.x86_64.rpm php-enchant-5.3.3-40.el6_6.x86_64.rpm php-fpm-5.3.3-40.el6_6.x86_64.rpm php-imap-5.3.3-40.el6_6.x86_64.rpm php-intl-5.3.3-40.el6_6.x86_64.rpm php-mbstring-5.3.3-40.el6_6.x86_64.rpm php-process-5.3.3-40.el6_6.x86_64.rpm php-pspell-5.3.3-40.el6_6.x86_64.rpm php-recode-5.3.3-40.el6_6.x86_64.rpm php-snmp-5.3.3-40.el6_6.x86_64.rpm php-tidy-5.3.3-40.el6_6.x86_64.rpm php-zts-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: php-5.3.3-40.el6_6.src.rpm i386: php-5.3.3-40.el6_6.i686.rpm php-cli-5.3.3-40.el6_6.i686.rpm php-common-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-gd-5.3.3-40.el6_6.i686.rpm php-ldap-5.3.3-40.el6_6.i686.rpm php-mysql-5.3.3-40.el6_6.i686.rpm php-odbc-5.3.3-40.el6_6.i686.rpm php-pdo-5.3.3-40.el6_6.i686.rpm php-pgsql-5.3.3-40.el6_6.i686.rpm php-soap-5.3.3-40.el6_6.i686.rpm php-xml-5.3.3-40.el6_6.i686.rpm php-xmlrpc-5.3.3-40.el6_6.i686.rpm x86_64: php-5.3.3-40.el6_6.x86_64.rpm php-cli-5.3.3-40.el6_6.x86_64.rpm php-common-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-gd-5.3.3-40.el6_6.x86_64.rpm php-ldap-5.3.3-40.el6_6.x86_64.rpm php-mysql-5.3.3-40.el6_6.x86_64.rpm php-odbc-5.3.3-40.el6_6.x86_64.rpm php-pdo-5.3.3-40.el6_6.x86_64.rpm php-pgsql-5.3.3-40.el6_6.x86_64.rpm php-soap-5.3.3-40.el6_6.x86_64.rpm php-xml-5.3.3-40.el6_6.x86_64.rpm php-xmlrpc-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.6): i386: php-bcmath-5.3.3-40.el6_6.i686.rpm php-dba-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-devel-5.3.3-40.el6_6.i686.rpm php-embedded-5.3.3-40.el6_6.i686.rpm php-enchant-5.3.3-40.el6_6.i686.rpm php-fpm-5.3.3-40.el6_6.i686.rpm php-imap-5.3.3-40.el6_6.i686.rpm php-intl-5.3.3-40.el6_6.i686.rpm php-mbstring-5.3.3-40.el6_6.i686.rpm php-process-5.3.3-40.el6_6.i686.rpm php-pspell-5.3.3-40.el6_6.i686.rpm php-recode-5.3.3-40.el6_6.i686.rpm php-snmp-5.3.3-40.el6_6.i686.rpm php-tidy-5.3.3-40.el6_6.i686.rpm php-zts-5.3.3-40.el6_6.i686.rpm x86_64: php-bcmath-5.3.3-40.el6_6.x86_64.rpm php-dba-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-devel-5.3.3-40.el6_6.x86_64.rpm php-embedded-5.3.3-40.el6_6.x86_64.rpm php-enchant-5.3.3-40.el6_6.x86_64.rpm php-fpm-5.3.3-40.el6_6.x86_64.rpm php-imap-5.3.3-40.el6_6.x86_64.rpm php-intl-5.3.3-40.el6_6.x86_64.rpm php-mbstring-5.3.3-40.el6_6.x86_64.rpm php-process-5.3.3-40.el6_6.x86_64.rpm php-pspell-5.3.3-40.el6_6.x86_64.rpm php-recode-5.3.3-40.el6_6.x86_64.rpm php-snmp-5.3.3-40.el6_6.x86_64.rpm php-tidy-5.3.3-40.el6_6.x86_64.rpm php-zts-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Client Optional (v.7): Source: php-5.4.16-23.el7_0.3.src.rpm x86_64: php-5.4.16-23.el7_0.3.x86_64.rpm php-bcmath-5.4.16-23.el7_0.3.x86_64.rpm php-cli-5.4.16-23.el7_0.3.x86_64.rpm php-common-5.4.16-23.el7_0.3.x86_64.rpm php-dba-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-devel-5.4.16-23.el7_0.3.x86_64.rpm php-embedded-5.4.16-23.el7_0.3.x86_64.rpm php-enchant-5.4.16-23.el7_0.3.x86_64.rpm php-fpm-5.4.16-23.el7_0.3.x86_64.rpm php-gd-5.4.16-23.el7_0.3.x86_64.rpm php-intl-5.4.16-23.el7_0.3.x86_64.rpm php-ldap-5.4.16-23.el7_0.3.x86_64.rpm php-mbstring-5.4.16-23.el7_0.3.x86_64.rpm php-mysql-5.4.16-23.el7_0.3.x86_64.rpm php-mysqlnd-5.4.16-23.el7_0.3.x86_64.rpm php-odbc-5.4.16-23.el7_0.3.x86_64.rpm php-pdo-5.4.16-23.el7_0.3.x86_64.rpm php-pgsql-5.4.16-23.el7_0.3.x86_64.rpm php-process-5.4.16-23.el7_0.3.x86_64.rpm php-pspell-5.4.16-23.el7_0.3.x86_64.rpm php-recode-5.4.16-23.el7_0.3.x86_64.rpm php-snmp-5.4.16-23.el7_0.3.x86_64.rpm php-soap-5.4.16-23.el7_0.3.x86_64.rpm php-xml-5.4.16-23.el7_0.3.x86_64.rpm php-xmlrpc-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): Source: php-5.4.16-23.el7_0.3.src.rpm x86_64: php-5.4.16-23.el7_0.3.x86_64.rpm php-bcmath-5.4.16-23.el7_0.3.x86_64.rpm php-cli-5.4.16-23.el7_0.3.x86_64.rpm php-common-5.4.16-23.el7_0.3.x86_64.rpm php-dba-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-devel-5.4.16-23.el7_0.3.x86_64.rpm php-embedded-5.4.16-23.el7_0.3.x86_64.rpm php-enchant-5.4.16-23.el7_0.3.x86_64.rpm php-fpm-5.4.16-23.el7_0.3.x86_64.rpm php-gd-5.4.16-23.el7_0.3.x86_64.rpm php-intl-5.4.16-23.el7_0.3.x86_64.rpm php-ldap-5.4.16-23.el7_0.3.x86_64.rpm php-mbstring-5.4.16-23.el7_0.3.x86_64.rpm php-mysql-5.4.16-23.el7_0.3.x86_64.rpm php-mysqlnd-5.4.16-23.el7_0.3.x86_64.rpm php-odbc-5.4.16-23.el7_0.3.x86_64.rpm php-pdo-5.4.16-23.el7_0.3.x86_64.rpm php-pgsql-5.4.16-23.el7_0.3.x86_64.rpm php-process-5.4.16-23.el7_0.3.x86_64.rpm php-pspell-5.4.16-23.el7_0.3.x86_64.rpm php-recode-5.4.16-23.el7_0.3.x86_64.rpm php-snmp-5.4.16-23.el7_0.3.x86_64.rpm php-soap-5.4.16-23.el7_0.3.x86_64.rpm php-xml-5.4.16-23.el7_0.3.x86_64.rpm php-xmlrpc-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: php-5.4.16-23.el7_0.3.src.rpm ppc64: php-5.4.16-23.el7_0.3.ppc64.rpm php-cli-5.4.16-23.el7_0.3.ppc64.rpm php-common-5.4.16-23.el7_0.3.ppc64.rpm php-debuginfo-5.4.16-23.el7_0.3.ppc64.rpm php-gd-5.4.16-23.el7_0.3.ppc64.rpm php-ldap-5.4.16-23.el7_0.3.ppc64.rpm php-mysql-5.4.16-23.el7_0.3.ppc64.rpm php-odbc-5.4.16-23.el7_0.3.ppc64.rpm php-pdo-5.4.16-23.el7_0.3.ppc64.rpm php-pgsql-5.4.16-23.el7_0.3.ppc64.rpm php-process-5.4.16-23.el7_0.3.ppc64.rpm php-recode-5.4.16-23.el7_0.3.ppc64.rpm php-soap-5.4.16-23.el7_0.3.ppc64.rpm php-xml-5.4.16-23.el7_0.3.ppc64.rpm php-xmlrpc-5.4.16-23.el7_0.3.ppc64.rpm s390x: php-5.4.16-23.el7_0.3.s390x.rpm php-cli-5.4.16-23.el7_0.3.s390x.rpm php-common-5.4.16-23.el7_0.3.s390x.rpm php-debuginfo-5.4.16-23.el7_0.3.s390x.rpm php-gd-5.4.16-23.el7_0.3.s390x.rpm php-ldap-5.4.16-23.el7_0.3.s390x.rpm php-mysql-5.4.16-23.el7_0.3.s390x.rpm php-odbc-5.4.16-23.el7_0.3.s390x.rpm php-pdo-5.4.16-23.el7_0.3.s390x.rpm php-pgsql-5.4.16-23.el7_0.3.s390x.rpm php-process-5.4.16-23.el7_0.3.s390x.rpm php-recode-5.4.16-23.el7_0.3.s390x.rpm php-soap-5.4.16-23.el7_0.3.s390x.rpm php-xml-5.4.16-23.el7_0.3.s390x.rpm php-xmlrpc-5.4.16-23.el7_0.3.s390x.rpm x86_64: php-5.4.16-23.el7_0.3.x86_64.rpm php-cli-5.4.16-23.el7_0.3.x86_64.rpm php-common-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-gd-5.4.16-23.el7_0.3.x86_64.rpm php-ldap-5.4.16-23.el7_0.3.x86_64.rpm php-mysql-5.4.16-23.el7_0.3.x86_64.rpm php-odbc-5.4.16-23.el7_0.3.x86_64.rpm php-pdo-5.4.16-23.el7_0.3.x86_64.rpm php-pgsql-5.4.16-23.el7_0.3.x86_64.rpm php-process-5.4.16-23.el7_0.3.x86_64.rpm php-recode-5.4.16-23.el7_0.3.x86_64.rpm php-soap-5.4.16-23.el7_0.3.x86_64.rpm php-xml-5.4.16-23.el7_0.3.x86_64.rpm php-xmlrpc-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: php-bcmath-5.4.16-23.el7_0.3.ppc64.rpm php-dba-5.4.16-23.el7_0.3.ppc64.rpm php-debuginfo-5.4.16-23.el7_0.3.ppc64.rpm php-devel-5.4.16-23.el7_0.3.ppc64.rpm php-embedded-5.4.16-23.el7_0.3.ppc64.rpm php-enchant-5.4.16-23.el7_0.3.ppc64.rpm php-fpm-5.4.16-23.el7_0.3.ppc64.rpm php-intl-5.4.16-23.el7_0.3.ppc64.rpm php-mbstring-5.4.16-23.el7_0.3.ppc64.rpm php-mysqlnd-5.4.16-23.el7_0.3.ppc64.rpm php-pspell-5.4.16-23.el7_0.3.ppc64.rpm php-snmp-5.4.16-23.el7_0.3.ppc64.rpm s390x: php-bcmath-5.4.16-23.el7_0.3.s390x.rpm php-dba-5.4.16-23.el7_0.3.s390x.rpm php-debuginfo-5.4.16-23.el7_0.3.s390x.rpm php-devel-5.4.16-23.el7_0.3.s390x.rpm php-embedded-5.4.16-23.el7_0.3.s390x.rpm php-enchant-5.4.16-23.el7_0.3.s390x.rpm php-fpm-5.4.16-23.el7_0.3.s390x.rpm php-intl-5.4.16-23.el7_0.3.s390x.rpm php-mbstring-5.4.16-23.el7_0.3.s390x.rpm php-mysqlnd-5.4.16-23.el7_0.3.s390x.rpm php-pspell-5.4.16-23.el7_0.3.s390x.rpm php-snmp-5.4.16-23.el7_0.3.s390x.rpm x86_64: php-bcmath-5.4.16-23.el7_0.3.x86_64.rpm php-dba-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-devel-5.4.16-23.el7_0.3.x86_64.rpm php-embedded-5.4.16-23.el7_0.3.x86_64.rpm php-enchant-5.4.16-23.el7_0.3.x86_64.rpm php-fpm-5.4.16-23.el7_0.3.x86_64.rpm php-intl-5.4.16-23.el7_0.3.x86_64.rpm php-mbstring-5.4.16-23.el7_0.3.x86_64.rpm php-mysqlnd-5.4.16-23.el7_0.3.x86_64.rpm php-pspell-5.4.16-23.el7_0.3.x86_64.rpm php-snmp-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux Workstation (v.7): Source: php-5.4.16-23.el7_0.3.src.rpm x86_64: php-5.4.16-23.el7_0.3.x86_64.rpm php-cli-5.4.16-23.el7_0.3.x86_64.rpm php-common-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-gd-5.4.16-23.el7_0.3.x86_64.rpm php-ldap-5.4.16-23.el7_0.3.x86_64.rpm php-mysql-5.4.16-23.el7_0.3.x86_64.rpm php-odbc-5.4.16-23.el7_0.3.x86_64.rpm php-pdo-5.4.16-23.el7_0.3.x86_64.rpm php-pgsql-5.4.16-23.el7_0.3.x86_64.rpm php-process-5.4.16-23.el7_0.3.x86_64.rpm php-recode-5.4.16-23.el7_0.3.x86_64.rpm php-soap-5.4.16-23.el7_0.3.x86_64.rpm php-xml-5.4.16-23.el7_0.3.x86_64.rpm php-xmlrpc-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: php-bcmath-5.4.16-23.el7_0.3.x86_64.rpm php-dba-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-devel-5.4.16-23.el7_0.3.x86_64.rpm php-embedded-5.4.16-23.el7_0.3.x86_64.rpm php-enchant-5.4.16-23.el7_0.3.x86_64.rpm php-fpm-5.4.16-23.el7_0.3.x86_64.rpm php-intl-5.4.16-23.el7_0.3.x86_64.rpm php-mbstring-5.4.16-23.el7_0.3.x86_64.rpm php-mysqlnd-5.4.16-23.el7_0.3.x86_64.rpm php-pspell-5.4.16-23.el7_0.3.x86_64.rpm php-snmp-5.4.16-23.el7_0.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2014-3668 https://access.redhat.com/security/cve/CVE-2014-3669 https://access.redhat.com/security/cve/CVE-2014-3670 https://access.redhat.com/security/cve/CVE-2014-3710 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFUUqXLXlSAg2UNWIIRArMhAJ9Ov3Q5W/uB3IphUA4NGVwiPVlLaQCeMrx9 swi9y8yPiOr52b6Lbq1+ym4=gO0B -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. .Essential PHP patch for Red Hat rectifies significant vulnerabilities to boost security and preserve system reliability.. PHP Security Update, Red Hat Advisory, Exploit Mitigation, Buffer Overflow, Remote Threats. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 30, 2014 Important Red Hat
172

Ubuntu 11.04: USN-1178-1 Critical: IcedTea-Web, OpenJDK 6 Threats

An attacker could discover a user's name or confuse a user into grantingunintended access to files.. =========================================================================Ubuntu Security Notice USN-1178-1 July 27, 2011 icedtea-web, openjdk-6, openjdk-6b18 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: An attacker could discover a user's name or confuse a user into granting unintended access to files. Software Description: - icedtea-web: An implementation of the Java Network Launching Protocol (JNLP) - openjdk-6: Open Source Java implementation - openjdk-6b18: Open Source Java implementation Details: Omair Majid discovered that an unsigned Web Start application or applet could determine the path to the cache directory used to store downloaded class and jar files by querying class loader properties. This could allow a remote attacker to discover a user's name and home directory path. (CVE-2011-2513) Omair Majid discovered that an unsigned Web Start application could manipulate the content of the security warning dialog message to show different file names in prompts. This could allow a remote attacker to confuse a user into granting access to a different file than they believe they are granting access to. This issue only affected Ubuntu 11.04. (CVE-2011-2514) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: icedtea-netx 1.1.1-0ubuntu1~11.04.1 icedtea-plugin 1.1.1-0ubuntu1~11.04.1 Ubuntu 10.10: icedtea6-plugin 6b20-1.9.9-0ubuntu1~10.10.2 Ubuntu 10.04 LTS: icedtea6-plugin 6b20-1.9.9-0ubuntu1~10.04.2 After a standard system update you need to restart any Java applications or applets to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1178-1 CVE-2011-2513, CVE-2011-2514 Package Information: https://launchpad.net/ubuntu/+source/icedtea-web/1.1.1-0ubuntu1~11.04.1 https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.9-0ubuntu1~10.10.2 https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.8-0ubuntu1~10.10.2+1.8.9 https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.9-0ubuntu1~10.04.2 https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.8-0ubuntu1~10.04.2+1.8.9 . Ubuntu Security Alert USN-1842-2 highlights severe vulnerabilities in openjdk-7 and icedtea-web that impact various Ubuntu versions.. IcedTea, OpenJDK, User Privacy, Security Threats. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 27, 2011 Critical Ubuntu
87

Debian DSA-2132-1 Critical: Xulrunner Remote Threats Update

Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-2132-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff December 11, 2010 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : xulrunner Vulnerability : several Problem type : remote Debian-specific: no CVE Id(s) : CVE-2010-3776 CVE-2010-3778 CVE-2010-3769 CVE-2010-3771 CVE-2010-3772 CVE-2010-3775 CVE-2010-3767 CVE-2010-3773 CVE-2010-3770 Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems: For the stable distribution (lenny), these problems have been fixed in version 1.9.0.19-7. For the upcoming stable version (squeeze) and the unstable distribution (sid), these problems have been fixed in version 3.5.15-1. For the experimental distribution, these problems have been fixed in version 3.6.13-1. We recommend that you upgrade your xulrunner packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc,s390 and sparc. Source archives: Size/MD5 checksum: 2395 644970f97799b0cedf925a2c8303f2e8 Size/MD5 checksum: 192334 56a4a1a9b083b7cd92b29cd11a015e79 Size/MD5 checksum: 44174623 83667df1e46399960593fdd8832e958e Architecture independent packages: Size/MD5 checksum: 1468538 408e0dba665407318563c9ace335f887 alpha architecture (DEC Alpha) Size/MD5 checksum: 223280 178397115d1162385892d626fe792b24 Size/MD5 checksum: 9511894 7db4e68bf006563fc76e5d7ef7cc1f35 Size/MD5 checksum: 51220414 46e2eb53a8450dc6b09ab2c04e46c393 Size/MD5 checksum: 434238 8b7075f8a39aa75c39b119e0d3d135dc Size/MD5 checksum: 165054 5022695ffeb82bc7e38e229a578e586e Size/MD5 checksum: 72976 f7b15c4573ea75fe83fd6398f8a6b1d7 Size/MD5 checksum: 939744 19dd61fd1ad9d23add66faab4720c3c8 Size/MD5 checksum: 3658850 51980c9c9cf575d4af59a5e2033f6b1d Size/MD5 checksum: 113776 700edb5b7b4778ce0b43eeff702bf4ce amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 50471444 5c27a6ce1376234377e1327cece90e58 Size/MD5 checksum: 7736416 73c4297d3f7693eb75e1f52275968dd3 Size/MD5 checksum: 70642 62fa42480817a42b7c3186644e395adf Size/MD5 checksum: 3300092 de7c05ebe980974b7f677d691675346e Size/MD5 checksum: 153778 3095de264efc138f55a08932e5f633b2 Size/MD5 checksum: 375798 6076292260d0a0a21f426e205c2c8045 Size/MD5 checksum: 102292 3e2e5af63df8a9db1c898ef092edef7d Size/MD5 checksum: 891538 b5851f59bc3c61fe0ff6a85b870477da Size/MD5 checksum: 223652 45370096b9ad11d37126f9d4da5f2dfe arm architecture (ARM) Size/MD5 checksum: 84364 2b6ca89bc12cd2df1a1958638f2b6a19 Size/MD5 checksum: 352324 d1f0a3422bbbbfdb05a68c703b333b7b Size/MD5 checksum: 818192 9631161a7acb39824b0d40270f2f828d Size/MD5 checksum: 224266 8f229b45f02deaf66d3c1ccacc125909 Size/MD5 checksum: 3588414 b6de490be37c35b6a7201002a5dcd660 Size/MD5 checksum: 6818158ee9b933d0563218819922119bc39dec1 Size/MD5 checksum: 49413206 1229357e1cb60d5db4261aa39e890fd6 Size/MD5 checksum: 68732 8494bbd0306c67349fcda88b503d450d Size/MD5 checksum: 141954 483ea1908eca504f242bed3291765ef4 armel architecture (ARM EABI) Size/MD5 checksum: 85036 d3335128ed334f3213ccd984c58f5f69 Size/MD5 checksum: 354000 d166273acc1e23dd740c39141e3fb4f8 Size/MD5 checksum: 222498 c08938473e4ef23df0d40c297b20e2bb Size/MD5 checksum: 71090 69ce3831870708d27267013ae8c80340 Size/MD5 checksum: 3574582 7955f9e31c6b183cfc68d239d1704fb0 Size/MD5 checksum: 50257234 7600317a37eb2a9c37ccf80da8bf4e14 Size/MD5 checksum: 6965756 075c79fa64ec01ebe4f1160a03292c48 Size/MD5 checksum: 142408 9f293b106d5016f8c11528e28d25a5ff Size/MD5 checksum: 823738 95d47a4f7a80ceb3ad22b7bc9bc81955 hppa architecture (HP PA RISC) Size/MD5 checksum: 900154 c6770f86eed7c45d9c33c925dfdc94d8 Size/MD5 checksum: 9529646 009b61d895b622466d5da74c3a932139 Size/MD5 checksum: 158980 3974546696e1141d708f70d31a25aaae Size/MD5 checksum: 3636260 aa6c114be84f87b7f7e4c7fe8c9bac87 Size/MD5 checksum: 413824 fc7626c9d32c4b04f72db0ed20ed248f Size/MD5 checksum: 72504 7553c6e4706eb91e04195a53ed0e72e7 Size/MD5 checksum: 107220 f4131ea49f0b186e669348a147256e88 Size/MD5 checksum: 223844 bdbac51475d12a6d7b815f36e4b5a7f6 Size/MD5 checksum: 51362540 f304719b21b97c096eb3daa8c40fa250 i386 architecture (Intel ia32) Size/MD5 checksum: 352304 7bf93a593725507866080e137954d6ce Size/MD5 checksum: 3577326 00cc9e0a3ae8a399d02724a3a30f05fe Size/MD5 checksum: 143220 f5a60e3795974cbcd96a8617a70a005e Size/MD5 checksum: 6616834 a69896146e791431fdd263d992d0a3fb Size/MD5 checksum: 49624400 772fd8eadf485efaec614d2aebde2759 Size/MD5 checksum: 852782 2e36eb0fbe5599aa30f85300c9ec7989 Size/MD5 checksum: 79838 516419904db720a7b8ce729db0771a2c Size/MD5 checksum: 224708df850c028a186cfead37b22d2bcdfcf8 Size/MD5 checksum: 69212 a34d57b0412813c2c435292b1a9d09d6 ia64 architecture (Intel ia64) Size/MD5 checksum: 77072 a5f3093605c728fcae801ec4a6a34fe8 Size/MD5 checksum: 811894 939a9193369d070f387ced4c3fa29618 Size/MD5 checksum: 223648 00ac511ec1f3922a1b20da88458c95a3 Size/MD5 checksum: 122012 a9c9fc88c16c919f4f0fd934797dfc57 Size/MD5 checksum: 11324750 4270a6d5f04f4bde1861d2c11e6a1d4b Size/MD5 checksum: 3403204 92244edd7fa45fc2f8eefa7148ed94ba Size/MD5 checksum: 180730 247a57cac4033af253b2f0ac66ce10d8 Size/MD5 checksum: 543054 7088c92cd15a9f21a3735f9a14641da3 Size/MD5 checksum: 49815268 5d41fce562553f411e23ad8da9af991c mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 97596 aae76aafb1643a3e6892f35ff928acea Size/MD5 checksum: 223870 a7922622373346e883ab5e0c8f012781 Size/MD5 checksum: 381098 b5f4975be234777fa92e8f0047b93091 Size/MD5 checksum: 7680280 32b008f0bdfbc9082e02ef3d6e16e86a Size/MD5 checksum: 70542 f1440f582f5e83367e0a2e757c1429c2 Size/MD5 checksum: 145450 6dcca30b995c0ad7cef8dcf8bb6a3ba5 Size/MD5 checksum: 51981382 74d3bc5b26d0c6da3cef8506e56000b5 Size/MD5 checksum: 3612158 f7565161666d9155be2dafd6a5066d7b Size/MD5 checksum: 917662 90b6acdf9fb6b104b4387b8489e3f14d mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 97274 8932be2e001cab62cf2536b2ccc49160 Size/MD5 checksum: 901536 a992d95b5fa5d61f51d0bf80f9708b01 Size/MD5 checksum: 223648 a9200d880d63ac9f11e4e5142da504c3 Size/MD5 checksum: 70434 c116043e0d1b3ca1aed17fab4e8b7074 Size/MD5 checksum: 7391960 29f18c6167a22dddbf66dd734e763d7b Size/MD5 checksum: 379632 235a73f45e044901c03c9a0ba5bfd3ff Size/MD5 checksum: 145568 e15bbc03233b75b85120113551314247 Size/MD5 checksum: 50093512 f8b364eb399f9e3fa0dd700403fe7e27 Size/MD5 checksum: 3313754 568d31e6a1c83803f91ab8e7f8b21469 powerpcarchitecture (PowerPC) Size/MD5 checksum: 95296 1f03682ec71fcc352a5f8c48647a451d Size/MD5 checksum: 73584 06a80a5c288d5342a48655795849e0e6 Size/MD5 checksum: 888614 068e2fd4f17719fd9c3774f85737f3da Size/MD5 checksum: 152724 cfbb558bb75ed6615972c784acbb677d Size/MD5 checksum: 51526180 998b07a9dd6944ac545a4b8f8244c309 Size/MD5 checksum: 223660 3fe5463aa6eff01330ee13ced216d9d0 Size/MD5 checksum: 363274 0f80c4936242ccb79f2974be9b689bba Size/MD5 checksum: 3288188 3858b9e6e97cf9b549acdb425d94b538 Size/MD5 checksum: 7292448 b3a02b207d499a2909177e7dc629b8d6 s390 architecture (IBM S/390) Size/MD5 checksum: 223456 c0552ce6b2d73639db458f2739f4583b Size/MD5 checksum: 909980 04e9a175fae9182dae6ed3f7a71fe44e Size/MD5 checksum: 73756 357e968a6a23757c80d6eea737f76cbc Size/MD5 checksum: 8433674 a64377c8a4741bd8761d61999c427c7a Size/MD5 checksum: 105980 089cac8b869c1a02db977eb919f919a3 Size/MD5 checksum: 51298252 af8eabc6439a5e4086ecdcd0412d3322 Size/MD5 checksum: 407998 0028994a489adeea5e48192b8a6ae91f Size/MD5 checksum: 155662 08437d3d7bad0a64625ffb7552e6fe44 Size/MD5 checksum: 3612610 62f361699599d1200db324a9144d2877 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 223486 37a29eaab1a2c534f5dc62f44b0a4236 Size/MD5 checksum: 144326 20c0f34db6494765a13656eac739619c Size/MD5 checksum: 3587652 e3d2bc88b9050c27c8bf0399a6f52dbe Size/MD5 checksum: 822702 625feb71bd53859a40d0b4f75dce9292 Size/MD5 checksum: 350920 668c1ccfd704b50e327857bc27086810 Size/MD5 checksum: 49490890 71a88412f9ba2817e5d6a405162a378d Size/MD5 checksum: 70432 458f8b7f98a0d4cac45161c65d40a8b0 Size/MD5 checksum: 7185870 c8ad3b10261488a4026c54128154d726 Size/MD5 checksum: 84790 b9d86d92952c65d8a8249f39a3c6af41 These files will probably be moved into the stable distribution on its next update. ---------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Caution Notification DSA-3210-2 issued for Ubuntu; upgrade firefox to address severe network vulnerabilities immediately.. debian security advisory,xulrunner update,remote threat fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 11, 2010 Critical Debian
87

Debian: DSA-2038-2 Moderate: Remote Vulnerabilities in Pidgin

The packages for Pidgin released as DSA 2038-1 had a regression, as they unintentionally disabled the Zephyr instant messaging protocol. This update restores Zephyr functionality. For reference the original advisory text below. . - ------------------------------------------------------------------------ Debian Security Advisory DSA-2038-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst May 17, 2010 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : pidgin Vulnerability : several Problem type : remote Debian-specific: no CVE Id(s) : CVE-2010-0420 CVE-2010-0423 Debian Bug : 566775 579601 The packages for Pidgin released as DSA 2038-1 had a regression, as they unintentionally disabled the Zephyr instant messaging protocol. This update restores Zephyr functionality. For reference the original advisory text below. Several remote vulnerabilities have been discovered in Pidgin, a multi protocol instant messaging client. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-0420 Crafted nicknames in the XMPP protocol can crash Pidgin remotely. CVE-2010-0423 Remote contacts may send too many custom smilies, crashing Pidgin. Since a few months, Microsoft's servers for MSN have changed the protocol, making Pidgin non-functional for use with MSN. It is not feasible to port these changes to the version of Pidgin in Debian Lenny. This update formalises that situation by disabling the protocol in the client. Usersof the MSN protocol are advised to use the version of Pidgin in the repositories of https://backports.debian.org/. For the stable distribution (lenny), these problems have been fixed in version 2.4.3-4lenny7. For the unstable distribution (sid), these problems have been fixed in version 2.6.6-1. We recommend that you upgrade your pidgin package. Upgrade instructions --------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Source archives: Size/MD5 checksum: 13123610 d0e0bd218fbc67df8b2eca2f21fcd427 Size/MD5 checksum: 72195 fe0a9dd9d55d642dc77c4f7c678522c8 Size/MD5 checksum: 1784 300f72738867fcd326db7f836ac47d67 Architecture independent packages: Size/MD5 checksum: 7019174 3d1e4508e5543441a5d04a31f03b0979 Size/MD5 checksum: 193842 b2c75fc6891adad16add69903ce9762d Size/MD5 checksum: 159766 5bb66c4efe6c67eeb33297738799a831 Size/MD5 checksum: 133930 c25806d1d9a07c49c5a3b2fd0b83964c Size/MD5 checksum: 277224 c169cf3a82bb6a0faf1d285a7377b695 alpha architecture (DEC Alpha) Size/MD5 checksum: 1501864 9aa23188e1610834d035e88fd30308b8 Size/MD5 checksum: 369772 a8eb912226cf47f5f74892f0b1110cc4 Size/MD5 checksum: 776646 bf0f80658559ab3e4c22356dd47d809d Size/MD5 checksum: 4989752 30e054746fff6d56a9e3b288039ff6c9 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 727950 57554918978a95ea250a8494c9aab433 Size/MD5 checksum: 1429960 2779007da91fe74a1304f3263cd7d53e Size/MD5 checksum: 348100 d01043df40ed1861c63043b44289984d Size/MD5 checksum: 5101892 af2ea1456eb390f3930e6164108a9c7f arm architecture (ARM) Size/MD5 checksum: 316624 290e5d8fa14bcc09dde3ce6d326d84bd Size/MD5 checksum: 657416 1997d30109a1c86c6c8979ff2e0511ee Size/MD5 checksum: 4835872 9f2aaef6679c3b2e27a73240799a7ffa Size/MD5 checksum: 1239516 640fd3ff6c91ac45820581df86965af8 armel architecture (ARM EABI) Size/MD5checksum: 668000 b0bc286a8e2d74a033ac69b5ed234e6e Size/MD5 checksum: 1243880 88c529b8e9178969c3a3a13e1a8e3230 Size/MD5 checksum: 319962 72d956d2c3b6b04dc0aed07e6d99e944 Size/MD5 checksum: 4851712 6134571c92b5495489555c01fc4a6d51 hppa architecture (HP PA RISC) Size/MD5 checksum: 1522820 023def8c7a3051e1d15030347c99e99d Size/MD5 checksum: 752858 43129b10ef60136293b349614a662972 Size/MD5 checksum: 4943738 9cc7aee5d06445b07cceb81efa3ba30d Size/MD5 checksum: 360748 353f5caf6903c89a3bdd482dd6a520e6 i386 architecture (Intel ia32) Size/MD5 checksum: 681390 82c10195fb937a47a113940fa93dbdb5 Size/MD5 checksum: 4837960 416ddcf7b18e7b2a474fa56731a93f7b Size/MD5 checksum: 326994 06bb2fefdc9ea9dce38a5481f33dcdf5 Size/MD5 checksum: 1317496 9218b0b46b8716781d80133e77194170 ia64 architecture (Intel ia64) Size/MD5 checksum: 1821990 87c03b5c08d97b8c8ae2a573ecd3cecb Size/MD5 checksum: 435010 22dee93a1714c2654ec0dfaa8705cfe2 Size/MD5 checksum: 4706272 6e0b0c3291dceb229522e1de229e3361 Size/MD5 checksum: 948766 ddf4cff0ac25735e5d18edcbeb970bf4 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 1117676 eb4a88cc934233faafebdcebc1171bc3 Size/MD5 checksum: 319576 4ad4d7a878a0d5daaff189da549c4638 Size/MD5 checksum: 5087780 9ebfc36f1749b61ab7a4fe70d0770f88 Size/MD5 checksum: 654936 d63bd6a67138596ef85b7a3259fceee7 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 4999390 ad6121a42731cb360d76b6fe67180924 Size/MD5 checksum: 318598 8b0b8f40209b828098f6ed000c517f65 Size/MD5 checksum: 1108760 4e9f79966b7fa0df677a1a5952488e62 Size/MD5 checksum: 651474 7b24d4210caaf4d27b9b3863393bffd6 powerpc architecture (PowerPC) Size/MD5 checksum: 1470622 c51b3531cc31005e58feac25f8606bd3 Size/MD5 checksum: 5052846 986c8a8ac0ccd3399393bceda957656f Size/MD5 checksum: 362770 f00c1a33b3598333dfc4ae9d61bf1d83 Size/MD5 checksum: 755104ae81b0387a32b162fb30ac425dc4ad43 s390 architecture (IBM S/390) Size/MD5 checksum: 5014182 c093e4c7e6e3b6132a8145a35e88c3fb Size/MD5 checksum: 359260 919eb5ad29cb280d84ef36b2c45273b9 Size/MD5 checksum: 1351418 a94314c09692e3a9350b8bd1684843bc Size/MD5 checksum: 718026 52121ab6cf237545c29f10826b98894b sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 4639296 f38822c989d40d124d82abc53ae42d38 Size/MD5 checksum: 328662 f5fe4eb9c81b2aa8d335b983288902dd Size/MD5 checksum: 683246 d37d198e8bb1d5c3f98521dcc0a43c24 Size/MD5 checksum: 1323820 54026420c5be2e153e7a8ffbcb70b5cd These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Ubuntu notice UBA-7894-1 addresses issues in Pidgin builds reinstating Zephyr operations and mitigating security vulnerabilities.. Debian Security Update, Pidgin Patch, Remote Threats, Zephyr Restore. . LinuxSecurity.com Team

Calendar%202 May 17, 2010 Debian
98

Red Hat Enterprise Linux: RHSA-2009-0341-01 Moderate: Curl File Access Risk

Updated curl packages that fix a security issue are now available for Red Hat Enterprise Linux 2.1, 3, 4, and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: curl security update Advisory ID: RHSA-2009:0341-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:0341.html Issue date: 2009-03-19 CVE Names: CVE-2009-0037 ==================================================================== 1. Summary: Updated curl packages that fix a security issue are now available for Red Hat Enterprise Linux 2.1, 3, 4, and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Linux Advanced Workstation 2.1 - ia64 3. Description: cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict servers, using any of the supported protocols. cURL is designed to work without userinteraction or any kind of interactivity. David Kierznowski discovered a flaw in libcurl where it would not differentiate between different target URLs when handling automatic redirects. This caused libcurl to follow any new URL that it understood, including the "file://" URL type. This could allow a remote server to force a local libcurl-using application to read a local file instead of the remote one, possibly exposing local files that were not meant to be exposed. (CVE-2009-0037) Note: Applications using libcurl that are expected to follow redirects to "file://" protocol must now explicitly call curl_easy_setopt(3) and set the newly introduced CURLOPT_REDIR_PROTOCOLS option as required. cURL users should upgrade to these updated packages, which contain backported patches to correct these issues. All running applications using libcurl must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 485271 - CVE-2009-0037 curl: local file access via unsafe redirects 6. Package List: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 : Source: i386: curl-7.8-3.rhel2.i386.rpm curl-devel-7.8-3.rhel2.i386.rpm ia64: curl-7.8-3.rhel2.ia64.rpm curl-devel-7.8-3.rhel2.ia64.rpm Red Hat Linux Advanced Workstation 2.1: Source: ia64: curl-7.8-3.rhel2.ia64.rpm curl-devel-7.8-3.rhel2.ia64.rpm Red Hat Enterprise Linux ES version 2.1: Source: i386: curl-7.8-3.rhel2.i386.rpm curl-devel-7.8-3.rhel2.i386.rpm Red Hat Enterprise Linux WS version 2.1: Source: i386: curl-7.8-3.rhel2.i386.rpm curl-devel-7.8-3.rhel2.i386.rpm Red Hat Enterprise Linux AS version3: Source: i386: curl-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-devel-7.10.6-9.rhel3.i386.rpm ia64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.ia64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.ia64.rpm curl-devel-7.10.6-9.rhel3.ia64.rpm ppc: curl-7.10.6-9.rhel3.ppc.rpm curl-7.10.6-9.rhel3.ppc64.rpm curl-debuginfo-7.10.6-9.rhel3.ppc.rpm curl-debuginfo-7.10.6-9.rhel3.ppc64.rpm curl-devel-7.10.6-9.rhel3.ppc.rpm s390: curl-7.10.6-9.rhel3.s390.rpm curl-debuginfo-7.10.6-9.rhel3.s390.rpm curl-devel-7.10.6-9.rhel3.s390.rpm s390x: curl-7.10.6-9.rhel3.s390.rpm curl-7.10.6-9.rhel3.s390x.rpm curl-debuginfo-7.10.6-9.rhel3.s390.rpm curl-debuginfo-7.10.6-9.rhel3.s390x.rpm curl-devel-7.10.6-9.rhel3.s390x.rpm x86_64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.x86_64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.x86_64.rpm curl-devel-7.10.6-9.rhel3.x86_64.rpm Red Hat Desktop version 3: Source: i386: curl-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-devel-7.10.6-9.rhel3.i386.rpm x86_64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.x86_64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.x86_64.rpm curl-devel-7.10.6-9.rhel3.x86_64.rpm Red Hat Enterprise Linux ES version 3: Source: i386: curl-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-devel-7.10.6-9.rhel3.i386.rpm ia64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.ia64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.ia64.rpm curl-devel-7.10.6-9.rhel3.ia64.rpm x86_64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.x86_64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.x86_64.rpm curl-devel-7.10.6-9.rhel3.x86_64.rpm Red Hat Enterprise Linux WS version3: Source: i386: curl-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-devel-7.10.6-9.rhel3.i386.rpm ia64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.ia64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.ia64.rpm curl-devel-7.10.6-9.rhel3.ia64.rpm x86_64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.x86_64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.x86_64.rpm curl-devel-7.10.6-9.rhel3.x86_64.rpm Red Hat Enterprise Linux AS version 4: Source: i386: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-devel-7.12.1-11.1.el4_7.1.i386.rpm ia64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.ia64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ia64.rpm curl-devel-7.12.1-11.1.el4_7.1.ia64.rpm ppc: curl-7.12.1-11.1.el4_7.1.ppc.rpm curl-7.12.1-11.1.el4_7.1.ppc64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ppc.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ppc64.rpm curl-devel-7.12.1-11.1.el4_7.1.ppc.rpm s390: curl-7.12.1-11.1.el4_7.1.s390.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.s390.rpm curl-devel-7.12.1-11.1.el4_7.1.s390.rpm s390x: curl-7.12.1-11.1.el4_7.1.s390.rpm curl-7.12.1-11.1.el4_7.1.s390x.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.s390.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.s390x.rpm curl-devel-7.12.1-11.1.el4_7.1.s390x.rpm x86_64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.x86_64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.x86_64.rpm curl-devel-7.12.1-11.1.el4_7.1.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-devel-7.12.1-11.1.el4_7.1.i386.rpm x86_64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.x86_64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.x86_64.rpm curl-devel-7.12.1-11.1.el4_7.1.x86_64.rpm Red Hat Enterprise Linux ES version4: Source: i386: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-devel-7.12.1-11.1.el4_7.1.i386.rpm ia64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.ia64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ia64.rpm curl-devel-7.12.1-11.1.el4_7.1.ia64.rpm x86_64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.x86_64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.x86_64.rpm curl-devel-7.12.1-11.1.el4_7.1.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-devel-7.12.1-11.1.el4_7.1.i386.rpm ia64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.ia64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ia64.rpm curl-devel-7.12.1-11.1.el4_7.1.ia64.rpm x86_64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.x86_64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.x86_64.rpm curl-devel-7.12.1-11.1.el4_7.1.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: curl-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm x86_64: curl-7.15.5-2.1.el5_3.4.i386.rpm curl-7.15.5-2.1.el5_3.4.x86_64.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-devel-7.15.5-2.1.el5_3.4.i386.rpm x86_64: curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.x86_64.rpm curl-devel-7.15.5-2.1.el5_3.4.i386.rpm curl-devel-7.15.5-2.1.el5_3.4.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: curl-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-devel-7.15.5-2.1.el5_3.4.i386.rpm ia64: curl-7.15.5-2.1.el5_3.4.ia64.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.ia64.rpm curl-devel-7.15.5-2.1.el5_3.4.ia64.rpm ppc: curl-7.15.5-2.1.el5_3.4.ppc.rpm curl-7.15.5-2.1.el5_3.4.ppc64.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.ppc.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.ppc64.rpm curl-devel-7.15.5-2.1.el5_3.4.ppc.rpm curl-devel-7.15.5-2.1.el5_3.4.ppc64.rpm s390x: curl-7.15.5-2.1.el5_3.4.s390.rpm curl-7.15.5-2.1.el5_3.4.s390x.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.s390.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.s390x.rpm curl-devel-7.15.5-2.1.el5_3.4.s390.rpm curl-devel-7.15.5-2.1.el5_3.4.s390x.rpm x86_64: curl-7.15.5-2.1.el5_3.4.i386.rpm curl-7.15.5-2.1.el5_3.4.x86_64.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.x86_64.rpm curl-devel-7.15.5-2.1.el5_3.4.i386.rpm curl-devel-7.15.5-2.1.el5_3.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-0037 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFJwm7vXlSAg2UNWIIRAroFAKCKDeunP0rbrBA4fvgQX+CS2i3rPACff22Y ILjVK6SGd0jni2ahCuMeuUk=BV0F -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian announces a critical patch addressing potential vulnerabilities in the SSH protocol affecting various server distributions.. curl update, Red Hat security, file access risk, Linux packages, moderate impact. . LinuxSecurity.com Team

Calendar%202 Mar 19, 2009 Red Hat
87

Debian: DSA-1534-2 Critical: Iceape Remote Threat Resolved

Several remote vulnerabilities have been discovered in the Iceape internet suite, an unbranded version of the Seamonkey Internet Suite. The Common Vulnerabilities and Exposures project identifies the following problems:. - ------------------------------------------------------------------------Debian Security Advisory DSA-1534-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff April 24, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : iceape Vulnerability : several Problem-Type : remote Debian-specific: no CVE ID : CVE-2007-4879 CVE-2008-1233 CVE-2008-1234 CVE-2008-1235 CVE-2008-1236 CVE-2008-1237 CVE-2008-1238 CVE-2008-1240 CVE-2008-1241 A regression in mailnews handling has been fixed. For reference the original advisory text below: Several remote vulnerabilities have been discovered in the Iceape internet suite, an unbranded version of the Seamonkey Internet Suite. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-4879 Peter Brodersen and Alexander Klink discovered that the autoselection of SSL client certificates could lead to users being tracked, resulting in a loss of privacy. CVE-2008-1233 "moz_bug_r_a4" discovered that variants of CVE-2007-3738 and CVE-2007-5338 allow the execution of arbitrary code through XPCNativeWrapper. CVE-2008-1234 "moz_bug_r_a4" discovered that insecure handling of event handlers could lead to cross-site scripting. CVE-2008-1235 Boris Zbarsky, Johnny Stenback, and "moz_bug_r_a4" discovered that incorrect principal handling can lead to cross-site scripting and the execution of arbitrary code. CVE-2008-1236 Tom Ferris, Seth Spitzer, Martin Wargers, John Daggett and Mats Palmgren discovered crashes in the layout engine,which might allow the execution of arbitrary code. CVE-2008-1237 "georgi", "tgirmann" and Igor Bukanov discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. CVE-2008-1238 Gregory Fleischer discovered that HTTP Referrer headers were handled incorrectly in combination with URLs containing Basic Authentication credentials with empty usernames, resulting in potential Cross-Site Request Forgery attacks. CVE-2008-1240 Gregory Fleischer discovered that web content fetched through the jar: protocol can use Java to connect to arbitrary ports. This is only an issue in combination with the non-free Java plugin. CVE-2008-1241 Chris Thomas discovered that background tabs could generate XUL popups overlaying the current tab, resulting in potential spoofing attacks. For the stable distribution (etch), these problems have been fixed in version 1.0.13~pre080323b-0etch2. We recommend that you upgrade your iceape packages. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 4.0 (stable) - -------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 270431 fc94cccf043f45b5bd2f1ea2d6b9b225 Size/MD5 checksum: 1439 3a1c421b0d61223760b7724dcf7ff6d9 Size/MD5 checksum: 42900009 f2a3c50d814f6e7015f779b10494fac8 Architecture independent packages: Size/MD5 checksum: 28532 87c74c4e89522054101318d3a6aaaef9 Size/MD5checksum: 27594 5795424a813f6d765400d27852161904 Size/MD5 checksum: 27568 7b63ae9c6c56a43ae9db63e2f4c0ff85 Size/MD5 checksum: 27576 a3cb70fb2e4811959f447c35effd3dcc Size/MD5 checksum: 3928614 14cc24bbe9b509d69db0a20ccc1de079 Size/MD5 checksum: 27558 bde53046463a722d1831cb45a59bb3cf Size/MD5 checksum: 27560 62b1ef313aa14596c934a8121eb412c2 Size/MD5 checksum: 282312 6df637681e0a66b1bf68833b347b2124 Size/MD5 checksum: 28966 549dc26dd898c58013aeb624098d5db1 Size/MD5 checksum: 27582 9c5919265f60ed5ba60075bc9b5102dc Size/MD5 checksum: 27596 9aa97c6c5f94155ec3e8d36c2414fd1d Size/MD5 checksum: 27694 c2a812caa94a72724bb98ec8cfc93249 alpha architecture (DEC Alpha) Size/MD5 checksum: 12886108 2d9a38d95503842a3832aed859f0f80a Size/MD5 checksum: 2281642 791f3a80ebdb173c2f9d0ff152f976c9 Size/MD5 checksum: 627482 5729fa2e2f72dfa803e37a99b461417b Size/MD5 checksum: 54972 11524f4ed3875809260eac9a6c0325a0 Size/MD5 checksum: 60658744 e56cb39f56de70aaf7a201b0e13d309a Size/MD5 checksum: 199028 8d154e497acf9e7796390f2b1c1501dd amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 59663026 37829add13c621e391eb2c6c9e047ca7 Size/MD5 checksum: 2099876 895840b306a190900c44dc4088961c50 Size/MD5 checksum: 11692150 69a227342b3e5d563a716149eadfc7ca Size/MD5 checksum: 53740 d716f72d98622c3c97a679705426c2d5 Size/MD5 checksum: 195436 c5838a1fcb25f0588abed9da193c06ce Size/MD5 checksum: 614236 0483f95d4be4d1a5b359a3864bc466f4 arm architecture (ARM) Size/MD5 checksum: 586622 65a7a73dc018e2c1c77c26a412510e7d Size/MD5 checksum: 58798986 33ad7943133f5f00672dcdeaa245f057 Size/MD5 checksum: 10426214 24dbab44f5ab57bccd1a0bfbb0f17680 Size/MD5 checksum: 187090 57015ccb41fa214c46cd79b696d14198 Size/MD5 checksum: 47796 e0c6b965e643018af3abb27d41a01c38 Size/MD5 checksum: 191692236584dddf43f46a70412fe794991d07e hppa architecture (HP PA RISC) Size/MD5 checksum: 55158 0f80d4449589b0b77c8ef469ed9c2102 Size/MD5 checksum: 619606 4ac9462c322063202406f20eb08b6adb Size/MD5 checksum: 198562 7dcaaf89e91e427acefa886275f2606c Size/MD5 checksum: 12991842 40dbc4f08611a986d30c358b4c442cab Size/MD5 checksum: 2349778 0400cc18d7078e6a5c9d675cc5ec935d Size/MD5 checksum: 60520824 a501cd292183eb7a909cdc481302cc9d i386 architecture (Intel ia32) Size/MD5 checksum: 1891942 8b55f7fffc8dda99a78c8deb587b3601 Size/MD5 checksum: 48796 920f9ba79b92a527149a3f8e3ca9e80f Size/MD5 checksum: 58740626 87ac20b038ce496fe0dec8fc78f8fb66 Size/MD5 checksum: 190146 7d2da0e3a0a4291f5a78da36e4d91758 Size/MD5 checksum: 589368 c07d98219b6c237b4ecdc8cc24dde349 Size/MD5 checksum: 10480450 b302009b8337411c5b1cc59a394249a9 ia64 architecture (Intel ia64) Size/MD5 checksum: 62286 ae7ef14b5c6bc27032715154c3b830d1 Size/MD5 checksum: 205078 7ffa6a5b770b336fe224c9c659e22236 Size/MD5 checksum: 2817294 c1330dea34afd59505ba68496dfc9de0 Size/MD5 checksum: 59920064 1e9f504516f7e024e3aa7df03b7859c4 Size/MD5 checksum: 15794360 5a0009de6fe96fd8745b6d1da4f57512 Size/MD5 checksum: 662296 a147dba65a655f2ffc4bc2dba80d062a mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 11157426 2894d4aa411f541d24321e7cfc8c40dc Size/MD5 checksum: 1959586 8245d1d89e210dc64822059177c60935 Size/MD5 checksum: 191382 993aa97774959191af28842e469ee122 Size/MD5 checksum: 50272 71182383f85762af687451ac3ef38824 Size/MD5 checksum: 599816 32d92af3b4068d460b27aea4a2941ef5 Size/MD5 checksum: 61513408 ddaa38162de39210cf0372b66d277afd mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 10910758 dc4b71d0b3b3877411f1d6434152ae60 Size/MD5 checksum: 191610 9829f7d8bf6d3057b575f44f2e42d7ba Size/MD5 checksum: 5963521fbd24b1af0f0a8f09fa6caabd05f9d1 Size/MD5 checksum: 50114 5321e20192aba965da843116d5198a81 Size/MD5 checksum: 59864402 a591a34d73e69d6f8ba4985f7398cb60 Size/MD5 checksum: 1942674 7e8584f9c790ab330d760e0589a8a657 powerpc architecture (PowerPC) Size/MD5 checksum: 596578 8ca91ddc369b7c2ef83d0cd1596cd644 Size/MD5 checksum: 192394 87211ca1331a30d20a2c899ce647cfc2 Size/MD5 checksum: 49580 f483e34bfbe4f072ba48fe4467c6d9eb Size/MD5 checksum: 2006802 cd1f36cb35b56996ed18ccc2bce77769 Size/MD5 checksum: 61653704 d6a8402134109d8aa8d086f5a014e180 Size/MD5 checksum: 11310660 d7775c0b98494daec085df09bdbc87c8 s390 architecture (IBM S/390) Size/MD5 checksum: 197250 556af0df979862515c7a58f9b823cec7 Size/MD5 checksum: 54332 ef3f1234a167fa3056075501d4ab7ccb Size/MD5 checksum: 612090 5b6a56753f5a39caa9336a9dd5e6f67c Size/MD5 checksum: 2186154 c106802c2fbf29e99beb440ade898d06 Size/MD5 checksum: 60408796 7169c59d6b3ea8758e6ca752a44b537d Size/MD5 checksum: 12288118 e54834b616bba85af29add06b7c18be7 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 585692 caea96e57a9283b7978ad15fcc6a378c Size/MD5 checksum: 1896400 609528b7ee5eb3ca761853daf8a5f619 Size/MD5 checksum: 10659906 27159c6c7c281cbf50e8b6f8bcb9164a Size/MD5 checksum: 58546410 4d394093ea9de39766982f3047fd3f9b Size/MD5 checksum: 190044 f0a2981d7f48f1c8e3cec1fb9b9ec6ed Size/MD5 checksum: 48396 ad3f586fd1c9f3239fa1a587fcc1603e These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . - ------------------------------------------------------------------------Debian Security Advisory D. remote,vulnerabilities, iceape, internet, suite, unbranded, versi. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 24, 2008 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200