The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected (CVE-2016-8605). . MGASA-2021-0340 - Updated guile1.8 packages fix security vulnerabilities Publication date: 12 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0340.html Type: security Affected Mageia releases: 7 CVE: CVE-2016-3605, CVE-2016-3606 The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected (CVE-2016-8605). The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack (CVE-2016-8606). References: - https://bugs.mageia.org/show_bug.cgi?id=27200 - https://bugs.mageia.org/show_bug.cgi?id=19567 - https://www.cve.org/CVERecord?id=CVE-2016-3605 - https://www.cve.org/CVERecord?id=CVE-2016-3606 SRPMS: - 7/core/guile1.8-1.8.8-25.1.mga7 . The Guile 2.0.13 release addresses umask concerns and mitigates code execution risks found in Mageia's guile1.8.. Guile Security Update, Mageia Permissions Issue, Code Execution Risk, Secure Directory Creation. . Severity: Important. LinuxSecurity.com Team
An upstream patch has been backported to fix a security vulnerability in python-django. CVE-2019-3498: Content spoofing possibility in the default 404 page An attacker could craft a malicious URL that could make spoofed content . MGASA-2019-0035 - Updated python-django packages fix security vulnerability Publication date: 11 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0035.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-3498 An upstream patch has been backported to fix a security vulnerability in python-django. CVE-2019-3498: Content spoofing possibility in the default 404 page An attacker could craft a malicious URL that could make spoofed content appear on the default page generated by the django.views.defaults.page_not_found() view. The URL path is no longer displayed in the default 404 template and the request_path context variable is now quoted to fix the issue for custom templates that use the path. References: - https://bugs.mageia.org/show_bug.cgi?id=24128 - https://www.djangoproject.com/weblog/2019/jan/04/security-releases/ - https://security-tracker.debian.org/tracker/CVE-2019-3498 - https://www.cve.org/CVERecord?id=CVE-2019-3498 SRPMS: - 6/core/python-django-1.8.19-1.1.mga6 . The recent django-python patch in Mageia fixes a critical security issue related to potential content spoofing.. Mageia Security Advisory, python-django Update, Content Spoofing Threat. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-3084-1 September 19, 2016 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: Pengfei Wang discovered a race condition in the audit subsystem in the Linux kernel. A local attacker could use this to corrupt audit logs or disrupt system-call auditing. (CVE-2016-6136) It was discovered that the powerpc and powerpc64 hypervisor-mode KVM implementation in the Linux kernel for did not properly maintain state about transactional memory. An unprivileged attacker in a guest could cause a denial of service (CPU lockup) in the host OS. (CVE-2016-5412) Pengfei Wang discovered a race condition in the Chrome OS embedded controller device driver in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-6156) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: linux-image-4.4.0-38-generic 4.4.0-38.57 linux-image-4.4.0-38-generic-lpae 4.4.0-38.57 linux-image-4.4.0-38-lowlatency 4.4.0-38.57 linux-image-4.4.0-38-powerpc-e500mc 4.4.0-38.57 linux-image-4.4.0-38-powerpc-smp 4.4.0-38.57 linux-image-4.4.0-38-powerpc64-emb 4.4.0-38.57 linux-image-4.4.0-38-powerpc64-smp 4.4.0-38.57 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic,linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: CVE-2016-5412, CVE-2016-6136, CVE-2016-6156 Package Information: https://launchpad.net/ubuntu/+source/linux/4.4.0-38.57 . Multiple security patches applied for Ubuntu 16.04 LTS kernel weaknesses, addressing denial of service risks and auditing concerns.. Ubuntu Update, Linux Kernel, Security Fixes. . Severity: Critical. LinuxSecurity.com Team
Updated package.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1274-1
Get the latest Linux and open source security news straight to your inbox.