Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
ceph 14.2.21 GA Security fix for CVE-2021-3524, CVE-2021-3531. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-6e540b85b9 2021-05-23 01:29:39.229346 --------------------------------------------------------------------------------Name : ceph Product : Fedora 32 Version : 14.2.21 Release : 1.fc32 URL : Summary : User space components of the Ceph file system Description : Ceph is a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage. --------------------------------------------------------------------------------Update Information: ceph 14.2.21 GA Security fix for CVE-2021-3524, CVE-2021-3531 --------------------------------------------------------------------------------ChangeLog: * Thu May 13 2021 Kaleb S. KEITHLEY - 2:14.2.21-1 - ceph 14.2.21 GA --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-6e540b85b9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The Qualys Research Labs reported several vulnerabilities in Exim, a mail transport agent, which could result in local privilege escalation and remote code execution. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2650-1
New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2016-095-01) New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/mozilla-thunderbird-38.7.2-i486-1_slack14.1.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/ (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.1 package: d60cfd10b8c26b1df43e9683a9a1f0d6 mozilla-thunderbird-38.7.2-i486-1_slack14.1.txz Slackware x86_64 14.1 package: d4a33e4edfaaa8bebba291ac11b4d1a0 mozilla-thunderbird-38.7.2-x86_64-1_slack14.1.txz Slackware -current package: b6a3444a1ea9e91c98337001b7aa49ae xap/mozilla-thunderbird-38.7.2-i586-1.txz Slackware x86_64 -current package: 07e97d2546740c3b15cf2932ec00846d xap/mozilla-thunderbird-38.7.2-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg mozilla-thunderbird-38.7.2-i486-1_slack14.1.txz +-----+ . Recent Mozilla Thunderbird patch for Slackware 14.1 released, targeting security vulnerabilities while enhancing overall stability.. Mozilla Thunderbird, Slackware Security, Software Update. . Severity: Critical. LinuxSecurity.comTeam
Security fix for CVE-2014-0225. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-6862 2015-04-26 07:27:39 -------------------------------------------------------------------------------- Name : springframework Product : Fedora 20 Version : 3.1.4 Release : 3.fc20 URL : https://spring.io Summary : Spring Java Application Framework Description : Spring is a layered Java/J2EE application framework, based on code published in Expert One-on-One J2EE Design and Development by Rod Johnson (Wrox, 2002). -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2014-0225 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 24 2015 Michal Srb - 0:3.1.4-3 - Resolves: CVE-2014-0225 * Fri Dec 6 2013 gil cattaneo 0:3.1.4-2 - fix for rhbz: 993376, 953977 - switch to XMvn - disable derby (partial), and jopt-simple support - enable castor and jruby support * Thu Dec 5 2013 Orion Poplawski - 0:3.1.4-1 - Update to 3.1.4 - Add BR xmlunit - Change wstx-asl to woodstox-core-asl * Sun Aug 4 2013 Fedora Release Engineering - 0:3.1.1-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1110110 - CVE-2014-0225 Spring Framework: Information disclosure via SSRF https://bugzilla.redhat.com/show_bug.cgi?id=1110110 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update springframework' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
**2.5.11** (2015-04-01) * security #14167 CVE-2015-2308 (nicolas-grekas) * security #14166 CVE-2015-2309 (neclimdul). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5457 2015-04-04 03:51:41 -------------------------------------------------------------------------------- Name : php-symfony Product : Fedora 21 Version : 2.5.11 Release : 1.fc21 URL : https://symfony.com/ Summary : PHP framework for web projects Description : PHP framework for web projects -------------------------------------------------------------------------------- Update Information: **2.5.11** (2015-04-01) * security #14167 CVE-2015-2308 (nicolas-grekas) * security #14166 CVE-2015-2309 (neclimdul) -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 2 2015 Remi Collet - 2.5.11-1 - Update to 2.5.11 - security fix for CVE-2015-2308 and CVE-2015-2309 * Wed Mar 18 2015 Remi Collet - 2.5.10-1 - Update to 2.5.10 * Mon Dec 15 2014 Remi Collet - 2.5.8-1 - Update to 2.5.8 * Thu Nov 20 2014 Shawn Iwinski - 2.5.7-1 - Updated to 2.5.7 (BZ #1166396) - Added php-composer(egulias/email-validator) dependency -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update php-symfony' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1181-1
Get the latest Linux and open source security news straight to your inbox.