| |
Debian: DSA-3920-1: qemu security update (Jul 25) |
| |
Multiple vulnerabilities were found in in qemu, a fast processor emulator: CVE-2017-9310
|
| |
Debian: DSA-3919-1: openjdk-8 security update (Jul 25) |
| |
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in sandbox bypass, use of insecure cryptography, side channel attacks, information disclosure, the execution of arbitrary code, denial of service or
|
| |
Debian: DSA-3918-1: icedove/thunderbird security update (Jul 25) |
| |
Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. Debian follows the extended support releases (ESR) of Thunderbird.
|
| |
Debian: DSA-3904-2: bind9 regression update (Jul 23) |
| |
The security update announced as DSA-3904-1 in bind9 introduced a regression. The fix for CVE-2017-3142 broke verification of TSIG signed TCP message sequences where not all the messages contain TSIG records. This is conform to the spec and may be used in AXFR and IXFR response.
|
| |
Debian: DSA-3917-1: catdoc security update (Jul 23) |
| |
A heap-based buffer underflow flaw was discovered in catdoc, a text extractor for MS-Office files, which may lead to denial of service (application crash) or have unspecified other impact, if a specially crafted file is processed.
|
| |
Debian: DSA-3916-1: atril security update (Jul 21) |
| |
It was discovered that Atril, the MATE document viewer, made insecure use of tar when opening tar comic book archives (CBT). Opening a malicious CBT archive could result in the execution of arbitrary code. This update disables the CBT format entirely.
|
| |
Debian: DSA-3915-1: ruby-mixlib-archive security update (Jul 20) |
| |
It was discovered that ruby-mixlib-archive, a Chef Software's library used to handle various archive formats, was vulnerable to a directory traversal attack. This allowed attackers to overwrite arbitrary files by using a malicious tar archive containing ".." in its entries.
|
| |
|
| |
Fedora 25: freeradius Security Update (Jul 27) |
| |
- Upgrade to upstream v3.0.15 release. See upstream ChangeLog for details (in freeradius-doc subpackage). - Resolves: Bug#1471848 CVE-2017-10978 freeradius: Out-of-bounds read/write due to improper output buffer size check in make_secret() - Resolves: Bug#1471860 CVE-2017-10983 freeradius: Out-of-bounds read in
|
| |
Fedora 25: mingw-poppler Security Update (Jul 27) |
| |
This update fixes multiple security vulnerabilities (CVE-2017-7515, CVE-2017-9775, CVE-2017-9776, CVE-2017-9865).
|
| |
Fedora 25: minicom Security Update (Jul 27) |
| |
Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129
|
| |
Fedora 24: bind99 Security Update (Jul 27) |
| |
Fixes CVE-2017-3142 and CVE-2017-3143
|
| |
Fedora 24: dhcp Security Update (Jul 27) |
| |
Fixes CVE-2017-3142 and CVE-2017-3143
|
| |
Fedora 24: mingw-poppler Security Update (Jul 27) |
| |
This update fixes multiple security vulnerabilities (CVE-2017-7515, CVE-2017-9775, CVE-2017-9776, CVE-2017-9865).
|
| |
Fedora 24: minicom Security Update (Jul 27) |
| |
Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129
|
| |
Fedora 26: webkitgtk4 Security Update (Jul 27) |
| |
This update addresses the following vulnerabilities: * [CVE-2017-7018](https://www.cve.org/CVERecord?id=CVE-2017-7018), [CVE-2017-7030](https://www.cve.org/CVERecord?id=CVE-2017-7030), [CVE-2017-7034](https://www.cve.org/CVERecord?id=CVE-2017-7034), [CVE-2017-7037](https://www.cve.org/CVERecord?id=CVE-2017-7037),
|
| |
Fedora 26: php-symfony Security Update (Jul 27) |
| |
## 2.8.25 (2017-07-17) * security #23507 [Security] validate empty passwords again (xabbuh) * bug #23526 [HttpFoundation] Set meta refresh time to 0 in RedirectResponse content (jnvsor) * bug #23540 Disable inlining deprecated services (alekitto) * bug #23468 [DI] Handle root namespace in service definitions (ro0NL) * bug #23256 [Security] Fix authentication.failure event
|
| |
Fedora 26: freeradius Security Update (Jul 27) |
| |
- Upgrade to upstream v3.0.15 release. See upstream ChangeLog for details (in freeradius-doc subpackage). - Resolves: Bug#1471848 CVE-2017-10978 freeradius: Out-of-bounds read/write due to improper output buffer size check in make_secret() - Resolves: Bug#1471860 CVE-2017-10983 freeradius: Out-of-bounds read in
|
| |
Fedora 26: mingw-poppler Security Update (Jul 27) |
| |
This update fixes multiple security vulnerabilities (CVE-2017-7515, CVE-2017-9775, CVE-2017-9776, CVE-2017-9865).
|
| |
Fedora 26: minicom Security Update (Jul 27) |
| |
Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129
|
| |
Fedora 26: golang Security Update (Jul 27) |
| |
* Bump to 1.8.3 * Security fix for CVE-2017-8932 * add support for 28+bit OIDs in asn1
|
| |
Fedora 25: kernel Security Update (Jul 26) |
| |
The 4.11.12 update contains a number of important fixes across the tree.
|
| |
Fedora 25: java-1.8.0-openjdk Security Update (Jul 26) |
| |
Updated to latest security fxes. https://www.oracle.com/security-alerts/cpujul2017.html - search Java SE Risk Matrix (yah, href is no longer an option obviously...) Disabled autokarmatism as I need to run JDK testsuite over weekend. ---- restored support for system NSS (commented out in java.security by default)
|
| |
Fedora 24: kernel Security Update (Jul 26) |
| |
The 4.11.12 update contains a number of important fixes across the tree. ---- The 4.11.11 update contains a number of important fixes across the tree.
|
| |
Fedora 26: open-vm-tools Security Update (Jul 26) |
| |
Fix /tmp race conditions in libDeployPkg (CVE-2015-5191).
|
| |
Fedora 26: java-1.8.0-openjdk Security Update (Jul 26) |
| |
Updated to latest security fxes. https://www.oracle.com/security-alerts/cpujul2017.html - search Java SE Risk Matrix (yah, href is no longer an option obviously...) Disabled autokarmatism as I need to run JDK testsuite over weekend.
|
| |
Fedora 25: perl-XML-LibXML Security Update (Jul 25) |
| |
This release fixes a use-after-free in replaceChild() call.
|
| |
Fedora 25: qemu Security Update (Jul 25) |
| |
* CVE-2017-7718: cirrus: OOB read access issue (bz #1443443) * CVE-2016-9603: cirrus: heap buffer overflow via vnc connection (bz #1432040) * CVE-2017-7377: 9pfs: fix file descriptor leak (bz #1437872) * CVE-2017-7980: cirrus: OOB r/w access issues in bitblt (bz #1444372) * CVE-2017-8112: vmw_pvscsi: infinite loop in pvscsi_log2 (bz #1445622) * CVE-2017-8309: audio: host memory lekage via
|
| |
Fedora 24: perl-XML-LibXML Security Update (Jul 25) |
| |
This release fixes a use-after-free in replaceChild() call.
|
| |
Fedora 24: krb5 Security Update (Jul 25) |
| |
Fix CVE-2017-11368 (remote triggerable assertion failure in krb5kdc)
|
| |
Fedora 24: webkitgtk4 Security Update (Jul 25) |
| |
This update addresses the following vulnerabilities: * [CVE-2017-2538](https://www.cve.org/CVERecord?id=CVE-2017-2538) Additional fixes: * Fix web process deadlock when seeking youtube videos. * Fix blob downloads. * Improve theme rendering performance when using GTK+ >= 3.20. * Fix positioning of popup menus in Wayland. * Fix JavaScriptCore crashes on big-
|
| |
Fedora 26: subversion Security Update (Jul 25) |
| |
This update includes the latest stable release of _Apache Subversion_, version **1.9.6**. ### User-visible changes: #### Client-side bugfixes: * cp/mv: improve error message when target is an unversioned dir * merge: reduce memory usage with large amounts of mergeinfo ([issue 4667](https://issues.apache.org/jira/browse/SVN-4667)) #### Server-side
|
| |
Fedora 25: krb5 Security Update (Jul 24) |
| |
Fix CVE-2017-11368 (remote triggerable assertion failure in krb5kdc)
|
| |
Fedora 25: librsvg2 Security Update (Jul 24) |
| |
librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release-list/2017-July/msg00078.html
|
| |
Fedora 25: GraphicsMagick Security Update (Jul 24) |
| |
Security fix for CVE-2017-11403
|
| |
Fedora 25: yara Security Update (Jul 24) |
| |
bump to 3.6.3 release - bugfix CVE-2017-11328
|
| |
Fedora 25: phpldapadmin Security Update (Jul 24) |
| |
Fix CVE-2017-11107 (#1471112)
|
| |
Fedora 25: rubygem-rack-cors Security Update (Jul 24) |
| |
Security fix for CVE-2017-11173, new upstream version
|
| |
Fedora 25: nodejs Security Update (Jul 24) |
| |
[Security update](https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/)
|
| |
Fedora 24: phpldapadmin Security Update (Jul 24) |
| |
Fix CVE-2017-11107 (#1471112)
|
| |
Fedora 24: nodejs Security Update (Jul 24) |
| |
[Security update](https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/)
|
| |
Fedora 24: librsvg2 Security Update (Jul 24) |
| |
librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release-list/2017-July/msg00078.html
|
| |
Fedora 24: java-1.8.0-openjdk Security Update (Jul 24) |
| |
Updated to latest security fxes. https://www.oracle.com/security-alerts/cpujul2017.html - search Java SE Risk Matrix (yah, href is no longer an option obviously...) Disabled autokarmatism as I need to run JDK testsuite over weekend.
|
| |
Fedora 24: yara Security Update (Jul 24) |
| |
bump to 3.6.3 release - bugfix CVE-2017-11328
|
| |
Fedora 24: GraphicsMagick Security Update (Jul 24) |
| |
Security fix for CVE-2017-11403
|
| |
Fedora 26: librsvg2 Security Update (Jul 24) |
| |
librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release-list/2017-July/msg00078.html
|
| |
Fedora 26: krb5 Security Update (Jul 24) |
| |
Fix CVE-2017-11368 (remote triggerable assertion failure in krb5kdc)
|
| |
Fedora 26: yara Security Update (Jul 24) |
| |
bump to 3.6.3 release - bugfix CVE-2017-11328
|
| |
Fedora 26: phpldapadmin Security Update (Jul 24) |
| |
Fix CVE-2017-11107 (#1471112)
|
| |
Fedora 25: glpi Security Update (Jul 23) |
| |
Last upstream release (with security fixes)
|
| |
Fedora 25: kernel Security Update (Jul 23) |
| |
The 4.11.11 update contains a number of important fixes across the tree.
|
| |
Fedora 25: heimdal Security Update (Jul 23) |
| |
Update to 7.4.0 GA release (CVE-2017-11103)
|
| |
Fedora 24: qt5-qtwebengine Security Update (Jul 23) |
| |
This update updates QtWebEngine to a snapshot from the Qt 5.6 LTS (long-term support) branch. This is a snapshot of the QtWebEngine that will be included in the bugfix and security release Qt 5.6.3, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.6.2: CVE-2016-5133, CVE-2016-5147, CVE-2016-5153, CVE-2016-5155,
|
| |
Fedora 26: GraphicsMagick Security Update (Jul 23) |
| |
Security fix for CVE-2017-11403
|
| |
Fedora 26: kernel Security Update (Jul 23) |
| |
The 4.11.11 update contains a number of important fixes across the tree
|
| |
Fedora 26: perl-XML-LibXML Security Update (Jul 23) |
| |
This release fixes a use-after-free in replaceChild() call.
|
| |
Fedora 26: nodejs Security Update (Jul 23) |
| |
[Security update](https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/)
|
| |
Fedora 26: glpi Security Update (Jul 23) |
| |
Last upstream release (with security fixes)
|
| |
Fedora 26: heimdal Security Update (Jul 23) |
| |
Update to 7.4.0 GA release (CVE-2017-11103)
|
| |
Fedora 25: knot Security Update (Jul 20) |
| |
New upstream release: 2.4.5
|
| |
Fedora 25: knot-resolver Security Update (Jul 20) |
| |
Update to upstream version 1.3.1.
|
| |
Fedora 24: spice Security Update (Jul 20) |
| |
Security fix for CVE-2017-7506
|
| |
Fedora 24: knot-resolver Security Update (Jul 20) |
| |
Update to upstream version 1.3.1.
|
| |
Fedora 24: knot Security Update (Jul 20) |
| |
New upstream release: 2.4.5
|
| |
Fedora 26: knot Security Update (Jul 20) |
| |
New upstream release: 2.4.5
|
| |
Fedora 26: knot-resolver Security Update (Jul 20) |
| |
build experimental command line interface "kresc"
|
| |
|
| |
(Jul 21) |
| |
Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.
|
| |
|
| |
Slackware: 2017-205-01: tcpdump Security Update (Jul 24) |
| |
New tcpdump packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
|
| |
Slackware: 2017-202-01: seamonkey Security Update (Jul 21) |
| |
New seamonkey packages are available for Slackware 14.2 and -current to fix security issues.
|
| |
|
| |
openSUSE: 2017:1948-1: important: rubygem-puppet (Jul 24) |
| |
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
|
| |
SuSE: 2017:1946-1: important: Linux Kernel Live Patch 10 for SLE 12 SP1 (Jul 24) |
| |
An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is now available. now available.
|
| |
SuSE: 2017:1945-1: important: Linux Kernel Live Patch 20 for SLE 12 (Jul 24) |
| |
An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes is now available. is now available.
|
| |
SuSE: 2017:1944-1: important: Linux Kernel Live Patch 14 for SLE 12 SP1 (Jul 24) |
| |
An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes is now available. is now available.
|
| |
SuSE: 2017:1943-1: important: Linux Kernel Live Patch 15 for SLE 12 SP1 (Jul 24) |
| |
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
|
| |
SuSE: 2017:1941-1: important: Linux Kernel Live Patch 13 for SLE 12 SP1 (Jul 24) |
| |
An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.
|
| |
SuSE: 2017:1939-1: important: Linux Kernel Live Patch 21 for SLE 12 (Jul 24) |
| |
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
|
| |
SuSE: 2017:1937-1: important: Linux Kernel Live Patch 12 for SLE 12 SP1 (Jul 24) |
| |
An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is now available. now available.
|
| |
openSUSE: 2017:1933-1: important: evince (Jul 24) |
| |
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
|
| |
SuSE: 2017:1925-1: important: Linux Kernel Live Patch 6 for SLE 12 SP2 (Jul 21) |
| |
An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes is now available. is now available.
|
| |
SuSE: 2017:1924-1: important: Linux Kernel Live Patch 19 for SLE 12 (Jul 21) |
| |
An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.
|
| |
SuSE: 2017:1922-1: important: Linux Kernel Live Patch 18 for SLE 12 (Jul 21) |
| |
An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.
|
| |
SuSE: 2017:1923-1: important: Linux Kernel Live Patch 4 for SLE 12 SP2 (Jul 21) |
| |
An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.
|
| |
SuSE: 2017:1915-1: important: Linux Kernel Live Patch 16 for SLE 12 SP1 (Jul 20) |
| |
An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.
|
| |
SuSE: 2017:1914-1: important: Linux Kernel Live Patch 3 for SLE 12 SP2 (Jul 20) |
| |
An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.
|
| |
SuSE: 2017:1912-1: important: Linux Kernel Live Patch 22 for SLE 12 (Jul 20) |
| |
An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.
|
| |
SuSE: 2017:1913-1: important: Linux Kernel Live Patch 2 for SLE 12 SP2 (Jul 20) |
| |
An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is now available. now available.
|
| |
SuSE: 2017:1910-1: important: Linux Kernel Live Patch 8 for SLE 12 SP1 (Jul 20) |
| |
An update that solves one vulnerability and has 11 fixes is An update that solves one vulnerability and has 11 fixes is An update that solves one vulnerability and has 11 fixes is now available. now available.
|
| |
SuSE: 2017:1909-1: important: Linux Kernel Live Patch 9 for SLE 12 SP1 (Jul 20) |
| |
An update that solves one vulnerability and has 10 fixes is An update that solves one vulnerability and has 10 fixes is An update that solves one vulnerability and has 10 fixes is now available. now available.
|
| |
SuSE: 2017:1908-1: important: Linux Kernel Live Patch 0 for SLE 12 SP2 (Jul 20) |
| |
An update that solves one vulnerability and has 11 fixes is An update that solves one vulnerability and has 11 fixes is An update that solves one vulnerability and has 11 fixes is now available. now available.
|
| |
SuSE: 2017:1907-1: important: Linux Kernel Live Patch 1 for SLE 12 SP2 (Jul 20) |
| |
An update that solves one vulnerability and has 10 fixes is An update that solves one vulnerability and has 10 fixes is An update that solves one vulnerability and has 10 fixes is now available. now available.
|
| |
SuSE: 2017:1905-1: important: Linux Kernel Live Patch 16 for SLE 12 (Jul 20) |
| |
An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is now available. now available.
|
| |
SuSE: 2017:1906-1: important: Linux Kernel Live Patch 17 for SLE 12 (Jul 20) |
| |
An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.
|
| |
SuSE: 2017:1904-1: important: Linux Kernel Live Patch 7 for SLE 12 SP2 (Jul 20) |
| |
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
|
| |
SuSE: 2017:1903-1: important: Linux Kernel Live Patch 8 for SLE 12 SP2 (Jul 20) |
| |
An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.
|
| |
|
| |
Ubuntu 3366-1: OpenJDK 8 vulnerabilities (Jul 26) |
| |
Several security issues were fixed in OpenJDK 8.
|
| |
Ubuntu 3364-3: Linux kernel (AWS, GKE) vulnerabilities (Jul 25) |
| |
Several security issues were fixed in the Linux kernel.
|
| |
Ubuntu 3364-1: Linux kernel vulnerabilities (Jul 24) |
| |
Several security issues were fixed in the Linux kernel.
|
| |
Ubuntu 3364-2: Linux kernel (Xenial HWE) vulnerabilities (Jul 24) |
| |
Several security issues were fixed in the Linux kernel.
|
| |
Ubuntu 0026-1: Linux kernel vulnerability (Jul 24) |
| |
Several security issues were fixed in the kernel.
|
| |
Ubuntu 3357-2: MySQL vulnerabilities (Jul 24) |
| |
Several security issues were fixed in MySQL.
|
| |
Ubuntu 3353-4: Samba vulnerability (Jul 24) |
| |
Samba could allow unintended access to network services.
|
| |
Ubuntu 3353-3: Heimdal vulnerability (Jul 24) |
| |
Heimdal could allow unintended access to network services.
|
| |
Ubuntu 3360-2: Linux kernel (Trusty HWE) vulnerabilities (Jul 21) |
| |
Several security issues were fixed in the Linux kernel.
|
| |
Ubuntu 3361-1: Linux kernel (HWE) vulnerabilities (Jul 21) |
| |
Several security issues were fixed in the Linux kernel.
|
| |
Ubuntu 3360-1: Linux kernel vulnerabilities (Jul 21) |
| |
Several security issues were fixed in the Linux kernel.
|
| |
Ubuntu 3359-1: Linux kernel vulnerabilities (Jul 20) |
| |
Several security issues were fixed in the Linux kernel.
|
| |
Ubuntu 3358-1: Linux kernel vulnerabilities (Jul 20) |
| |
Several security issues were fixed in the Linux kernel.
|