Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kpatch-patch security update Advisory ID: RHSA-2023:1660-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1660 Issue date: 2023-04-05 CVE Names: CVE-2023-0266 CVE-2023-0386 ==================================================================== 1. Summary: An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS EUS (v.8.6) - ppc64le, x86_64 3. Description: This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel. Security Fix(es): * ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266) * kernel: FUSE filesystem low-privileged user privileges escalation (CVE-2023-0386) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2159505 - CVE-2023-0386 kernel: FUSE filesystemlow-privileged user privileges escalation 2163379 - CVE-2023-0266 ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF 6. Package List: Red Hat Enterprise Linux BaseOS EUS(v.8.6): Source: kpatch-patch-4_18_0-372_26_1-1-6.el8_6.src.rpm kpatch-patch-4_18_0-372_32_1-1-5.el8_6.src.rpm kpatch-patch-4_18_0-372_36_1-1-4.el8_6.src.rpm kpatch-patch-4_18_0-372_40_1-1-4.el8_6.src.rpm kpatch-patch-4_18_0-372_41_1-1-3.el8_6.src.rpm kpatch-patch-4_18_0-372_46_1-1-1.el8_6.src.rpm ppc64le: kpatch-patch-4_18_0-372_26_1-1-6.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_26_1-debuginfo-1-6.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_26_1-debugsource-1-6.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_32_1-1-5.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_32_1-debuginfo-1-5.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_32_1-debugsource-1-5.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_36_1-1-4.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_36_1-debuginfo-1-4.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_36_1-debugsource-1-4.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_40_1-1-4.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_40_1-debuginfo-1-4.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_40_1-debugsource-1-4.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_41_1-1-3.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_41_1-debuginfo-1-3.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_41_1-debugsource-1-3.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_46_1-1-1.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_46_1-debuginfo-1-1.el8_6.ppc64le.rpm kpatch-patch-4_18_0-372_46_1-debugsource-1-1.el8_6.ppc64le.rpm x86_64: kpatch-patch-4_18_0-372_26_1-1-6.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_26_1-debuginfo-1-6.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_26_1-debugsource-1-6.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_32_1-1-5.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_32_1-debuginfo-1-5.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_32_1-debugsource-1-5.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_36_1-1-4.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_36_1-debuginfo-1-4.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_36_1-debugsource-1-4.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_40_1-1-4.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_40_1-debuginfo-1-4.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_40_1-debugsource-1-4.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_41_1-1-3.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_41_1-debuginfo-1-3.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_41_1-debugsource-1-3.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_46_1-1-1.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_46_1-debuginfo-1-1.el8_6.x86_64.rpm kpatch-patch-4_18_0-372_46_1-debugsource-1-1.el8_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-0266 https://access.redhat.com/security/cve/CVE-2023-0386 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZC2QfNzjgjWX9erEAQgNNg/9Eho8CXtXoHqZQdLrGhk/KvGhNdZ75hDt nARC7hATfax98FiwvYMvEcL9ZdBGzrxcsd9yXmE+TT8pKlu2x2AX10Y8EAKg76GX YSWS6YpVHmrxi2pV7w5WjPqY+Xz7pbTxhCqXxJF6AeiaDgpq29N8XxlIwy12VNey N6RuS9pUQ9JjuE3RnxYdWUD1AzHFjM9OZsSs1jEJr9RLKzoYHuo9SD+Md7PAyaba ifrzTxNOcAfbZME1O30dObcKgJM10No4gTvxrwA7V6ZSHMNl9qn9mtKFdGrqnl70 RHXL4NkeJJJ2yDw9SEqQevc/tPfP2rqEenn35UK6smANdXNL2OQ1GLXnCu+rF6e9 KOltIkQJ+ypYU5ot5g6KsvlCB4vXJ1FJe5aBAhHrKpuQds7IkyNoy9mPoIs/Mjen bS2dX7AsI3uT28qxkrsEQRGS9Okh2FsMQjjLe+f0KeerxA8e5feVJBRUS42Schab TTw2NU5W+sfRa20kDcm/fkt/7Ft8qFRnUHqAbJTlvvepL8hodl2RtU0eymACVk0T kTRK44aoZJFbLAbTuiQHFlDTnWi+0O2PoFga5l5XhbF/9zc6hk29rR0hM1BbcHje LBWtNTttvPBwBg5hv1/VvCniiIVMPYvcRYg5RDAA3knXd5IEtOats4UBTTxnVg0W sQWzQbcINb0=plbD -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Update to 3.107. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-cd5ad916e4 2020-09-28 00:54:22.602624 --------------------------------------------------------------------------------Name : xawtv Product : Fedora 32 Version : 3.107 Release : 1.fc32 URL : https://linuxtv.org/wiki/index.php/Xawtv Summary : TV applications for video4linux compliant devices Description : Xawtv is a simple xaw-based TV program which uses the bttv driver or video4linux. Xawtv contains various command-line utilities for grabbing images and .avi movies, for tuning in to TV stations, etc. Xawtv also includes a grabber driver for vic. --------------------------------------------------------------------------------Update Information: Update to 3.107 --------------------------------------------------------------------------------ChangeLog: * Sat May 16 2020 Mauro Carvalho Chehab - 3.107-1 - upgrade to version 3.107 --------------------------------------------------------------------------------References: [ 1 ] Bug #1882286 - CVE-2020-13696 xawtv: specially crafted input leads to information disclosure and user privilege escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1882286 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-cd5ad916e4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2016:2766-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:2766.html Issue date: 2016-11-15 CVE Names: CVE-2016-1583 CVE-2016-2143 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, noarch, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - noarch, x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, noarch, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * It was found that stacking a file system over procfs in the Linux kernel could lead to a kernel stack overflow due to deep nesting, as demonstrated by mounting ecryptfs overprocfs and creating a recursion by mapping /proc/environ. An unprivileged, local user could potentially use this flaw to escalate their privileges on the system. (CVE-2016-1583, Important) * It was reported that on s390x, the fork of a process with four page table levels will cause memory corruption with a variety of symptoms. All processes are created with three level page table and a limit of 4TB for the address space. If the parent process has four page table levels with a limit of 8PB, the function that duplicates the address space will try to copy memory areas outside of the address space limit for the child process. (CVE-2016-2143, Moderate) Bug Fix(es): * Use of a multi-threaded workload with high memory mappings sometiems caused a kernel panic, due to a race condition between the context switch and the pagetable upgrade. This update fixes the switch_mm() by using the complete asce parameter instead of the asce_bits parameter. As a result, the kernel no longer panics in the described scenario. (BZ#1377472) * When iptables created the Transmission Control Protocol (TCP) reset packet, a kernel crash could occur due to uninitialized pointer to the TCP header within the Socket Buffer (SKB). This update fixes the transport header pointer in TCP reset for both IPv4 and IPv6, and the kernel no longer crashes in the described situation.(BZ#1372266) * Previously, when the Enhanced Error Handling (EEH) mechanism did not block the PCI configuration space access and an error was detected, a kernel panic occurred. This update fixes EEH to fix this problem. As a result, the kernel no longer panics in the described scenario. (BZ#1379596) * When the lockd service failed to start up completely, the notifier blocks were in some cases registered on a notification chain multiple times, which caused the occurrence of a circular list on the notification chain. Consequently, a soft lock-up or a kernel oops occurred. With this update, the notifier blocks are unregistered if lockd fails to start up completely, and the softlock-ups or the kernel oopses no longer occur under the described circumstances. (BZ#1375637) * When the Fibre Channel over Ethernet (FCoE) was configured, the FCoE MaxFrameSize parameter was incorrectly restricted to 1452. With this update, the NETIF_F_ALL_FCOE symbol is no longer ignored, which fixes this bug. MaxFrameSize is now restricted to 2112, which is the correct value. (BZ#1381592) * When the fnic driver was installed on Cisco UCS Blade Server, the discs were under certain circumstances put into the offline state with the following error message: "Medium access timeout failure. Offlining disk!". This update fixes fnic to set the Small Computer System Interface (SCSI) status as DID_ABORT after a successful abort operation. As a result, the discs are no longer put into the offlined state in the described situation. (BZ#1382620) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1308908 - CVE-2016-2143 kernel: Fork of large process causes memory corruption 1344721 - CVE-2016-1583 kernel: Stack overflow via ecryptfs and /proc/$pid/environ 6. Package List: Red Hat Enterprise Linux Desktop (v.6): Source: kernel-2.6.32-642.11.1.el6.src.rpm i386: kernel-2.6.32-642.11.1.el6.i686.rpm kernel-debug-2.6.32-642.11.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debug-devel-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm kernel-devel-2.6.32-642.11.1.el6.i686.rpm kernel-headers-2.6.32-642.11.1.el6.i686.rpm perf-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm noarch: kernel-abi-whitelists-2.6.32-642.11.1.el6.noarch.rpm kernel-doc-2.6.32-642.11.1.el6.noarch.rpm kernel-firmware-2.6.32-642.11.1.el6.noarch.rpm x86_64: kernel-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-642.11.1.el6.i686.rpm kernel-debug-devel-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-x86_64-2.6.32-642.11.1.el6.x86_64.rpm kernel-devel-2.6.32-642.11.1.el6.x86_64.rpm kernel-headers-2.6.32-642.11.1.el6.x86_64.rpm perf-2.6.32-642.11.1.el6.x86_64.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v.6): i386: kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm x86_64: kernel-debug-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-642.11.1.el6.x86_64.rpm perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm python-perf-2.6.32-642.11.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: kernel-2.6.32-642.11.1.el6.src.rpm noarch: kernel-abi-whitelists-2.6.32-642.11.1.el6.noarch.rpm kernel-doc-2.6.32-642.11.1.el6.noarch.rpm kernel-firmware-2.6.32-642.11.1.el6.noarch.rpm x86_64: kernel-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-642.11.1.el6.i686.rpm kernel-debug-devel-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-x86_64-2.6.32-642.11.1.el6.x86_64.rpm kernel-devel-2.6.32-642.11.1.el6.x86_64.rpm kernel-headers-2.6.32-642.11.1.el6.x86_64.rpm perf-2.6.32-642.11.1.el6.x86_64.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v.6): x86_64: kernel-debug-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-642.11.1.el6.x86_64.rpm perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm python-perf-2.6.32-642.11.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: kernel-2.6.32-642.11.1.el6.src.rpm i386: kernel-2.6.32-642.11.1.el6.i686.rpm kernel-debug-2.6.32-642.11.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debug-devel-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm kernel-devel-2.6.32-642.11.1.el6.i686.rpm kernel-headers-2.6.32-642.11.1.el6.i686.rpm perf-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm noarch: kernel-abi-whitelists-2.6.32-642.11.1.el6.noarch.rpm kernel-doc-2.6.32-642.11.1.el6.noarch.rpm kernel-firmware-2.6.32-642.11.1.el6.noarch.rpm ppc64: kernel-2.6.32-642.11.1.el6.ppc64.rpm kernel-bootwrapper-2.6.32-642.11.1.el6.ppc64.rpm kernel-debug-2.6.32-642.11.1.el6.ppc64.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.ppc64.rpm kernel-debug-devel-2.6.32-642.11.1.el6.ppc64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.ppc64.rpm kernel-debuginfo-common-ppc64-2.6.32-642.11.1.el6.ppc64.rpm kernel-devel-2.6.32-642.11.1.el6.ppc64.rpm kernel-headers-2.6.32-642.11.1.el6.ppc64.rpm perf-2.6.32-642.11.1.el6.ppc64.rpm perf-debuginfo-2.6.32-642.11.1.el6.ppc64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.ppc64.rpm s390x: kernel-2.6.32-642.11.1.el6.s390x.rpm kernel-debug-2.6.32-642.11.1.el6.s390x.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.s390x.rpm kernel-debug-devel-2.6.32-642.11.1.el6.s390x.rpm kernel-debuginfo-2.6.32-642.11.1.el6.s390x.rpm kernel-debuginfo-common-s390x-2.6.32-642.11.1.el6.s390x.rpm kernel-devel-2.6.32-642.11.1.el6.s390x.rpm kernel-headers-2.6.32-642.11.1.el6.s390x.rpm kernel-kdump-2.6.32-642.11.1.el6.s390x.rpm kernel-kdump-debuginfo-2.6.32-642.11.1.el6.s390x.rpm kernel-kdump-devel-2.6.32-642.11.1.el6.s390x.rpm perf-2.6.32-642.11.1.el6.s390x.rpm perf-debuginfo-2.6.32-642.11.1.el6.s390x.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.s390x.rpm x86_64: kernel-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-642.11.1.el6.i686.rpm kernel-debug-devel-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-x86_64-2.6.32-642.11.1.el6.x86_64.rpm kernel-devel-2.6.32-642.11.1.el6.x86_64.rpm kernel-headers-2.6.32-642.11.1.el6.x86_64.rpm perf-2.6.32-642.11.1.el6.x86_64.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): i386: kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm ppc64: kernel-debug-debuginfo-2.6.32-642.11.1.el6.ppc64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.ppc64.rpm kernel-debuginfo-common-ppc64-2.6.32-642.11.1.el6.ppc64.rpm perf-debuginfo-2.6.32-642.11.1.el6.ppc64.rpm python-perf-2.6.32-642.11.1.el6.ppc64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.ppc64.rpm s390x: kernel-debug-debuginfo-2.6.32-642.11.1.el6.s390x.rpm kernel-debuginfo-2.6.32-642.11.1.el6.s390x.rpm kernel-debuginfo-common-s390x-2.6.32-642.11.1.el6.s390x.rpm kernel-kdump-debuginfo-2.6.32-642.11.1.el6.s390x.rpm perf-debuginfo-2.6.32-642.11.1.el6.s390x.rpm python-perf-2.6.32-642.11.1.el6.s390x.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.s390x.rpm x86_64: kernel-debug-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-642.11.1.el6.x86_64.rpm perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm python-perf-2.6.32-642.11.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm RedHat Enterprise Linux Workstation (v. 6): Source: kernel-2.6.32-642.11.1.el6.src.rpm i386: kernel-2.6.32-642.11.1.el6.i686.rpm kernel-debug-2.6.32-642.11.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debug-devel-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm kernel-devel-2.6.32-642.11.1.el6.i686.rpm kernel-headers-2.6.32-642.11.1.el6.i686.rpm perf-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm noarch: kernel-abi-whitelists-2.6.32-642.11.1.el6.noarch.rpm kernel-doc-2.6.32-642.11.1.el6.noarch.rpm kernel-firmware-2.6.32-642.11.1.el6.noarch.rpm x86_64: kernel-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-642.11.1.el6.i686.rpm kernel-debug-devel-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-x86_64-2.6.32-642.11.1.el6.x86_64.rpm kernel-devel-2.6.32-642.11.1.el6.x86_64.rpm kernel-headers-2.6.32-642.11.1.el6.x86_64.rpm perf-2.6.32-642.11.1.el6.x86_64.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.6): i386: kernel-debug-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-2.6.32-642.11.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-642.11.1.el6.i686.rpm perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm python-perf-2.6.32-642.11.1.el6.i686.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.i686.rpm x86_64: kernel-debug-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-642.11.1.el6.x86_64.rpm perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm python-perf-2.6.32-642.11.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-642.11.1.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2016-1583 https://access.redhat.com/security/cve/CVE-2016-2143 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYK2b7XlSAg2UNWIIRAg/zAKDAkaTTYcL6DAm13YKKe6S9SuXpcQCgnT3k PbrYvhoK7j0z8LjqP5jWjG0=lQkt -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2015:1023-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2015:1023.html Issue date: 2015-05-25 CVE Names: CVE-2015-1251 CVE-2015-1252 CVE-2015-1253 CVE-2015-1254 CVE-2015-1255 CVE-2015-1256 CVE-2015-1257 CVE-2015-1258 CVE-2015-1259 CVE-2015-1260 CVE-2015-1261 CVE-2015-1262 CVE-2015-1263 CVE-2015-1264 CVE-2015-1265 ==================================================================== 1. Summary: Updated chromium-browser packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: Chromium is an open-source web browser, powered by WebKit (Blink). Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash or, potentially, execute arbitrary code with the privileges of the user running Chromium. (CVE-2015-1251, CVE-2015-1252, CVE-2015-1253, CVE-2015-1254, CVE-2015-1255, CVE-2015-1256,CVE-2015-1257, CVE-2015-1258, CVE-2015-1259, CVE-2015-1260, CVE-2015-1261, CVE-2015-1262, CVE-2015-1263, CVE-2015-1264, CVE-2015-1265) All Chromium users should upgrade to these updated packages, which contain Chromium version 43.0.2357.65, which corrects these issues. After installing the update, Chromium must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1223258 - CVE-2015-1251 chromium-browser: Use-after-free in Speech. 1223259 - CVE-2015-1252 chromium-browser: Sandbox escape in Chrome. 1223260 - CVE-2015-1253 chromium-browser: Cross-origin bypass in DOM. 1223261 - CVE-2015-1254 chromium-browser: Cross-origin bypass in Editing. 1223262 - CVE-2015-1255 chromium-browser: Use-after-free in WebAudio. 1223263 - CVE-2015-1256 chromium-browser: Use-after-free in SVG. 1223264 - CVE-2015-1257 chromium-browser: Container-overflow in SVG. 1223266 - CVE-2015-1258 chromium-browser: Negative-size parameter in Libvpx. 1223267 - CVE-2015-1259 chromium-browser: Uninitialized value in PDFium. 1223268 - CVE-2015-1260 chromium-browser: Use-after-free in WebRTC. 1223269 - CVE-2015-1261 chromium-browser: URL bar spoofing in unspecified component 1223270 - CVE-2015-1262 chromium-browser: Uninitialized value in Blink. 1223271 - CVE-2015-1263 chromium-browser: insecure download of spellcheck dictionary in unspecified component 1223272 - CVE-2015-1264 chromium-browser: Cross-site scripting in bookmarks. 1223273 - CVE-2015-1265 chromium-browser: Various fixes from internal audits, fuzzing and other initiatives. 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v.6): i386: chromium-browser-43.0.2357.65-1.el6_6.i686.rpm chromium-browser-debuginfo-43.0.2357.65-1.el6_6.i686.rpm x86_64: chromium-browser-43.0.2357.65-1.el6_6.x86_64.rpm chromium-browser-debuginfo-43.0.2357.65-1.el6_6.x86_64.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: chromium-browser-43.0.2357.65-1.el6_6.i686.rpm chromium-browser-debuginfo-43.0.2357.65-1.el6_6.i686.rpm x86_64: chromium-browser-43.0.2357.65-1.el6_6.x86_64.rpm chromium-browser-debuginfo-43.0.2357.65-1.el6_6.x86_64.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: chromium-browser-43.0.2357.65-1.el6_6.i686.rpm chromium-browser-debuginfo-43.0.2357.65-1.el6_6.i686.rpm x86_64: chromium-browser-43.0.2357.65-1.el6_6.x86_64.rpm chromium-browser-debuginfo-43.0.2357.65-1.el6_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-1251 https://access.redhat.com/security/cve/CVE-2015-1252 https://access.redhat.com/security/cve/CVE-2015-1253 https://access.redhat.com/security/cve/CVE-2015-1254 https://access.redhat.com/security/cve/CVE-2015-1255 https://access.redhat.com/security/cve/CVE-2015-1256 https://access.redhat.com/security/cve/CVE-2015-1257 https://access.redhat.com/security/cve/CVE-2015-1258 https://access.redhat.com/security/cve/CVE-2015-1259 https://access.redhat.com/security/cve/CVE-2015-1260 https://access.redhat.com/security/cve/CVE-2015-1261 https://access.redhat.com/security/cve/CVE-2015-1262 https://access.redhat.com/security/cve/CVE-2015-1263 https://access.redhat.com/security/cve/CVE-2015-1264 https://access.redhat.com/security/cve/CVE-2015-1265 https://access.redhat.com/security/updates/classification/#important https://chromereleases.googleblog.com/2015/05/stable-channel-update_19.html 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. . Crucial security patch for chromium-browser on Red Hat Enterprise Linux resolves several vulnerabilities in the application.. red hat update, browser security, chromium vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Updated postgresql packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: postgresql security update Advisory ID: RHSA-2014:0249-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2014:0249.html Issue date: 2014-03-04 CVE Names: CVE-2014-0060 CVE-2014-0061 CVE-2014-0062 CVE-2014-0063 CVE-2014-0064 CVE-2014-0065 CVE-2014-0066 ==================================================================== 1. Summary: Updated postgresql packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: PostgreSQL is an advanced object-relational database management system (DBMS). Multiple stack-based buffer overflow flaws were found in the date/time implementation of PostgreSQL. An authenticated database user could provide a specially crafted date/time value that, when processed, could cause PostgreSQL to crash or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL. (CVE-2014-0063) Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in various type input functions in PostgreSQL. An authenticated database user could possibly use these flaws to crashPostgreSQL or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL. (CVE-2014-0064) Multiple potential buffer overflow flaws were found in PostgreSQL. An authenticated database user could possibly use these flaws to crash PostgreSQL or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL. (CVE-2014-0065) It was found that granting an SQL role to a database user in a PostgreSQL database without specifying the "ADMIN" option allowed the grantee to remove other users from their granted role. An authenticated database user could use this flaw to remove a user from an SQL role which they were granted access to. (CVE-2014-0060) A flaw was found in the validator functions provided by PostgreSQL's procedural languages (PLs). An authenticated database user could possibly use this flaw to escalate their privileges. (CVE-2014-0061) A race condition was found in the way the CREATE INDEX command performed multiple independent lookups of a table that had to be indexed. An authenticated database user could possibly use this flaw to escalate their privileges. (CVE-2014-0062) It was found that the chkpass extension of PostgreSQL did not check the return value of the crypt() function. An authenticated database user could possibly use this flaw to crash PostgreSQL via a null pointer dereference. (CVE-2014-0066) Red Hat would like to thank the PostgreSQL project for reporting these issues. Upstream acknowledges Noah Misch as the original reporter of CVE-2014-0060 and CVE-2014-0063, Heikki Linnakangas and Noah Misch as the original reporters of CVE-2014-0064, Peter Eisentraut and Jozef Mlich as the original reporters of CVE-2014-0065, Andres Freund as the original reporter of CVE-2014-0061, Robert Haas and Andres Freund as the original reporters of CVE-2014-0062, and Honza Horak and Bruce Momjian as the original reporters of CVE-2014-0066. All PostgreSQL users are advised to upgrade to these updated packages, which contain backported patches to correctthese issues. If the postgresql service is running, it will be automatically restarted after installing this update. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1065219 - CVE-2014-0060 postgresql: SET ROLE without ADMIN OPTION allows adding and removing group members1065220 - CVE-2014-0061 postgresql: privilege escalation via procedural language validator functions 1065222 - CVE-2014-0062 postgresql: CREATE INDEX race condition possibly leading to privilege escalation 1065226 - CVE-2014-0063 postgresql: stack-based buffer overflow in datetime input/output 1065230 - CVE-2014-0064 postgresql: integer overflows leading to buffer overflows 1065235 - CVE-2014-0065 postgresql: possible buffer overflow flaws 1065236 - CVE-2014-0066 postgresql: NULL pointer dereference 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: postgresql-8.1.23-10.el5_10.i386.rpm postgresql-contrib-8.1.23-10.el5_10.i386.rpm postgresql-debuginfo-8.1.23-10.el5_10.i386.rpm postgresql-docs-8.1.23-10.el5_10.i386.rpm postgresql-libs-8.1.23-10.el5_10.i386.rpm postgresql-python-8.1.23-10.el5_10.i386.rpm postgresql-tcl-8.1.23-10.el5_10.i386.rpm x86_64: postgresql-8.1.23-10.el5_10.x86_64.rpm postgresql-contrib-8.1.23-10.el5_10.x86_64.rpm postgresql-debuginfo-8.1.23-10.el5_10.i386.rpm postgresql-debuginfo-8.1.23-10.el5_10.x86_64.rpm postgresql-docs-8.1.23-10.el5_10.x86_64.rpm postgresql-libs-8.1.23-10.el5_10.i386.rpm postgresql-libs-8.1.23-10.el5_10.x86_64.rpm postgresql-python-8.1.23-10.el5_10.x86_64.rpm postgresql-tcl-8.1.23-10.el5_10.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: postgresql-debuginfo-8.1.23-10.el5_10.i386.rpm postgresql-devel-8.1.23-10.el5_10.i386.rpm postgresql-pl-8.1.23-10.el5_10.i386.rpm postgresql-server-8.1.23-10.el5_10.i386.rpm postgresql-test-8.1.23-10.el5_10.i386.rpm x86_64: postgresql-debuginfo-8.1.23-10.el5_10.i386.rpm postgresql-debuginfo-8.1.23-10.el5_10.x86_64.rpm postgresql-devel-8.1.23-10.el5_10.i386.rpm postgresql-devel-8.1.23-10.el5_10.x86_64.rpm postgresql-pl-8.1.23-10.el5_10.x86_64.rpm postgresql-server-8.1.23-10.el5_10.x86_64.rpm postgresql-test-8.1.23-10.el5_10.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: postgresql-8.1.23-10.el5_10.i386.rpm postgresql-contrib-8.1.23-10.el5_10.i386.rpm postgresql-debuginfo-8.1.23-10.el5_10.i386.rpm postgresql-devel-8.1.23-10.el5_10.i386.rpm postgresql-docs-8.1.23-10.el5_10.i386.rpm postgresql-libs-8.1.23-10.el5_10.i386.rpm postgresql-pl-8.1.23-10.el5_10.i386.rpm postgresql-python-8.1.23-10.el5_10.i386.rpm postgresql-server-8.1.23-10.el5_10.i386.rpm postgresql-tcl-8.1.23-10.el5_10.i386.rpm postgresql-test-8.1.23-10.el5_10.i386.rpm ia64: postgresql-8.1.23-10.el5_10.ia64.rpm postgresql-contrib-8.1.23-10.el5_10.ia64.rpm postgresql-debuginfo-8.1.23-10.el5_10.i386.rpm postgresql-debuginfo-8.1.23-10.el5_10.ia64.rpm postgresql-devel-8.1.23-10.el5_10.ia64.rpm postgresql-docs-8.1.23-10.el5_10.ia64.rpm postgresql-libs-8.1.23-10.el5_10.i386.rpm postgresql-libs-8.1.23-10.el5_10.ia64.rpm postgresql-pl-8.1.23-10.el5_10.ia64.rpm postgresql-python-8.1.23-10.el5_10.ia64.rpm postgresql-server-8.1.23-10.el5_10.ia64.rpm postgresql-tcl-8.1.23-10.el5_10.ia64.rpm postgresql-test-8.1.23-10.el5_10.ia64.rpm ppc: postgresql-8.1.23-10.el5_10.ppc.rpm postgresql-8.1.23-10.el5_10.ppc64.rpm postgresql-contrib-8.1.23-10.el5_10.ppc.rpm postgresql-debuginfo-8.1.23-10.el5_10.ppc.rpm postgresql-debuginfo-8.1.23-10.el5_10.ppc64.rpm postgresql-devel-8.1.23-10.el5_10.ppc.rpm postgresql-devel-8.1.23-10.el5_10.ppc64.rpm postgresql-docs-8.1.23-10.el5_10.ppc.rpm postgresql-libs-8.1.23-10.el5_10.ppc.rpm postgresql-libs-8.1.23-10.el5_10.ppc64.rpm postgresql-pl-8.1.23-10.el5_10.ppc.rpm postgresql-python-8.1.23-10.el5_10.ppc.rpm postgresql-server-8.1.23-10.el5_10.ppc.rpm postgresql-tcl-8.1.23-10.el5_10.ppc.rpm postgresql-test-8.1.23-10.el5_10.ppc.rpm s390x: postgresql-8.1.23-10.el5_10.s390x.rpm postgresql-contrib-8.1.23-10.el5_10.s390x.rpm postgresql-debuginfo-8.1.23-10.el5_10.s390.rpm postgresql-debuginfo-8.1.23-10.el5_10.s390x.rpm postgresql-devel-8.1.23-10.el5_10.s390.rpm postgresql-devel-8.1.23-10.el5_10.s390x.rpm postgresql-docs-8.1.23-10.el5_10.s390x.rpm postgresql-libs-8.1.23-10.el5_10.s390.rpm postgresql-libs-8.1.23-10.el5_10.s390x.rpm postgresql-pl-8.1.23-10.el5_10.s390x.rpm postgresql-python-8.1.23-10.el5_10.s390x.rpm postgresql-server-8.1.23-10.el5_10.s390x.rpm postgresql-tcl-8.1.23-10.el5_10.s390x.rpm postgresql-test-8.1.23-10.el5_10.s390x.rpm x86_64: postgresql-8.1.23-10.el5_10.x86_64.rpm postgresql-contrib-8.1.23-10.el5_10.x86_64.rpm postgresql-debuginfo-8.1.23-10.el5_10.i386.rpm postgresql-debuginfo-8.1.23-10.el5_10.x86_64.rpm postgresql-devel-8.1.23-10.el5_10.i386.rpm postgresql-devel-8.1.23-10.el5_10.x86_64.rpm postgresql-docs-8.1.23-10.el5_10.x86_64.rpm postgresql-libs-8.1.23-10.el5_10.i386.rpm postgresql-libs-8.1.23-10.el5_10.x86_64.rpm postgresql-pl-8.1.23-10.el5_10.x86_64.rpm postgresql-python-8.1.23-10.el5_10.x86_64.rpm postgresql-server-8.1.23-10.el5_10.x86_64.rpm postgresql-tcl-8.1.23-10.el5_10.x86_64.rpm postgresql-test-8.1.23-10.el5_10.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2014-0060 https://access.redhat.com/security/cve/CVE-2014-0061 https://access.redhat.com/security/cve/CVE-2014-0062 https://access.redhat.com/security/cve/CVE-2014-0063 https://access.redhat.com/security/cve/CVE-2014-0064 https://access.redhat.com/security/cve/CVE-2014-0065 https://access.redhat.com/security/cve/CVE-2014-0066 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . Recent enhancements for PostgreSQL mitigate various vulnerabilities affecting Red Hat Enterprise Linux 5, bolstering database protection.. PostgreSQL Security Update, Red Hat Advisory, Buffer Overflow Risk, Database Security Fix. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-2036-1 December 03, 2013 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: A flaw was discovered in the Linux kernel's KVM (kernel virtual machine). An administrative user in the guest OS could leverage this flaw to cause a denial of service in the host OS. (CVE-2012-2121) Multiple integer overflow flaws where discovered in the Alchemy LCD frame-buffer drivers in the Linux kernel. An unprivileged local user could exploit this flaw to gain administrative privileges. (CVE-2013-4511) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-54-386 2.6.32-54.116 linux-image-2.6.32-54-generic 2.6.32-54.116 linux-image-2.6.32-54-generic-pae 2.6.32-54.116 linux-image-2.6.32-54-ia64 2.6.32-54.116 linux-image-2.6.32-54-lpia 2.6.32-54.116 linux-image-2.6.32-54-powerpc 2.6.32-54.116 linux-image-2.6.32-54-powerpc-smp 2.6.32-54.116 linux-image-2.6.32-54-powerpc64-smp 2.6.32-54.116 linux-image-2.6.32-54-preempt 2.6.32-54.116 linux-image-2.6.32-54-server 2.6.32-54.116 linux-image-2.6.32-54-sparc64 2.6.32-54.116 linux-image-2.6.32-54-sparc64-smp 2.6.32-54.116 linux-image-2.6.32-54-versatile 2.6.32-54.116 linux-image-2.6.32-54-virtual 2.6.32-54.116 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules youmight have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-2036-1 CVE-2012-2121, CVE-2013-4511 Package Information: https://launchpad.net/ubuntu/+source/linux/2.6.32-54.116 . Debian Security Bulletin DSA-4646-1 addresses vulnerabilities in the system that may impact performance and escalate user permissions.. Kernel Security, Ubuntu Advisory, System Updates. . Severity: Critical. LinuxSecurity.com Team
A flaw in fvwm-menu-directory may permit a local attacker to execute arbitrary commands with the privileges of another user.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200611-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: fvwm: fvwm-menu-directory fvwm command injection Date: November 23, 2006 Bugs: #155078 ID: 200611-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A flaw in fvwm-menu-directory may permit a local attacker to execute arbitrary commands with the privileges of another user. Background ========= fvwm is a highly configurable virtual window manager for X11 desktops. fvwm-menu-directory allows fvwm users to browse directories from within fvwm. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-wm/fvwm < 2.5.18-r1 > = 2.5.18-r1 Description ========== Tavis Ormandy of the Gentoo Linux Security Audit Team discovered that fvwm-menu-directory does not sufficiently sanitise directory names prior to generating menus. Impact ===== A local attacker who can convince an fvwm-menu-directory user to browse a directory they control could cause fvwm commands to be executed with the privileges of the fvwm user. Fvwm commands can be used to execute arbitrary shell commands. Workaround ========= There is no known workaround at this time. Resolution ========= All fvwm users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-wm/fvwm-2.5.18-r1" References ========= [ 1] CVE-2006-5969 https://www.cve.org/CVERecord?id=CVE-2006-5969 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200611-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
eroaster does nottake appropriate security precautions when creating a temporary filefor use as a lockfile.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 366-1
Get the latest Linux and open source security news straight to your inbox.