Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The package openssl before version 1.0.2.g-3 is vulnerable to multiple issues including but not limited to private key extraction, denial of service, arbitrary code execution, resource consumption and cross-protocol attacks leading to cipher text decryption. . Arch Linux Security Advisory ASA-201603-2 ======================================== Severity: High Date : 2016-03-07 CVE-ID : CVE-2016-0702 CVE-2016-0705 CVE-2016-0797 CVE-2016-0798 CVE-2016-0799 CVE-2016-0800 Package : openssl Type : multiple issues Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package openssl before version 1.0.2.g-3 is vulnerable to multiple issues including but not limited to private key extraction, denial of service, arbitrary code execution, resource consumption and cross-protocol attacks leading to cipher text decryption. Resolution ========= Upgrade to 1.0.2.g-3. # pacman -Syu "openssl> =1.0.2.g-3" The problems have been fixed upstream in version 1.0.2.g-3. Workaround ========= None. Description ========== - CVE-2016-0702 (private key extraction) A side-channel attack was found that makes use of cache-bank conflicts on the Intel Sandy-Bridge microarchitecture. An attacker who has the ability to control code in a thread running on the same hyper-threaded core as the victim's thread that is performing decryption, could use this flaw to recover RSA private keys. - CVE-2016-0705 (denial of service) A double-free flaw was found in the way OpenSSL parsed certain malformed DSA (Digital Signature Algorithm) private keys. An attacker could create specially crafted DSA private keys that, when processed by an application compiled against OpenSSL, could cause the application to crash. - CVE-2016-0797 (arbitrary code execution) An integer overflow flaw, leading to a NULL pointer dereference or a heap-based memory corruption, was found in the way some BIGNUM functions of OpenSSL were implemented. Applications that use these functionswith large untrusted input could crash or, potentially, execute arbitrary code. - CVE-2016-0798 (resource consumption) A memory leak flaw was found in the way OpenSSL performed SRP user database look-ups using the SRP_VBASE_get_by_user() function. A remote attacker connecting to certain SRP servers with an invalid user name could leak approximately 300 bytes of the server's memory per connection. - CVE-2016-0799 (denial of service) The fmtstr function in crypto/bio/b_print.c improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842. - CVE-2016-0800 (cross-protocol attack) A padding oracle flaw was found in the Secure Sockets Layer version 2.0 (SSLv2) protocol. An attacker can potentially use this flaw to decrypt RSA-encrypted cipher text from a connection using a newer SSL/TLS protocol version, allowing them to decrypt such connections. This cross-protocol attack is publicly referred to as DROWN. Impact ===== A remote attacker is able to use multiple issues to perform a denial of service attack, trigger a memory leak resulting in resource consumption, use a cross-protocol attack that is leading to cipher text decryption or possibly execute arbitrary code under certain circumstances. Furthermore a local attacker may be able to extract the RSA private key by running code in a thread that is running on the same hyper-threaded core as the victim's thread that is performingdecryption. References ========= https://openssl-library.org/news/secadv/20160301.txt https://access.redhat.com/security/cve/CVE-2016-0702 https://access.redhat.com/security/cve/CVE-2016-0705 https://access.redhat.com/security/cve/CVE-2016-0797 https://access.redhat.com/security/cve/CVE-2016-0798 https://access.redhat.com/security/cve/CVE-2016-0799 https://access.redhat.com/security/cve/CVE-2016-0800 . Critical vulnerabilities detected in the Arch Linux openssl package necessitate an urgent update to address potential security risks.. Arch Linux, OpenSSL Issues, Remote Attack, Security Risks. . LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for clamav ______________________________________________________________________________ Announcement ID: openSUSE-SU-2015:0285-1 Rating: important References: #915512 #916214 #916215 #916217 Cross-References: CVE-2014-9328 CVE-2015-1461 CVE-2015-1462 CVE-2015-1463 Affected Products: openSUSE 13.2 openSUSE 13.1 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: clamav was updated to version 0.98.6 that fixes bugs and several security issues: * bsc#916217, CVE-2015-1461: Remote attackers can have unspecified impact via Yoda's crypter or mew packer files. * bsc#916214, CVE-2015-1462: Unspecified impact via acrafted upx packer file. * bsc#916215, CVE-2015-1463: Remote attackers can cause a denial of service via a crafted petite packer file. * bsc#915512, CVE-2014-9328: heap out of bounds condition with crafted upack packer files. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2015-147=1 - openSUSE 13.1: zypper in -t patch openSUSE-2015-147=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (i586 x86_64): clamav-0.98.6-2.13.1 clamav-debuginfo-0.98.6-2.13.1 clamav-debugsource-0.98.6-2.13.1 - openSUSE 13.1 (i586 x86_64): clamav-0.98.6-30.1 clamav-debuginfo-0.98.6-30.1 clamav-debugsource-0.98.6-30.1 References: https://www.suse.com/security/cve/CVE-2014-9328.html https://www.suse.com/security/cve/CVE-2015-1461.html https://www.suse.com/security/cve/CVE-2015-1462.html https://www.suse.com/security/cve/CVE-2015-1463.html https://bugzilla.suse.com/show_bug.cgi?id=915512 https://bugzilla.suse.com/show_bug.cgi?id=916214 https://bugzilla.suse.com/show_bug.cgi?id=916215 https://bugzilla.suse.com/show_bug.cgi?id=916217 . This critical update report highlights various enhancements for clamav on openSUSE, safeguarding the system's security.. clamav security, software update, openSUSE patch. . Severity: Important. LinuxSecurity.com Team
Updated php packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: php security update Advisory ID: RHSA-2014:1767-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:1767.html Issue date: 2014-10-30 CVE Names: CVE-2014-3668 CVE-2014-3669 CVE-2014-3670 CVE-2014-3710 ==================================================================== 1. Summary: Updated php packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v.7) - x86_64 3. Description: PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. A buffer overflow flaw was found in the Exif extension. A specially crafted JPEG or TIFF file could cause a PHP application using the exif_thumbnail() function to crash or, possibly, execute arbitrary code with the privileges of the user running that PHP application. (CVE-2014-3670) An integer overflow flaw was found in the way custom objects were unserialized. Specially crafted input processed by the unserialize() function could cause a PHP application to crash. (CVE-2014-3669) An out-of-bounds read flaw was found in the way the File Information (fileinfo) extension parsed Executable and Linkable Format (ELF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted ELF file. (CVE-2014-3710) An out of bounds read flaw was found in the way the xmlrpc extension parsed dates in the ISO 8601 format. A specially crafted XML-RPC request or response could possibly cause a PHP application to crash. (CVE-2014-3668) The CVE-2014-3710 issue was discovered by Francisco Alonso of Red Hat Product Security. All php users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, the httpd daemon must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1154500 - CVE-2014-3669 php: integer overflow in unserialize() 1154502 - CVE-2014-3670 php: heap corruption issue in exif_thumbnail() 1154503 - CVE-2014-3668 php: xmlrpc ISO8601 date format parsing out-of-bounds read in mkgmtime() 1155071 - CVE-2014-3710 file: out-of-bounds read in elfnote headers 6. Package List: Red Hat Enterprise Linux Desktop Optional (v.6): Source: php-5.3.3-40.el6_6.src.rpm i386: php-5.3.3-40.el6_6.i686.rpm php-bcmath-5.3.3-40.el6_6.i686.rpm php-cli-5.3.3-40.el6_6.i686.rpm php-common-5.3.3-40.el6_6.i686.rpm php-dba-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-devel-5.3.3-40.el6_6.i686.rpm php-embedded-5.3.3-40.el6_6.i686.rpm php-enchant-5.3.3-40.el6_6.i686.rpm php-fpm-5.3.3-40.el6_6.i686.rpm php-gd-5.3.3-40.el6_6.i686.rpm php-imap-5.3.3-40.el6_6.i686.rpm php-intl-5.3.3-40.el6_6.i686.rpm php-ldap-5.3.3-40.el6_6.i686.rpm php-mbstring-5.3.3-40.el6_6.i686.rpm php-mysql-5.3.3-40.el6_6.i686.rpm php-odbc-5.3.3-40.el6_6.i686.rpm php-pdo-5.3.3-40.el6_6.i686.rpm php-pgsql-5.3.3-40.el6_6.i686.rpm php-process-5.3.3-40.el6_6.i686.rpm php-pspell-5.3.3-40.el6_6.i686.rpm php-recode-5.3.3-40.el6_6.i686.rpm php-snmp-5.3.3-40.el6_6.i686.rpm php-soap-5.3.3-40.el6_6.i686.rpm php-tidy-5.3.3-40.el6_6.i686.rpm php-xml-5.3.3-40.el6_6.i686.rpm php-xmlrpc-5.3.3-40.el6_6.i686.rpm php-zts-5.3.3-40.el6_6.i686.rpm x86_64: php-5.3.3-40.el6_6.x86_64.rpm php-bcmath-5.3.3-40.el6_6.x86_64.rpm php-cli-5.3.3-40.el6_6.x86_64.rpm php-common-5.3.3-40.el6_6.x86_64.rpm php-dba-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-devel-5.3.3-40.el6_6.x86_64.rpm php-embedded-5.3.3-40.el6_6.x86_64.rpm php-enchant-5.3.3-40.el6_6.x86_64.rpm php-fpm-5.3.3-40.el6_6.x86_64.rpm php-gd-5.3.3-40.el6_6.x86_64.rpm php-imap-5.3.3-40.el6_6.x86_64.rpm php-intl-5.3.3-40.el6_6.x86_64.rpm php-ldap-5.3.3-40.el6_6.x86_64.rpm php-mbstring-5.3.3-40.el6_6.x86_64.rpm php-mysql-5.3.3-40.el6_6.x86_64.rpm php-odbc-5.3.3-40.el6_6.x86_64.rpm php-pdo-5.3.3-40.el6_6.x86_64.rpm php-pgsql-5.3.3-40.el6_6.x86_64.rpm php-process-5.3.3-40.el6_6.x86_64.rpm php-pspell-5.3.3-40.el6_6.x86_64.rpm php-recode-5.3.3-40.el6_6.x86_64.rpm php-snmp-5.3.3-40.el6_6.x86_64.rpm php-soap-5.3.3-40.el6_6.x86_64.rpm php-tidy-5.3.3-40.el6_6.x86_64.rpm php-xml-5.3.3-40.el6_6.x86_64.rpm php-xmlrpc-5.3.3-40.el6_6.x86_64.rpm php-zts-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux HPC Node (v.6): Source: php-5.3.3-40.el6_6.src.rpm x86_64: php-cli-5.3.3-40.el6_6.x86_64.rpm php-common-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): x86_64: php-5.3.3-40.el6_6.x86_64.rpm php-bcmath-5.3.3-40.el6_6.x86_64.rpm php-dba-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-devel-5.3.3-40.el6_6.x86_64.rpm php-embedded-5.3.3-40.el6_6.x86_64.rpm php-enchant-5.3.3-40.el6_6.x86_64.rpm php-fpm-5.3.3-40.el6_6.x86_64.rpm php-gd-5.3.3-40.el6_6.x86_64.rpm php-imap-5.3.3-40.el6_6.x86_64.rpm php-intl-5.3.3-40.el6_6.x86_64.rpm php-ldap-5.3.3-40.el6_6.x86_64.rpm php-mbstring-5.3.3-40.el6_6.x86_64.rpm php-mysql-5.3.3-40.el6_6.x86_64.rpm php-odbc-5.3.3-40.el6_6.x86_64.rpm php-pdo-5.3.3-40.el6_6.x86_64.rpm php-pgsql-5.3.3-40.el6_6.x86_64.rpm php-process-5.3.3-40.el6_6.x86_64.rpm php-pspell-5.3.3-40.el6_6.x86_64.rpm php-recode-5.3.3-40.el6_6.x86_64.rpm php-snmp-5.3.3-40.el6_6.x86_64.rpm php-soap-5.3.3-40.el6_6.x86_64.rpm php-tidy-5.3.3-40.el6_6.x86_64.rpm php-xml-5.3.3-40.el6_6.x86_64.rpm php-xmlrpc-5.3.3-40.el6_6.x86_64.rpm php-zts-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: php-5.3.3-40.el6_6.src.rpm i386: php-5.3.3-40.el6_6.i686.rpm php-cli-5.3.3-40.el6_6.i686.rpm php-common-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-gd-5.3.3-40.el6_6.i686.rpm php-ldap-5.3.3-40.el6_6.i686.rpm php-mysql-5.3.3-40.el6_6.i686.rpm php-odbc-5.3.3-40.el6_6.i686.rpm php-pdo-5.3.3-40.el6_6.i686.rpm php-pgsql-5.3.3-40.el6_6.i686.rpm php-soap-5.3.3-40.el6_6.i686.rpm php-xml-5.3.3-40.el6_6.i686.rpm php-xmlrpc-5.3.3-40.el6_6.i686.rpm ppc64: php-5.3.3-40.el6_6.ppc64.rpm php-cli-5.3.3-40.el6_6.ppc64.rpm php-common-5.3.3-40.el6_6.ppc64.rpm php-debuginfo-5.3.3-40.el6_6.ppc64.rpm php-gd-5.3.3-40.el6_6.ppc64.rpm php-ldap-5.3.3-40.el6_6.ppc64.rpm php-mysql-5.3.3-40.el6_6.ppc64.rpm php-odbc-5.3.3-40.el6_6.ppc64.rpm php-pdo-5.3.3-40.el6_6.ppc64.rpm php-pgsql-5.3.3-40.el6_6.ppc64.rpm php-soap-5.3.3-40.el6_6.ppc64.rpm php-xml-5.3.3-40.el6_6.ppc64.rpm php-xmlrpc-5.3.3-40.el6_6.ppc64.rpm s390x: php-5.3.3-40.el6_6.s390x.rpm php-cli-5.3.3-40.el6_6.s390x.rpm php-common-5.3.3-40.el6_6.s390x.rpm php-debuginfo-5.3.3-40.el6_6.s390x.rpm php-gd-5.3.3-40.el6_6.s390x.rpm php-ldap-5.3.3-40.el6_6.s390x.rpm php-mysql-5.3.3-40.el6_6.s390x.rpm php-odbc-5.3.3-40.el6_6.s390x.rpm php-pdo-5.3.3-40.el6_6.s390x.rpm php-pgsql-5.3.3-40.el6_6.s390x.rpm php-soap-5.3.3-40.el6_6.s390x.rpm php-xml-5.3.3-40.el6_6.s390x.rpm php-xmlrpc-5.3.3-40.el6_6.s390x.rpm x86_64: php-5.3.3-40.el6_6.x86_64.rpm php-cli-5.3.3-40.el6_6.x86_64.rpm php-common-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-gd-5.3.3-40.el6_6.x86_64.rpm php-ldap-5.3.3-40.el6_6.x86_64.rpm php-mysql-5.3.3-40.el6_6.x86_64.rpm php-odbc-5.3.3-40.el6_6.x86_64.rpm php-pdo-5.3.3-40.el6_6.x86_64.rpm php-pgsql-5.3.3-40.el6_6.x86_64.rpm php-soap-5.3.3-40.el6_6.x86_64.rpm php-xml-5.3.3-40.el6_6.x86_64.rpm php-xmlrpc-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): i386: php-bcmath-5.3.3-40.el6_6.i686.rpm php-dba-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-devel-5.3.3-40.el6_6.i686.rpm php-embedded-5.3.3-40.el6_6.i686.rpm php-enchant-5.3.3-40.el6_6.i686.rpm php-fpm-5.3.3-40.el6_6.i686.rpm php-imap-5.3.3-40.el6_6.i686.rpm php-intl-5.3.3-40.el6_6.i686.rpm php-mbstring-5.3.3-40.el6_6.i686.rpm php-process-5.3.3-40.el6_6.i686.rpm php-pspell-5.3.3-40.el6_6.i686.rpm php-recode-5.3.3-40.el6_6.i686.rpm php-snmp-5.3.3-40.el6_6.i686.rpm php-tidy-5.3.3-40.el6_6.i686.rpm php-zts-5.3.3-40.el6_6.i686.rpm ppc64: php-bcmath-5.3.3-40.el6_6.ppc64.rpm php-dba-5.3.3-40.el6_6.ppc64.rpm php-debuginfo-5.3.3-40.el6_6.ppc64.rpm php-devel-5.3.3-40.el6_6.ppc64.rpm php-embedded-5.3.3-40.el6_6.ppc64.rpm php-enchant-5.3.3-40.el6_6.ppc64.rpm php-fpm-5.3.3-40.el6_6.ppc64.rpm php-imap-5.3.3-40.el6_6.ppc64.rpm php-intl-5.3.3-40.el6_6.ppc64.rpm php-mbstring-5.3.3-40.el6_6.ppc64.rpm php-process-5.3.3-40.el6_6.ppc64.rpm php-pspell-5.3.3-40.el6_6.ppc64.rpm php-recode-5.3.3-40.el6_6.ppc64.rpm php-snmp-5.3.3-40.el6_6.ppc64.rpm php-tidy-5.3.3-40.el6_6.ppc64.rpm php-zts-5.3.3-40.el6_6.ppc64.rpm s390x: php-bcmath-5.3.3-40.el6_6.s390x.rpm php-dba-5.3.3-40.el6_6.s390x.rpm php-debuginfo-5.3.3-40.el6_6.s390x.rpm php-devel-5.3.3-40.el6_6.s390x.rpm php-embedded-5.3.3-40.el6_6.s390x.rpm php-enchant-5.3.3-40.el6_6.s390x.rpm php-fpm-5.3.3-40.el6_6.s390x.rpm php-imap-5.3.3-40.el6_6.s390x.rpm php-intl-5.3.3-40.el6_6.s390x.rpm php-mbstring-5.3.3-40.el6_6.s390x.rpm php-process-5.3.3-40.el6_6.s390x.rpm php-pspell-5.3.3-40.el6_6.s390x.rpm php-recode-5.3.3-40.el6_6.s390x.rpm php-snmp-5.3.3-40.el6_6.s390x.rpm php-tidy-5.3.3-40.el6_6.s390x.rpm php-zts-5.3.3-40.el6_6.s390x.rpm x86_64: php-bcmath-5.3.3-40.el6_6.x86_64.rpm php-dba-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-devel-5.3.3-40.el6_6.x86_64.rpm php-embedded-5.3.3-40.el6_6.x86_64.rpm php-enchant-5.3.3-40.el6_6.x86_64.rpm php-fpm-5.3.3-40.el6_6.x86_64.rpm php-imap-5.3.3-40.el6_6.x86_64.rpm php-intl-5.3.3-40.el6_6.x86_64.rpm php-mbstring-5.3.3-40.el6_6.x86_64.rpm php-process-5.3.3-40.el6_6.x86_64.rpm php-pspell-5.3.3-40.el6_6.x86_64.rpm php-recode-5.3.3-40.el6_6.x86_64.rpm php-snmp-5.3.3-40.el6_6.x86_64.rpm php-tidy-5.3.3-40.el6_6.x86_64.rpm php-zts-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: php-5.3.3-40.el6_6.src.rpm i386: php-5.3.3-40.el6_6.i686.rpm php-cli-5.3.3-40.el6_6.i686.rpm php-common-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-gd-5.3.3-40.el6_6.i686.rpm php-ldap-5.3.3-40.el6_6.i686.rpm php-mysql-5.3.3-40.el6_6.i686.rpm php-odbc-5.3.3-40.el6_6.i686.rpm php-pdo-5.3.3-40.el6_6.i686.rpm php-pgsql-5.3.3-40.el6_6.i686.rpm php-soap-5.3.3-40.el6_6.i686.rpm php-xml-5.3.3-40.el6_6.i686.rpm php-xmlrpc-5.3.3-40.el6_6.i686.rpm x86_64: php-5.3.3-40.el6_6.x86_64.rpm php-cli-5.3.3-40.el6_6.x86_64.rpm php-common-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-gd-5.3.3-40.el6_6.x86_64.rpm php-ldap-5.3.3-40.el6_6.x86_64.rpm php-mysql-5.3.3-40.el6_6.x86_64.rpm php-odbc-5.3.3-40.el6_6.x86_64.rpm php-pdo-5.3.3-40.el6_6.x86_64.rpm php-pgsql-5.3.3-40.el6_6.x86_64.rpm php-soap-5.3.3-40.el6_6.x86_64.rpm php-xml-5.3.3-40.el6_6.x86_64.rpm php-xmlrpc-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.6): i386: php-bcmath-5.3.3-40.el6_6.i686.rpm php-dba-5.3.3-40.el6_6.i686.rpm php-debuginfo-5.3.3-40.el6_6.i686.rpm php-devel-5.3.3-40.el6_6.i686.rpm php-embedded-5.3.3-40.el6_6.i686.rpm php-enchant-5.3.3-40.el6_6.i686.rpm php-fpm-5.3.3-40.el6_6.i686.rpm php-imap-5.3.3-40.el6_6.i686.rpm php-intl-5.3.3-40.el6_6.i686.rpm php-mbstring-5.3.3-40.el6_6.i686.rpm php-process-5.3.3-40.el6_6.i686.rpm php-pspell-5.3.3-40.el6_6.i686.rpm php-recode-5.3.3-40.el6_6.i686.rpm php-snmp-5.3.3-40.el6_6.i686.rpm php-tidy-5.3.3-40.el6_6.i686.rpm php-zts-5.3.3-40.el6_6.i686.rpm x86_64: php-bcmath-5.3.3-40.el6_6.x86_64.rpm php-dba-5.3.3-40.el6_6.x86_64.rpm php-debuginfo-5.3.3-40.el6_6.x86_64.rpm php-devel-5.3.3-40.el6_6.x86_64.rpm php-embedded-5.3.3-40.el6_6.x86_64.rpm php-enchant-5.3.3-40.el6_6.x86_64.rpm php-fpm-5.3.3-40.el6_6.x86_64.rpm php-imap-5.3.3-40.el6_6.x86_64.rpm php-intl-5.3.3-40.el6_6.x86_64.rpm php-mbstring-5.3.3-40.el6_6.x86_64.rpm php-process-5.3.3-40.el6_6.x86_64.rpm php-pspell-5.3.3-40.el6_6.x86_64.rpm php-recode-5.3.3-40.el6_6.x86_64.rpm php-snmp-5.3.3-40.el6_6.x86_64.rpm php-tidy-5.3.3-40.el6_6.x86_64.rpm php-zts-5.3.3-40.el6_6.x86_64.rpm Red Hat Enterprise Linux Client Optional (v.7): Source: php-5.4.16-23.el7_0.3.src.rpm x86_64: php-5.4.16-23.el7_0.3.x86_64.rpm php-bcmath-5.4.16-23.el7_0.3.x86_64.rpm php-cli-5.4.16-23.el7_0.3.x86_64.rpm php-common-5.4.16-23.el7_0.3.x86_64.rpm php-dba-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-devel-5.4.16-23.el7_0.3.x86_64.rpm php-embedded-5.4.16-23.el7_0.3.x86_64.rpm php-enchant-5.4.16-23.el7_0.3.x86_64.rpm php-fpm-5.4.16-23.el7_0.3.x86_64.rpm php-gd-5.4.16-23.el7_0.3.x86_64.rpm php-intl-5.4.16-23.el7_0.3.x86_64.rpm php-ldap-5.4.16-23.el7_0.3.x86_64.rpm php-mbstring-5.4.16-23.el7_0.3.x86_64.rpm php-mysql-5.4.16-23.el7_0.3.x86_64.rpm php-mysqlnd-5.4.16-23.el7_0.3.x86_64.rpm php-odbc-5.4.16-23.el7_0.3.x86_64.rpm php-pdo-5.4.16-23.el7_0.3.x86_64.rpm php-pgsql-5.4.16-23.el7_0.3.x86_64.rpm php-process-5.4.16-23.el7_0.3.x86_64.rpm php-pspell-5.4.16-23.el7_0.3.x86_64.rpm php-recode-5.4.16-23.el7_0.3.x86_64.rpm php-snmp-5.4.16-23.el7_0.3.x86_64.rpm php-soap-5.4.16-23.el7_0.3.x86_64.rpm php-xml-5.4.16-23.el7_0.3.x86_64.rpm php-xmlrpc-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): Source: php-5.4.16-23.el7_0.3.src.rpm x86_64: php-5.4.16-23.el7_0.3.x86_64.rpm php-bcmath-5.4.16-23.el7_0.3.x86_64.rpm php-cli-5.4.16-23.el7_0.3.x86_64.rpm php-common-5.4.16-23.el7_0.3.x86_64.rpm php-dba-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-devel-5.4.16-23.el7_0.3.x86_64.rpm php-embedded-5.4.16-23.el7_0.3.x86_64.rpm php-enchant-5.4.16-23.el7_0.3.x86_64.rpm php-fpm-5.4.16-23.el7_0.3.x86_64.rpm php-gd-5.4.16-23.el7_0.3.x86_64.rpm php-intl-5.4.16-23.el7_0.3.x86_64.rpm php-ldap-5.4.16-23.el7_0.3.x86_64.rpm php-mbstring-5.4.16-23.el7_0.3.x86_64.rpm php-mysql-5.4.16-23.el7_0.3.x86_64.rpm php-mysqlnd-5.4.16-23.el7_0.3.x86_64.rpm php-odbc-5.4.16-23.el7_0.3.x86_64.rpm php-pdo-5.4.16-23.el7_0.3.x86_64.rpm php-pgsql-5.4.16-23.el7_0.3.x86_64.rpm php-process-5.4.16-23.el7_0.3.x86_64.rpm php-pspell-5.4.16-23.el7_0.3.x86_64.rpm php-recode-5.4.16-23.el7_0.3.x86_64.rpm php-snmp-5.4.16-23.el7_0.3.x86_64.rpm php-soap-5.4.16-23.el7_0.3.x86_64.rpm php-xml-5.4.16-23.el7_0.3.x86_64.rpm php-xmlrpc-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: php-5.4.16-23.el7_0.3.src.rpm ppc64: php-5.4.16-23.el7_0.3.ppc64.rpm php-cli-5.4.16-23.el7_0.3.ppc64.rpm php-common-5.4.16-23.el7_0.3.ppc64.rpm php-debuginfo-5.4.16-23.el7_0.3.ppc64.rpm php-gd-5.4.16-23.el7_0.3.ppc64.rpm php-ldap-5.4.16-23.el7_0.3.ppc64.rpm php-mysql-5.4.16-23.el7_0.3.ppc64.rpm php-odbc-5.4.16-23.el7_0.3.ppc64.rpm php-pdo-5.4.16-23.el7_0.3.ppc64.rpm php-pgsql-5.4.16-23.el7_0.3.ppc64.rpm php-process-5.4.16-23.el7_0.3.ppc64.rpm php-recode-5.4.16-23.el7_0.3.ppc64.rpm php-soap-5.4.16-23.el7_0.3.ppc64.rpm php-xml-5.4.16-23.el7_0.3.ppc64.rpm php-xmlrpc-5.4.16-23.el7_0.3.ppc64.rpm s390x: php-5.4.16-23.el7_0.3.s390x.rpm php-cli-5.4.16-23.el7_0.3.s390x.rpm php-common-5.4.16-23.el7_0.3.s390x.rpm php-debuginfo-5.4.16-23.el7_0.3.s390x.rpm php-gd-5.4.16-23.el7_0.3.s390x.rpm php-ldap-5.4.16-23.el7_0.3.s390x.rpm php-mysql-5.4.16-23.el7_0.3.s390x.rpm php-odbc-5.4.16-23.el7_0.3.s390x.rpm php-pdo-5.4.16-23.el7_0.3.s390x.rpm php-pgsql-5.4.16-23.el7_0.3.s390x.rpm php-process-5.4.16-23.el7_0.3.s390x.rpm php-recode-5.4.16-23.el7_0.3.s390x.rpm php-soap-5.4.16-23.el7_0.3.s390x.rpm php-xml-5.4.16-23.el7_0.3.s390x.rpm php-xmlrpc-5.4.16-23.el7_0.3.s390x.rpm x86_64: php-5.4.16-23.el7_0.3.x86_64.rpm php-cli-5.4.16-23.el7_0.3.x86_64.rpm php-common-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-gd-5.4.16-23.el7_0.3.x86_64.rpm php-ldap-5.4.16-23.el7_0.3.x86_64.rpm php-mysql-5.4.16-23.el7_0.3.x86_64.rpm php-odbc-5.4.16-23.el7_0.3.x86_64.rpm php-pdo-5.4.16-23.el7_0.3.x86_64.rpm php-pgsql-5.4.16-23.el7_0.3.x86_64.rpm php-process-5.4.16-23.el7_0.3.x86_64.rpm php-recode-5.4.16-23.el7_0.3.x86_64.rpm php-soap-5.4.16-23.el7_0.3.x86_64.rpm php-xml-5.4.16-23.el7_0.3.x86_64.rpm php-xmlrpc-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: php-bcmath-5.4.16-23.el7_0.3.ppc64.rpm php-dba-5.4.16-23.el7_0.3.ppc64.rpm php-debuginfo-5.4.16-23.el7_0.3.ppc64.rpm php-devel-5.4.16-23.el7_0.3.ppc64.rpm php-embedded-5.4.16-23.el7_0.3.ppc64.rpm php-enchant-5.4.16-23.el7_0.3.ppc64.rpm php-fpm-5.4.16-23.el7_0.3.ppc64.rpm php-intl-5.4.16-23.el7_0.3.ppc64.rpm php-mbstring-5.4.16-23.el7_0.3.ppc64.rpm php-mysqlnd-5.4.16-23.el7_0.3.ppc64.rpm php-pspell-5.4.16-23.el7_0.3.ppc64.rpm php-snmp-5.4.16-23.el7_0.3.ppc64.rpm s390x: php-bcmath-5.4.16-23.el7_0.3.s390x.rpm php-dba-5.4.16-23.el7_0.3.s390x.rpm php-debuginfo-5.4.16-23.el7_0.3.s390x.rpm php-devel-5.4.16-23.el7_0.3.s390x.rpm php-embedded-5.4.16-23.el7_0.3.s390x.rpm php-enchant-5.4.16-23.el7_0.3.s390x.rpm php-fpm-5.4.16-23.el7_0.3.s390x.rpm php-intl-5.4.16-23.el7_0.3.s390x.rpm php-mbstring-5.4.16-23.el7_0.3.s390x.rpm php-mysqlnd-5.4.16-23.el7_0.3.s390x.rpm php-pspell-5.4.16-23.el7_0.3.s390x.rpm php-snmp-5.4.16-23.el7_0.3.s390x.rpm x86_64: php-bcmath-5.4.16-23.el7_0.3.x86_64.rpm php-dba-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-devel-5.4.16-23.el7_0.3.x86_64.rpm php-embedded-5.4.16-23.el7_0.3.x86_64.rpm php-enchant-5.4.16-23.el7_0.3.x86_64.rpm php-fpm-5.4.16-23.el7_0.3.x86_64.rpm php-intl-5.4.16-23.el7_0.3.x86_64.rpm php-mbstring-5.4.16-23.el7_0.3.x86_64.rpm php-mysqlnd-5.4.16-23.el7_0.3.x86_64.rpm php-pspell-5.4.16-23.el7_0.3.x86_64.rpm php-snmp-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux Workstation (v.7): Source: php-5.4.16-23.el7_0.3.src.rpm x86_64: php-5.4.16-23.el7_0.3.x86_64.rpm php-cli-5.4.16-23.el7_0.3.x86_64.rpm php-common-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-gd-5.4.16-23.el7_0.3.x86_64.rpm php-ldap-5.4.16-23.el7_0.3.x86_64.rpm php-mysql-5.4.16-23.el7_0.3.x86_64.rpm php-odbc-5.4.16-23.el7_0.3.x86_64.rpm php-pdo-5.4.16-23.el7_0.3.x86_64.rpm php-pgsql-5.4.16-23.el7_0.3.x86_64.rpm php-process-5.4.16-23.el7_0.3.x86_64.rpm php-recode-5.4.16-23.el7_0.3.x86_64.rpm php-soap-5.4.16-23.el7_0.3.x86_64.rpm php-xml-5.4.16-23.el7_0.3.x86_64.rpm php-xmlrpc-5.4.16-23.el7_0.3.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: php-bcmath-5.4.16-23.el7_0.3.x86_64.rpm php-dba-5.4.16-23.el7_0.3.x86_64.rpm php-debuginfo-5.4.16-23.el7_0.3.x86_64.rpm php-devel-5.4.16-23.el7_0.3.x86_64.rpm php-embedded-5.4.16-23.el7_0.3.x86_64.rpm php-enchant-5.4.16-23.el7_0.3.x86_64.rpm php-fpm-5.4.16-23.el7_0.3.x86_64.rpm php-intl-5.4.16-23.el7_0.3.x86_64.rpm php-mbstring-5.4.16-23.el7_0.3.x86_64.rpm php-mysqlnd-5.4.16-23.el7_0.3.x86_64.rpm php-pspell-5.4.16-23.el7_0.3.x86_64.rpm php-snmp-5.4.16-23.el7_0.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2014-3668 https://access.redhat.com/security/cve/CVE-2014-3669 https://access.redhat.com/security/cve/CVE-2014-3670 https://access.redhat.com/security/cve/CVE-2014-3710 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFUUqXLXlSAg2UNWIIRArMhAJ9Ov3Q5W/uB3IphUA4NGVwiPVlLaQCeMrx9 swi9y8yPiOr52b6Lbq1+ym4=gO0B -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
An attacker could discover a user's name or confuse a user into grantingunintended access to files.. =========================================================================Ubuntu Security Notice USN-1178-1 July 27, 2011 icedtea-web, openjdk-6, openjdk-6b18 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: An attacker could discover a user's name or confuse a user into granting unintended access to files. Software Description: - icedtea-web: An implementation of the Java Network Launching Protocol (JNLP) - openjdk-6: Open Source Java implementation - openjdk-6b18: Open Source Java implementation Details: Omair Majid discovered that an unsigned Web Start application or applet could determine the path to the cache directory used to store downloaded class and jar files by querying class loader properties. This could allow a remote attacker to discover a user's name and home directory path. (CVE-2011-2513) Omair Majid discovered that an unsigned Web Start application could manipulate the content of the security warning dialog message to show different file names in prompts. This could allow a remote attacker to confuse a user into granting access to a different file than they believe they are granting access to. This issue only affected Ubuntu 11.04. (CVE-2011-2514) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: icedtea-netx 1.1.1-0ubuntu1~11.04.1 icedtea-plugin 1.1.1-0ubuntu1~11.04.1 Ubuntu 10.10: icedtea6-plugin 6b20-1.9.9-0ubuntu1~10.10.2 Ubuntu 10.04 LTS: icedtea6-plugin 6b20-1.9.9-0ubuntu1~10.04.2 After a standard system update you need to restart any Java applications or applets to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1178-1 CVE-2011-2513, CVE-2011-2514 Package Information: https://launchpad.net/ubuntu/+source/icedtea-web/1.1.1-0ubuntu1~11.04.1 https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.9-0ubuntu1~10.10.2 https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.8-0ubuntu1~10.10.2+1.8.9 https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.9-0ubuntu1~10.04.2 https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.8-0ubuntu1~10.04.2+1.8.9 . Ubuntu Security Alert USN-1842-2 highlights severe vulnerabilities in openjdk-7 and icedtea-web that impact various Ubuntu versions.. IcedTea, OpenJDK, User Privacy, Security Threats. . Severity: Critical. LinuxSecurity.com Team
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-2132-1
The packages for Pidgin released as DSA 2038-1 had a regression, as they unintentionally disabled the Zephyr instant messaging protocol. This update restores Zephyr functionality. For reference the original advisory text below. . - ------------------------------------------------------------------------ Debian Security Advisory DSA-2038-2
Updated curl packages that fix a security issue are now available for Red Hat Enterprise Linux 2.1, 3, 4, and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: curl security update Advisory ID: RHSA-2009:0341-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:0341.html Issue date: 2009-03-19 CVE Names: CVE-2009-0037 ==================================================================== 1. Summary: Updated curl packages that fix a security issue are now available for Red Hat Enterprise Linux 2.1, 3, 4, and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Linux Advanced Workstation 2.1 - ia64 3. Description: cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict servers, using any of the supported protocols. cURL is designed to work without userinteraction or any kind of interactivity. David Kierznowski discovered a flaw in libcurl where it would not differentiate between different target URLs when handling automatic redirects. This caused libcurl to follow any new URL that it understood, including the "file://" URL type. This could allow a remote server to force a local libcurl-using application to read a local file instead of the remote one, possibly exposing local files that were not meant to be exposed. (CVE-2009-0037) Note: Applications using libcurl that are expected to follow redirects to "file://" protocol must now explicitly call curl_easy_setopt(3) and set the newly introduced CURLOPT_REDIR_PROTOCOLS option as required. cURL users should upgrade to these updated packages, which contain backported patches to correct these issues. All running applications using libcurl must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 485271 - CVE-2009-0037 curl: local file access via unsafe redirects 6. Package List: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 : Source: i386: curl-7.8-3.rhel2.i386.rpm curl-devel-7.8-3.rhel2.i386.rpm ia64: curl-7.8-3.rhel2.ia64.rpm curl-devel-7.8-3.rhel2.ia64.rpm Red Hat Linux Advanced Workstation 2.1: Source: ia64: curl-7.8-3.rhel2.ia64.rpm curl-devel-7.8-3.rhel2.ia64.rpm Red Hat Enterprise Linux ES version 2.1: Source: i386: curl-7.8-3.rhel2.i386.rpm curl-devel-7.8-3.rhel2.i386.rpm Red Hat Enterprise Linux WS version 2.1: Source: i386: curl-7.8-3.rhel2.i386.rpm curl-devel-7.8-3.rhel2.i386.rpm Red Hat Enterprise Linux AS version3: Source: i386: curl-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-devel-7.10.6-9.rhel3.i386.rpm ia64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.ia64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.ia64.rpm curl-devel-7.10.6-9.rhel3.ia64.rpm ppc: curl-7.10.6-9.rhel3.ppc.rpm curl-7.10.6-9.rhel3.ppc64.rpm curl-debuginfo-7.10.6-9.rhel3.ppc.rpm curl-debuginfo-7.10.6-9.rhel3.ppc64.rpm curl-devel-7.10.6-9.rhel3.ppc.rpm s390: curl-7.10.6-9.rhel3.s390.rpm curl-debuginfo-7.10.6-9.rhel3.s390.rpm curl-devel-7.10.6-9.rhel3.s390.rpm s390x: curl-7.10.6-9.rhel3.s390.rpm curl-7.10.6-9.rhel3.s390x.rpm curl-debuginfo-7.10.6-9.rhel3.s390.rpm curl-debuginfo-7.10.6-9.rhel3.s390x.rpm curl-devel-7.10.6-9.rhel3.s390x.rpm x86_64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.x86_64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.x86_64.rpm curl-devel-7.10.6-9.rhel3.x86_64.rpm Red Hat Desktop version 3: Source: i386: curl-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-devel-7.10.6-9.rhel3.i386.rpm x86_64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.x86_64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.x86_64.rpm curl-devel-7.10.6-9.rhel3.x86_64.rpm Red Hat Enterprise Linux ES version 3: Source: i386: curl-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-devel-7.10.6-9.rhel3.i386.rpm ia64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.ia64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.ia64.rpm curl-devel-7.10.6-9.rhel3.ia64.rpm x86_64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.x86_64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.x86_64.rpm curl-devel-7.10.6-9.rhel3.x86_64.rpm Red Hat Enterprise Linux WS version3: Source: i386: curl-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-devel-7.10.6-9.rhel3.i386.rpm ia64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.ia64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.ia64.rpm curl-devel-7.10.6-9.rhel3.ia64.rpm x86_64: curl-7.10.6-9.rhel3.i386.rpm curl-7.10.6-9.rhel3.x86_64.rpm curl-debuginfo-7.10.6-9.rhel3.i386.rpm curl-debuginfo-7.10.6-9.rhel3.x86_64.rpm curl-devel-7.10.6-9.rhel3.x86_64.rpm Red Hat Enterprise Linux AS version 4: Source: i386: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-devel-7.12.1-11.1.el4_7.1.i386.rpm ia64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.ia64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ia64.rpm curl-devel-7.12.1-11.1.el4_7.1.ia64.rpm ppc: curl-7.12.1-11.1.el4_7.1.ppc.rpm curl-7.12.1-11.1.el4_7.1.ppc64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ppc.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ppc64.rpm curl-devel-7.12.1-11.1.el4_7.1.ppc.rpm s390: curl-7.12.1-11.1.el4_7.1.s390.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.s390.rpm curl-devel-7.12.1-11.1.el4_7.1.s390.rpm s390x: curl-7.12.1-11.1.el4_7.1.s390.rpm curl-7.12.1-11.1.el4_7.1.s390x.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.s390.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.s390x.rpm curl-devel-7.12.1-11.1.el4_7.1.s390x.rpm x86_64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.x86_64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.x86_64.rpm curl-devel-7.12.1-11.1.el4_7.1.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-devel-7.12.1-11.1.el4_7.1.i386.rpm x86_64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.x86_64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.x86_64.rpm curl-devel-7.12.1-11.1.el4_7.1.x86_64.rpm Red Hat Enterprise Linux ES version4: Source: i386: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-devel-7.12.1-11.1.el4_7.1.i386.rpm ia64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.ia64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ia64.rpm curl-devel-7.12.1-11.1.el4_7.1.ia64.rpm x86_64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.x86_64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.x86_64.rpm curl-devel-7.12.1-11.1.el4_7.1.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-devel-7.12.1-11.1.el4_7.1.i386.rpm ia64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.ia64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.ia64.rpm curl-devel-7.12.1-11.1.el4_7.1.ia64.rpm x86_64: curl-7.12.1-11.1.el4_7.1.i386.rpm curl-7.12.1-11.1.el4_7.1.x86_64.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.i386.rpm curl-debuginfo-7.12.1-11.1.el4_7.1.x86_64.rpm curl-devel-7.12.1-11.1.el4_7.1.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: curl-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm x86_64: curl-7.15.5-2.1.el5_3.4.i386.rpm curl-7.15.5-2.1.el5_3.4.x86_64.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-devel-7.15.5-2.1.el5_3.4.i386.rpm x86_64: curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.x86_64.rpm curl-devel-7.15.5-2.1.el5_3.4.i386.rpm curl-devel-7.15.5-2.1.el5_3.4.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: curl-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-devel-7.15.5-2.1.el5_3.4.i386.rpm ia64: curl-7.15.5-2.1.el5_3.4.ia64.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.ia64.rpm curl-devel-7.15.5-2.1.el5_3.4.ia64.rpm ppc: curl-7.15.5-2.1.el5_3.4.ppc.rpm curl-7.15.5-2.1.el5_3.4.ppc64.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.ppc.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.ppc64.rpm curl-devel-7.15.5-2.1.el5_3.4.ppc.rpm curl-devel-7.15.5-2.1.el5_3.4.ppc64.rpm s390x: curl-7.15.5-2.1.el5_3.4.s390.rpm curl-7.15.5-2.1.el5_3.4.s390x.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.s390.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.s390x.rpm curl-devel-7.15.5-2.1.el5_3.4.s390.rpm curl-devel-7.15.5-2.1.el5_3.4.s390x.rpm x86_64: curl-7.15.5-2.1.el5_3.4.i386.rpm curl-7.15.5-2.1.el5_3.4.x86_64.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.i386.rpm curl-debuginfo-7.15.5-2.1.el5_3.4.x86_64.rpm curl-devel-7.15.5-2.1.el5_3.4.i386.rpm curl-devel-7.15.5-2.1.el5_3.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-0037 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFJwm7vXlSAg2UNWIIRAroFAKCKDeunP0rbrBA4fvgQX+CS2i3rPACff22Y ILjVK6SGd0jni2ahCuMeuUk=BV0F -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Several remote vulnerabilities have been discovered in the Iceape internet suite, an unbranded version of the Seamonkey Internet Suite. The Common Vulnerabilities and Exposures project identifies the following problems:. - ------------------------------------------------------------------------Debian Security Advisory DSA-1534-2
Get the latest Linux and open source security news straight to your inbox.