The regression of postgresql-9.6-postgis-2.3-scripts being empty in 2.3.1+dfsg-2+deb9u1 has been fixed. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2857-2
Potential leak of redirect targets when loading scripts in a worker. (CVE-2020-15652) WebRTC data channel leaks internal address to peer. (CVE-2020-6514) . MGASA-2020-0320 - Updated thunderbird packages fix security vulnerability Publication date: 18 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0320.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-6463, CVE-2020-6514, CVE-2020-15652, CVE-2020-15659 Potential leak of redirect targets when loading scripts in a worker. (CVE-2020-15652) WebRTC data channel leaks internal address to peer. (CVE-2020-6514) Use-after-free in ANGLE gl::Texture::onUnbindAsSamplerTexture. (CVE-2020-6463) Memory safety bugs fixed in Thunderbird 68.11. (CVE-2020-15659) References: - https://bugs.mageia.org/show_bug.cgi?id=27025 - https://www.thunderbird.net/en-US/thunderbird/68.11.0/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2020-35/ - https://access.redhat.com/errata/RHSA-2020:3344 - https://www.cve.org/CVERecord?id=CVE-2020-6463 - https://www.cve.org/CVERecord?id=CVE-2020-6514 - https://www.cve.org/CVERecord?id=CVE-2020-15652 - https://www.cve.org/CVERecord?id=CVE-2020-15659 SRPMS: - 7/core/thunderbird-68.11.0-1.mga7 - 7/core/thunderbird-l10n-68.11.0-1.mga7 . Revised Thunderbird builds mitigate risks of leaks and safeguard memory vulnerabilities, essential for Mageia 7 adopters.. Thunderbird Security Update, Mageia 7, Data Leak Fix, Memory Safety Fix. . LinuxSecurity.com Team
Update to latest upstream release, fix CVE-2019-9844 (rhbz#1695304,. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-8e7c71f45b 2019-04-13 01:29:51.120150 --------------------------------------------------------------------------------Name : nodejs-simple-markdown Product : Fedora 28 Version : 0.4.4 Release : 1.fc28 URL : https://www.npmjs.com/package/simple-markdown Summary : Javascript markdown parsing, made simple Description : simple-markdown is a markdown-like parser designed for simplicity and extensibility. --------------------------------------------------------------------------------Update Information: Update to latest upstream release, fix CVE-2019-9844 (rhbz#1695304, --------------------------------------------------------------------------------ChangeLog: * Tue Apr 2 2019 Ben Rosser - 0.4.4-1 - Update to latest upstream release, fix CVE-2019-9844 (rhbz#1695304, rhbz#1695303). * Fri Feb 1 2019 Fedora Release Engineering - 0.4.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Fri Jul 13 2018 Fedora Release Engineering - 0.4.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Mon May 21 2018 Ben Rosser - 0.4.1-1 - Updated to latest upstream release (rhbz#1579339). * Mon Apr 30 2018 Ben Rosser - 0.4.0-1 - Updated to latest upstream release (#1554105). * Tue Mar 6 2018 Ben Rosser - 0.3.2-1 - Updated to latest upstream release (#1531831). * Thu Feb 8 2018 Fedora Release Engineering - 0.3.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1695303 - CVE-2019-9844 nodejs-simple-markdown: Cross-site script through the data of a vbscript link https://bugzilla.redhat.com/show_bug.cgi?id=1695303 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-8e7c71f45b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Zsh could be made to execute arbitrary code if it received a specially crafted script.. =========================================================================Ubuntu Security Notice USN-3764-1 September 11, 2018 zsh vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Zsh could be made to execute arbitrary code if it received a specially crafted script. Software Description: - zsh: shell with lots of features Details: It was discovered that Zsh incorrectly handled certain scripts. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-0502, CVE-2018-13259) Richard Maciel Costa discovered that Zsh incorrectly handled certain scripts. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-1100) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: zsh 5.4.2-3ubuntu3.1 Ubuntu 16.04 LTS: zsh 5.1.1-1ubuntu2.3 Ubuntu 14.04 LTS: zsh 5.0.2-3ubuntu6.3 After a standard system update you need to restart Zsh to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3764-1 CVE-2018-0502, CVE-2018-1100, CVE-2018-13259 Package Information: https://launchpad.net/ubuntu/+source/zsh/5.4.2-3ubuntu3.1 https://launchpad.net/ubuntu/+source/zsh/5.1.1-1ubuntu2.3 https://launchpad.net/ubuntu/+source/zsh/5.0.2-3ubuntu6.3 . Exploits in Zsh may lead to unauthorized code execution. Ensure your Ubuntu installations are updated immediately to safeguard against these threats.. Zsh vulnerabilities, Ubuntu security, code execution risks. . Severity: Critical.LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for zsh ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2686-1 Rating: important References: #1107294 #1107296 Cross-References: CVE-2018-0502 CVE-2018-13259 Affected Products: SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for zsh to version 5.6 fixes the following security issues: - CVE-2018-0502: The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line (bsc#1107296). - CVE-2018-13259: Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one (bsc#1107294). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1880=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): zsh-5.6-3.6.1 zsh-debuginfo-5.6-3.6.1 zsh-debugsource-5.6-3.6.1 References: https://www.suse.com/security/cve/CVE-2018-0502.html https://www.suse.com/security/cve/CVE-2018-13259.html https://bugzilla.suse.com/1107294 https://bugzilla.suse.com/1107296 _______________________________________________ sle-security-updates mailing list
Several vulnerabilities have been discovered in the chromium web browser. CVE-2017-5006 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3776-1
Low: yum-autoupdate update. Date: Tue, 25 Sep 2012 08:50:06 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: FASTBUGS for SL 5x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: perl-LDAP-0.33-4.el5_8.noarch.rpm x86_64: perl-LDAP-0.33-4.el5_8.noarch.rpm Date: Tue, 25 Sep 2012 08:50:08 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: FASTBUGS for SL 6x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploadedto i386: cvs-1.11.23-15.el6.i686.rpm cvs-inetd-1.11.23-15.el6.noarch.rpm graphviz-2.26.0-10.el6.i686.rpm graphviz-devel-2.26.0-10.el6.i686.rpm graphviz-doc-2.26.0-10.el6.i686.rpm graphviz-gd-2.26.0-10.el6.i686.rpm graphviz-graphs-2.26.0-10.el6.i686.rpm graphviz-guile-2.26.0-10.el6.i686.rpm graphviz-java-2.26.0-10.el6.i686.rpm graphviz-lua-2.26.0-10.el6.i686.rpm graphviz-perl-2.26.0-10.el6.i686.rpm graphviz-php-2.26.0-10.el6.i686.rpm graphviz-python-2.26.0-10.el6.i686.rpm graphviz-ruby-2.26.0-10.el6.i686.rpm graphviz-tcl-2.26.0-10.el6.i686.rpm krb5-devel-1.9-33.el6_3.3.i686.rpm krb5-libs-1.9-33.el6_3.3.i686.rpm krb5-pkinit-openssl-1.9-33.el6_3.3.i686.rpm krb5-server-1.9-33.el6_3.3.i686.rpm krb5-server-ldap-1.9-33.el6_3.3.i686.rpm krb5-workstation-1.9-33.el6_3.3.i686.rpm openswan-2.6.32-19.el6_3.i686.rpm openswan-doc-2.6.32-19.el6_3.i686.rpm squid-3.1.10-9.el6_3.i686.rpm x86_64: cvs-1.11.23-15.el6.x86_64.rpm cvs-inetd-1.11.23-15.el6.noarch.rpm graphviz-2.26.0-10.el6.i686.rpm graphviz-2.26.0-10.el6.x86_64.rpm graphviz-devel-2.26.0-10.el6.i686.rpm graphviz-devel-2.26.0-10.el6.x86_64.rpm graphviz-doc-2.26.0-10.el6.x86_64.rpm graphviz-gd-2.26.0-10.el6.i686.rpm graphviz-gd-2.26.0-10.el6.x86_64.rpm graphviz-graphs-2.26.0-10.el6.x86_64.rpm graphviz-guile-2.26.0-10.el6.x86_64.rpm graphviz-java-2.26.0-10.el6.x86_64.rpm graphviz-lua-2.26.0-10.el6.x86_64.rpm graphviz-perl-2.26.0-10.el6.x86_64.rpm graphviz-php-2.26.0-10.el6.x86_64.rpm graphviz-python-2.26.0-10.el6.x86_64.rpm graphviz-ruby-2.26.0-10.el6.x86_64.rpm graphviz-tcl-2.26.0-10.el6.x86_64.rpm krb5-devel-1.9-33.el6_3.3.i686.rpm krb5-devel-1.9-33.el6_3.3.x86_64.rpm krb5-libs-1.9-33.el6_3.3.i686.rpm krb5-libs-1.9-33.el6_3.3.x86_64.rpm krb5-pkinit-openssl-1.9-33.el6_3.3.x86_64.rpm krb5-server-1.9-33.el6_3.3.x86_64.rpm krb5-server-ldap-1.9-33.el6_3.3.i686.rpm krb5-server-ldap-1.9-33.el6_3.3.x86_64.rpm krb5-workstation-1.9-33.el6_3.3.x86_64.rpm openswan-2.6.32-19.el6_3.x86_64.rpm openswan-doc-2.6.32-19.el6_3.x86_64.rpm squid-3.1.10-9.el6_3.x86_64.rpm Date: Tue, 25 Sep2012 11:42:51 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Low: yum-autoupdate update on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Low: yum-autoupdate update Issue date: 2012-09-25 The Scientific Linux team was made aware of a problem with the use of temp files in the yum-autoupdate script by Elias Persson. The problem should be corrected in these packages. These packages also include some minor feature updates for each release. For SL5, the script now includes the 'PRERUN' and 'POSTRUN' functionality first provided in SL5.8 and SL6. The script is still configured as before, in the /etc/yum.d/ directory. The new features were added to the /etc/yum.d/yum.cron.updateexec config file. For SL6, the package now includes an augeas lense for possible automated configuration. Augeas is a configuration file editing tool. This lense allows augeas to read your configuration file so that you can customize it through that program. Typically augeas is used for automated configuration file edits. This lense should allow you to script out any changes you wish to make at your site. Automated tools such as puppet can use augeas as native tool for configuration file edits. These packages were placed in testing for two weeks before their release. There were no reported problems. SL5: i386: yum-autoupdate-1.2-2.SL.noarch.rpm x86_64: yum-autoupdate-1.2-2.SL.noarch.rpm SL6: i386: yum-autoupdate-2-5.0.noarch.rpm x86_64: yum-autoupdate-2-5.0.noarch.rpm . A new yum-autoupdate release has been published for Scientific Linux, rectifying a minor script-related concern while introducing improved functionalities.. yum-autoupdate, Scientific Linux, security advisory, software update. . Severity: Low. LinuxSecurity.com Team
The %post script in the gnome-icon-theme package had problems with icon theme names containing spaces. This update fixes this problem.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-889 2006-08-02 ---------------------------------------------------------------------Product : Fedora Core 5 Name : gnome-icon-theme Version : 2.14.2 Release : 1.fc5.2 Summary : Base gnome icons Description : Contains the base icons needed by the Gnome desktop environment. ---------------------------------------------------------------------Update Information: The %post script in the gnome-icon-theme package had problems with icon theme names containing spaces. This update fixes this problem. ---------------------------------------------------------------------* Wed Jun 7 2006 Matthias Clasen 2.14.2-1.fc5.2 - Fix a problem in %post (#194323) ---------------------------------------------------------------------This update can be downloaded from: 8170b490b7bae02a30ac15c69831376794d23f0e SRPMS/gnome-icon-theme-2.14.2-1.fc5.2.src.rpm 8170b490b7bae02a30ac15c69831376794d23f0e noarch/gnome-icon-theme-2.14.2-1.fc5.2.src.rpm c725201d750a532dcee6bffa228000bd8741838a ppc/gnome-icon-theme-2.14.2-1.fc5.2.noarch.rpm c725201d750a532dcee6bffa228000bd8741838a x86_64/gnome-icon-theme-2.14.2-1.fc5.2.noarch.rpm c725201d750a532dcee6bffa228000bd8741838a i386/gnome-icon-theme-2.14.2-1.fc5.2.noarch.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.