Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Backport fix for CVE-2023-51257.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b5b85798cd 2024-01-24 01:32:39.687107 -------------------------------------------------------------------------------- Name : mingw-jasper Product : Fedora 38 Version : 3.0.6 Release : 5.fc38 URL : https://www.ece.uvic.ca/~frodo/jasper/ Summary : MinGW Windows Jasper library Description : MinGW Windows Jasper library. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2023-51257. -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 15 2024 Sandro Mani - 3.0.6-5 - Backport memory fixes, incl CVE-2023-51257 * Thu Jul 20 2023 Fedora Release Engineering - 3.0.6-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2258403 - TRIAGE CVE-2023-51257 mingw-jasper: . A significant announcement regarding the mingw-jasper package in Fedora 38 addresses CVE-2023-51257, which is a severe memory vulnerability.. mingw-jasper update,Fedora 38 security advisory,memory fix. . Severity: Critical. LinuxSecurity.com Team
Benoit Morgan, Paul Grosen, Thais Moreira Hamasaki, Ke Sun, Alyssa Milburn, Hisham Shafi, Nir Shlomovich, avis Ormandy, Daniel Moghimi, Josh Eads, Salman Qazi, Alexandra Sandulescu, Andy Nguyen, Eduardo Vela, Doug Kwan, and Kostik Shtoyk discovered that some Intel processors . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5563-1
Two security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in unauthenticated command injection or LDAP authentication bypass. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5298-1
Qualys discovered that the OpenSMTPD SMTP server performed insufficient validation of email addresses which could result in the execution of arbitrary commands as root. In addition this update fixes a denial of service by triggering an opportunistic TLS downgrade. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4611-1
- Update jackson-databind to version 2.9.9.3. - Update jackson-core to version 2.9.9. - Update jackson-annotations to version 2.9.9. - Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-99ff6aa32c 2019-09-18 00:01:15.683454 --------------------------------------------------------------------------------Name : jackson-core Product : Fedora 31 Version : 2.9.9 Release : 1.fc31 URL : https://github.com/FasterXML/jackson-core/ Summary : Core part of Jackson Description : Core part of Jackson that defines Streaming API as well as basic shared abstractions. --------------------------------------------------------------------------------Update Information: - Update jackson-databind to version 2.9.9.3. - Update jackson-core to version 2.9.9. - Update jackson-annotations to version 2.9.9. - Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439. --------------------------------------------------------------------------------References: [ 1 ] Bug #1737518 - CVE-2019-14379 jackson-databind: default typing mishandling leading to remote code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1737518 [ 2 ] Bug #1725808 - CVE-2019-12384 jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1725808 [ 3 ] Bug #1725796 - CVE-2019-12814 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1725796 [ 4 ] Bug #1713469 - CVE-2019-12086 jackson-databind: polymorphic typing issue allows attacker to read arbitrarylocal files on the server. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1713469 [ 5 ] Bug #1752964 - CVE-2019-14439 jackson-databind: Polymorphic typing issue related to logback/JNDI [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1752964 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-99ff6aa32c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available.. openSUSE Security Update: Security update for php7 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:0588-1 Rating: important References: #1008026 #1019547 #1019550 #1019568 #1019570 #1022219 #1022255 #1022257 #1022260 #1022262 #1022263 #1022264 #1022265 Cross-References: CVE-2016-10158 CVE-2016-10159 CVE-2016-10160 CVE-2016-10161 CVE-2016-10162 CVE-2016-10166 CVE-2016-10167 CVE-2016-10168 CVE-2016-7478 CVE-2016-7479 CVE-2016-7480 CVE-2016-9138 CVE-2017-5340 Affected Products: openSUSE Leap 42.2 ______________________________________________________________________________ An update that fixes 13 vulnerabilities is now available. Description: This update for php7 fixes the following security issues: - CVE-2016-7480: The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP did not verify that a key is an object, which allowed remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data. (bsc#1019568) - CVE-2017-5340: Zend/zend_hash.c in PHP mishandled certain cases that require large array allocations, which allowed remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data. (bsc#1019570) - CVE-2016-7479: In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may have lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution. (bsc#1019547) - CVE-2016-7478: Zend/zend_exceptions.c in PHP allowed remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876. (bsc#1019550) - CVE-2016-10159: Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP allowed remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PHAR archive. (bsc#1022255) - CVE-2016-10160: Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP allowed remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch. (bsc#1022257) - CVE-2016-10161: The object_common1 function in ext/standard/var_unserializer.c in PHP allowed remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data that is mishandled in a finish_nested_data call. (bsc#1022260) - CVE-2016-10162: The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7 allowed remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call. (bsc#1022262) - CVE-2016-10166: A potential unsigned underflow in gd interpolation functions could lead to memory corruption in the PHP gd module (bsc#1022263) - CVE-2016-10167: A denial of service problem in gdImageCreateFromGd2Ctx() could lead to php out of memory even on small files. (bsc#1022264) - CVE-2016-10168: A signed integer overflow in the gd module could lead to memory corruption (bsc#1022265) - CVE-2016-9138: PHP mishandled property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup. (bsc#1008026) This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-304=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.2 (i586 x86_64): apache2-mod_php7-7.0.7-12.1 apache2-mod_php7-debuginfo-7.0.7-12.1 php7-7.0.7-12.1 php7-bcmath-7.0.7-12.1 php7-bcmath-debuginfo-7.0.7-12.1 php7-bz2-7.0.7-12.1 php7-bz2-debuginfo-7.0.7-12.1 php7-calendar-7.0.7-12.1 php7-calendar-debuginfo-7.0.7-12.1 php7-ctype-7.0.7-12.1 php7-ctype-debuginfo-7.0.7-12.1 php7-curl-7.0.7-12.1 php7-curl-debuginfo-7.0.7-12.1 php7-dba-7.0.7-12.1 php7-dba-debuginfo-7.0.7-12.1 php7-debuginfo-7.0.7-12.1 php7-debugsource-7.0.7-12.1 php7-devel-7.0.7-12.1 php7-dom-7.0.7-12.1 php7-dom-debuginfo-7.0.7-12.1 php7-enchant-7.0.7-12.1 php7-enchant-debuginfo-7.0.7-12.1 php7-exif-7.0.7-12.1 php7-exif-debuginfo-7.0.7-12.1 php7-fastcgi-7.0.7-12.1 php7-fastcgi-debuginfo-7.0.7-12.1 php7-fileinfo-7.0.7-12.1 php7-fileinfo-debuginfo-7.0.7-12.1 php7-firebird-7.0.7-12.1 php7-firebird-debuginfo-7.0.7-12.1 php7-fpm-7.0.7-12.1 php7-fpm-debuginfo-7.0.7-12.1 php7-ftp-7.0.7-12.1 php7-ftp-debuginfo-7.0.7-12.1 php7-gd-7.0.7-12.1 php7-gd-debuginfo-7.0.7-12.1 php7-gettext-7.0.7-12.1 php7-gettext-debuginfo-7.0.7-12.1 php7-gmp-7.0.7-12.1 php7-gmp-debuginfo-7.0.7-12.1 php7-iconv-7.0.7-12.1 php7-iconv-debuginfo-7.0.7-12.1 php7-imap-7.0.7-12.1 php7-imap-debuginfo-7.0.7-12.1 php7-intl-7.0.7-12.1 php7-intl-debuginfo-7.0.7-12.1 php7-json-7.0.7-12.1 php7-json-debuginfo-7.0.7-12.1 php7-ldap-7.0.7-12.1 php7-ldap-debuginfo-7.0.7-12.1 php7-mbstring-7.0.7-12.1 php7-mbstring-debuginfo-7.0.7-12.1 php7-mcrypt-7.0.7-12.1 php7-mcrypt-debuginfo-7.0.7-12.1 php7-mysql-7.0.7-12.1 php7-mysql-debuginfo-7.0.7-12.1 php7-odbc-7.0.7-12.1 php7-odbc-debuginfo-7.0.7-12.1 php7-opcache-7.0.7-12.1 php7-opcache-debuginfo-7.0.7-12.1 php7-openssl-7.0.7-12.1 php7-openssl-debuginfo-7.0.7-12.1 php7-pcntl-7.0.7-12.1 php7-pcntl-debuginfo-7.0.7-12.1 php7-pdo-7.0.7-12.1 php7-pdo-debuginfo-7.0.7-12.1 php7-pgsql-7.0.7-12.1 php7-pgsql-debuginfo-7.0.7-12.1 php7-phar-7.0.7-12.1 php7-phar-debuginfo-7.0.7-12.1 php7-posix-7.0.7-12.1 php7-posix-debuginfo-7.0.7-12.1 php7-pspell-7.0.7-12.1 php7-pspell-debuginfo-7.0.7-12.1 php7-readline-7.0.7-12.1 php7-readline-debuginfo-7.0.7-12.1 php7-shmop-7.0.7-12.1 php7-shmop-debuginfo-7.0.7-12.1 php7-snmp-7.0.7-12.1 php7-snmp-debuginfo-7.0.7-12.1 php7-soap-7.0.7-12.1 php7-soap-debuginfo-7.0.7-12.1 php7-sockets-7.0.7-12.1 php7-sockets-debuginfo-7.0.7-12.1 php7-sqlite-7.0.7-12.1 php7-sqlite-debuginfo-7.0.7-12.1 php7-sysvmsg-7.0.7-12.1 php7-sysvmsg-debuginfo-7.0.7-12.1 php7-sysvsem-7.0.7-12.1 php7-sysvsem-debuginfo-7.0.7-12.1 php7-sysvshm-7.0.7-12.1 php7-sysvshm-debuginfo-7.0.7-12.1 php7-tidy-7.0.7-12.1 php7-tidy-debuginfo-7.0.7-12.1 php7-tokenizer-7.0.7-12.1 php7-tokenizer-debuginfo-7.0.7-12.1 php7-wddx-7.0.7-12.1 php7-wddx-debuginfo-7.0.7-12.1 php7-xmlreader-7.0.7-12.1 php7-xmlreader-debuginfo-7.0.7-12.1 php7-xmlrpc-7.0.7-12.1 php7-xmlrpc-debuginfo-7.0.7-12.1 php7-xmlwriter-7.0.7-12.1 php7-xmlwriter-debuginfo-7.0.7-12.1 php7-xsl-7.0.7-12.1 php7-xsl-debuginfo-7.0.7-12.1 php7-zip-7.0.7-12.1 php7-zip-debuginfo-7.0.7-12.1 php7-zlib-7.0.7-12.1 php7-zlib-debuginfo-7.0.7-12.1 - openSUSE Leap 42.2 (noarch): php7-pear-7.0.7-12.1 php7-pear-Archive_Tar-7.0.7-12.1 References: https://www.suse.com/security/cve/CVE-2016-10158.html https://www.suse.com/security/cve/CVE-2016-10159.html https://www.suse.com/security/cve/CVE-2016-10160.html https://www.suse.com/security/cve/CVE-2016-10161.html https://www.suse.com/security/cve/CVE-2016-10162.html https://www.suse.com/security/cve/CVE-2016-10166.html https://www.suse.com/security/cve/CVE-2016-10167.html https://www.suse.com/security/cve/CVE-2016-10168.html https://www.suse.com/security/cve/CVE-2016-7478.html https://www.suse.com/security/cve/CVE-2016-7479.html https://www.suse.com/security/cve/CVE-2016-7480.html https://www.suse.com/security/cve/CVE-2016-9138.html https://www.suse.com/security/cve/CVE-2017-5340.html https://bugzilla.suse.com/1008026 https://bugzilla.suse.com/1019547 https://bugzilla.suse.com/1019550 https://bugzilla.suse.com/1019568 https://bugzilla.suse.com/1019570 https://bugzilla.suse.com/1022219 https://bugzilla.suse.com/1022255 https://bugzilla.suse.com/1022257 https://bugzilla.suse.com/1022260 https://bugzilla.suse.com/1022262 https://bugzilla.suse.com/1022263 https://bugzilla.suse.com/1022264 https://bugzilla.suse.com/1022265 . This critical enhancement addresses 15 vulnerabilities in php8, improving both reliability and protection for Fedora users.. openSUSE, php7, security update, code execution, denial of service. . Severity: Important. LinuxSecurity.com Team
This update updates the upstream fix for CVE-2014-0224 to address problems with CCS which could result in problems with the Postgres database. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-2950-2
An authentication bypass vulnerability was found in charon, the daemon handling IKEv2 in strongSwan, an IKE/IPsec suite. The state machine handling the security association (IKE_SA) handled some state transitions incorrectly. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2903-1
Get the latest Linux and open source security news straight to your inbox.