Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.


LinuxSecurity.com Feature Extras:

Know Your Enemy: Honeynets - Honeynets are an invaluable offensive security tool for learning the tactics and motives of the blackhat community and sharing the information and insights gathered. This article will explore what a Honeynet is, its value, how it works and the risks involved with deploying a Honeynet.

Decade of the RATs: Is Linux Secure? - Just recently, LinuxSecurity published a feature article exploring the rise in attacks targeting Linux, their implications for Linux users and the conclusions that can be drawn about the security of the operating system based on this disheartening trend. Now, yet another frightening attack campaign exploiting Linux has come to light.


  Debian: DSA-4658-1: webkit2gtk security updateDebian: DSA-4658-1: webkit2gtk security upda (Apr 16)
 

The following vulnerability has been discovered in the webkit2gtk web engine: CVE-2020-11793

  Debian: DSA-4657-1: git security update (Apr 14)
 

Felix Wilhelm of Google Project Zero discovered a flaw in git, a fast, scalable, distributed revision control system. With a crafted URL that contains a newline, the credential helper machinery can be fooled to return credential information for a wrong host.

  Debian: DSA-4656-1: thunderbird security update (Apr 13)
 

Multiple security issues have been found in Thunderbird which could result in denial of service or potentially the execution of arbitrary code. For the oldstable distribution (stretch), these problems have been fixed

 
  Fedora 30: nss FEDORA-2020-68ab318468Fedora 30: nss FEDORA-2020-68ab318468 (Apr 16)
 

- New Firefox and NSS upstream update - More info at https://www.mozilla.org/en-US/firefox/75.0/releasenotes/

  Fedora 30: firefox FEDORA-2020-68ab318468Fedora 30: firefox FEDORA-2020-68ab318468 (Apr 16)
 

- New Firefox and NSS upstream update - More info at https://www.mozilla.org/en-US/firefox/75.0/releasenotes/

  Fedora 31: thunderbird FEDORA-2020-b6dbdc3071Fedora 31: thunderbird FEDORA-2020-b6dbdc3071 (Apr 16)
 

Update to latest upstream version

  Fedora 30: kernel-tools FEDORA-2020-73c00eda1cFedora 30: kernel-tools FEDORA-2020-73c00eda (Apr 15)
 

The 5.5.16 stable kernel update contains a number of important fixes across the tree. ---- The 5.5.15 stable kernel update contains a number of important fixes across the tree. ---- The 5.5.13 stable kernel update contains a number of important fixes across the tree. ---- The 5.5.11 stable kernel update contains a number of important fixes across the tree.

  Fedora 30: kernel-headers FEDORA-2020-73c00eda1cFedora 30: kernel-headers FEDORA-2020-73c0 (Apr 15)
 

The 5.5.16 stable kernel update contains a number of important fixes across the tree. ---- The 5.5.15 stable kernel update contains a number of important fixes across the tree. ---- The 5.5.13 stable kernel update contains a number of important fixes across the tree. ---- The 5.5.11 stable kernel update contains a number of important fixes across the tree.

  Fedora 30: kernel FEDORA-2020-73c00eda1cFedora 30: kernel FEDORA-2020-73c00eda1c (Apr 15)
 

The 5.5.16 stable kernel update contains a number of important fixes across the tree. ---- The 5.5.15 stable kernel update contains a number of important fixes across the tree. ---- The 5.5.13 stable kernel update contains a number of important fixes across the tree. ---- The 5.5.11 stable kernel update contains a number of important fixes across the tree.

  Fedora 30: cacti FEDORA-2020-70fa57d566Fedora 30: cacti FEDORA-2020-70fa57d566 (Apr 15)
 

- Update to 1.2.11 Release notes:

  Fedora 30: cacti-spine FEDORA-2020-70fa57d566Fedora 30: cacti-spine FEDORA-2020-70fa57d566 (Apr 15)
 

- Update to 1.2.11 Release notes:

  Fedora 30: chromium FEDORA-2020-b2df49bb01Fedora 30: chromium FEDORA-2020-b2df49bb01 (Apr 15)
 

Bugfix release from Google for 80.0.3987.162. ---- Update to 80.0.3987.162. Fixes the following CVEs: * CVE-2020-6450 * CVE-2020-6451 * CVE-2020-6452

  Fedora 31: cacti-spine FEDORA-2020-c1745db1aaFedora 31: cacti-spine FEDORA-2020-c1745db1aa (Apr 15)
 

- Update to 1.2.11 Release notes:

  Fedora 31: cacti FEDORA-2020-c1745db1aaFedora 31: cacti FEDORA-2020-c1745db1aa (Apr 15)
 

- Update to 1.2.11 Release notes:

  Fedora 31: golang-github-buger-jsonparser FEDORA-2020-97e8a67945Fedora 31: golang-github-b (Apr 15)
 

Multiple bug fixes, including a fix for CVE-2020-10675 .

  Fedora 31: nrpe FEDORA-2020-c3cbce63a0 (Apr 13)
 

New upstream version, fix CVEs

  Fedora 31: php-robrichards-xmlseclibs1 FEDORA-2020-46d0f456a9 (Apr 13)
 

## 1.4.3 (12, Nov 2019) ### Security Improvements: - Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

  Fedora 31: drupal7-ckeditor FEDORA-2020-71ebbd64dc (Apr 13)
 

- https://www.drupal.org/project/ckeditor/releases/7.x-1.19 - https://www.drupal.org/sa-contrib-2020-007

  Fedora 30: nrpe FEDORA-2020-1c332effa3 (Apr 13)
 

New upstream version, fix CVEs

  Fedora 30: php-robrichards-xmlseclibs1 FEDORA-2020-1b95d7a131 (Apr 13)
 

## 1.4.3 (12, Nov 2019) ### Security Improvements: - Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465).

  Fedora 30: drupal7-ckeditor FEDORA-2020-e653bca022 (Apr 13)
 

- https://www.drupal.org/project/ckeditor/releases/7.x-1.19 - https://www.drupal.org/sa-contrib-2020-007

  Fedora 30: haproxy FEDORA-2020-16cd111544 (Apr 11)
 

Security fix for CVE-2020-11100)

  Fedora 31: nss FEDORA-2020-5967b8cd4e (Apr 9)
 

- New Firefox and NSS upstream update - More info at https://www.mozilla.org/en-US/firefox/75.0/releasenotes/

  Fedora 31: firefox FEDORA-2020-5967b8cd4e (Apr 9)
 

- New Firefox and NSS upstream update - More info at https://www.mozilla.org/en-US/firefox/75.0/releasenotes/

  Fedora 31: rubygem-puma FEDORA-2020-fd87f90634 (Apr 9)
 

Security fix for CVE-2020-5247, CVE-2020-5249

  Fedora 30: rubygem-puma FEDORA-2020-08092b4c97 (Apr 9)
 

Security fix for CVE-2020-5247, CVE-2020-5249

  Fedora 30: glibc FEDORA-2020-7f625c5ea8 (Apr 9)
 

This update incorporates fixes from the upstream glibc 2.29 stable release branch, including 3 fixes for medium severity security vulnerabilities. (CVE-2020-10029, CVE-2020-1752, CVE-2020-1751)

  Fedora 32: firefox FEDORA-2020-d3d6d60708 (Apr 9)
 

- New Firefox and NSS upstream update - More info at https://www.mozilla.org/en-US/firefox/75.0/releasenotes/

  Fedora 32: nss FEDORA-2020-d3d6d60708 (Apr 9)
 

- New Firefox and NSS upstream update - More info at https://www.mozilla.org/en-US/firefox/75.0/releasenotes/

  Fedora 32: haproxy FEDORA-2020-1f51251f01 (Apr 9)
 

Update to 2.1.4 (CVE-2010-11100, #1820200)

  Fedora 32: rubygem-puma FEDORA-2020-a3f26a9387 (Apr 9)
 

Security fix for CVE-2020-5247, CVE-2020-5249

  Fedora 32: php-symfony4 FEDORA-2020-fade6a8df7 (Apr 9)
 

**Version 4.4.7** (2020-03-30) * security #cve-2020-5255 [HttpFoundation] Do not set the default Content-Type based on the Accept header (yceruto) * security #cve-2020-5275 [Security] Fix access_control behavior with unanimous decision strategy (chalasr) * bug #36262 [DI] fix generating TypedReference from PriorityTaggedServiceTrait (nicolas-grekas) * bug #36252 [Security/Http]

 
  Gentoo: GLSA-202004-09: Chromium, Google Chrome: Multiple vulnerabilities (Apr 10)
 

Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More...]

  Gentoo: GLSA-202004-08: libssh: Denial of Service (Apr 10)
 

A vulnerability in libssh could allow a remote attacker to cause a Denial of Service condition.

 
  RedHat: RHSA-2020-1497:01 Moderate: tigervnc security updateRedHat: RHSA-2020-1497:01 Mode (Apr 16)
 

An update for tigervnc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2020-1495:01 Important: thunderbird security updateRedHat: RHSA-2020-1495:01 (Apr 16)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-1496:01 Important: thunderbird security updateRedHat: RHSA-2020-1496:01 (Apr 16)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-1493:01 Important: kernel-alt security and bug fix updateRedHat: RHSA-20 (Apr 16)
 

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-1488:01 Important: thunderbird security updateRedHat: RHSA-2020-1488:01 (Apr 16)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-1489:01 Important: thunderbird security updateRedHat: RHSA-2020-1489:01 (Apr 16)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-1486:01 Important: ipmitool security updateRedHat: RHSA-2020-1486:01 Imp (Apr 16)
 

An update for ipmitool is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-1487:01 Important: chromium-browser security updateRedHat: RHSA-2020-148 (Apr 16)
 

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-1478:01 Important: Red Hat JBoss Enterprise Application (Apr 14)
 

An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5, 6, and 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-1479:01 Important: Red Hat JBoss Enterprise Application (Apr 14)
 

An update is now available for Red Hat JBoss Enterprise Application Platform 6.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-1475:01 Moderate: Red Hat CodeReady Workspaces 2.1.0 (Apr 14)
 

Red Hat CodeReady Workspaces 2.1.0 has been released. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2020-1461:01 Important: nss-softokn security update (Apr 14)
 

An update for nss-softokn is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-1465:01 Important: kernel security, bug fix, (Apr 14)
 

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-1471:01 Low: elfutils security update (Apr 14)
 

An update for elfutils is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2020-1470:01 Low: ntp security update (Apr 14)
 

An update for ntp is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2020-1464:01 Moderate: procps-ng security update (Apr 14)
 

An update for procps-ng is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2020-1462:01 Moderate: python security update (Apr 14)
 

An update for python is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2020-1396:01 Low: OpenShift Container Platform 4.3.12 podman (Apr 14)
 

An update for podman is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2020-1473:01 Important: kernel security and bug fix update (Apr 14)
 

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

  RedHat: RHSA-2020-1460:01 Important: kernel security and bug fix update (Apr 14)
 

An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-1454:01 Important: Satellite 6.7 release. (Apr 14)
 

An update is now available for Red Hat Satellite 6.7 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-1445:01 Important: Red Hat AMQ Broker 7.4.3 release and (Apr 14)
 

Red Hat AMQ Broker 7.4.3 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-1402:01 Moderate: OpenShift Container Platform 4.2.28 (Apr 14)
 

An update for openshift-enterprise-builder-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2020-1401:01 Important: OpenShift Container Platform 4.2.28 (Apr 14)
 

Red Hat OpenShift Container Platform release 4.2.28 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-1429:01 Important: firefox security update (Apr 14)
 

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-1428:01 Moderate: Open Liberty 20.0.0.4 Runtime security (Apr 13)
 

Open Liberty 20.0.0.4 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2020-1420:01 Important: firefox security update (Apr 9)
 

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

 
  Slackware: 2020-107-01: openvpn Security UpdateSlackware: 2020-107-01: openvpn Security Up (Apr 17)
 

New openvpn packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

  Slackware: 2020-106-01: bind Security UpdateSlackware: 2020-106-01: bind Security Update (Apr 15)
 

New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

  Slackware: 2020-105-01: git Security Update (Apr 14)
 

New git packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

 
  SUSE: 2020:1023-1 moderate: freeradius-serverSUSE: 2020:1023-1 moderate: freeradius-server (Apr 17)
 

An update that solves two vulnerabilities and has one errata is now available.

  SUSE: 2020:1021-1 moderate: libqt4SUSE: 2020:1021-1 moderate: libqt4 (Apr 17)
 

An update that solves three vulnerabilities and has one errata is now available.

  SUSE: 2020:1020-1 moderate: freeradius-serverSUSE: 2020:1020-1 moderate: freeradius-server (Apr 17)
 

An update that solves two vulnerabilities and has one errata is now available.

  SUSE: 2020:1018-1 moderate: freeradius-serverSUSE: 2020:1018-1 moderate: freeradius-server (Apr 17)
 

An update that solves two vulnerabilities and has one errata is now available.

  SUSE: 2020:1009-1 moderate: quartzSUSE: 2020:1009-1 moderate: quartz (Apr 16)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:0995-1 moderate: ruby2.5SUSE: 2020:0995-1 moderate: ruby2.5 (Apr 15)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2020:0991-1 important: git (Apr 14)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:0992-1 important: git (Apr 14)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2020:0984-1 moderate: quartz (Apr 14)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:0978-1 important: MozillaFirefox (Apr 9)
 

An update that fixes 5 vulnerabilities is now available.

  SUSE: 2020:14339-1 important: MozillaFirefox (Apr 9)
 

An update that fixes 5 vulnerabilities is now available.

  SUSE: 2020:0970-1 djvulibre (Apr 9)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:0971-1 important: MozillaFirefox (Apr 9)
 

An update that fixes 5 vulnerabilities is now available.

  SUSE: 2020:0967-1 moderate: libssh (Apr 9)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:0969-1 moderate: permissions (Apr 9)
 

An update that contains security fixes can now be installed.

  SUSE: 2020:0968-1 moderate: libssh (Apr 9)
 

An update that fixes one vulnerability is now available.

 
  Ubuntu 4330-1: PHP vulnerabilitiesUbuntu 4330-1: PHP vulnerabilities (Apr 15)
 

Several security issues were fixed in PHP.

  Ubuntu 4329-1: Git vulnerability (Apr 14)
 

Git could be made to expose sensitive information.

  Ubuntu 4328-1: Thunderbird vulnerabilities (Apr 13)
 

Several security issues were fixed in Thunderbird.

  Ubuntu 0065-1: Linux kernel vulnerability (Apr 9)
 

Several security issues were fixed in the kernel.

  Ubuntu 4327-1: libssh vulnerability (Apr 9)
 

libssh could be made to crash if it received specially crafted network traffic.

 
  Debian LTS: DLA-2177-1: git security updateDebian LTS: DLA-2177-1: git security update (Apr 15)
 

Felix Wilhelm of Google Project Zero discovered a flaw in git, a fast, scalable, distributed revision control system. With a crafted URL that contains a newline, the credential helper machinery can be fooled to

  Debian LTS: DLA-2175-1: php-horde-trean security updateDebian LTS: DLA-2175-1: php-horde-t (Apr 14)
 

A directory traversal vulnerability resulting from insufficient input sanitization was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to execute code in the

  Debian LTS: DLA-2174-1: php-horde-data security updateDebian LTS: DLA-2174-1: php-horde-da (Apr 14)
 

A remote code execution vulnerability was discovered in the Horde Application Framework. An authenticated remote attacker could use this flaw to cause execution of uploaded CSV data.

  Debian LTS: DLA-2173-1: graphicsmagick security updateDebian LTS: DLA-2173-1: graphicsmagi (Apr 14)
 

A vulnerability was discovered in graphicsmagick, a collection of image processing tools, that results in a heap overflow in 32-bit applications because of a signed overflow on range check in the HuffmanDecodeImage

  Debian LTS: DLA-2171-1: ceph security update (Apr 9)
 

It was discovered that there was a header-splitting vulnerability in ceph, a distributed storage and file system. For Debian 8 "Jessie", this issue has been fixed in ceph version

 
  ArchLinux: 202004-15: chromium: arbitrary code executionArchLinux: 202004-15: chromium: ar (Apr 17)
 

The package chromium before version 81.0.4044.113-1 is vulnerable to arbitrary code execution.

  ArchLinux: 202004-14: apache: multiple issuesArchLinux: 202004-14: apache: multiple issues (Apr 17)
 

The package apache before version 2.4.43-1 is vulnerable to multiple issues including information disclosure and open redirect.

  ArchLinux: 202004-13: git: information disclosureArchLinux: 202004-13: git: information di (Apr 15)
 

The package git before version 2.26.1-1 is vulnerable to information disclosure.

  ArchLinux: 202004-12: thunderbird: multiple issues (Apr 13)
 

The package thunderbird before version 68.7.0-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

  ArchLinux: 202004-11: libssh: denial of service (Apr 10)
 

The package libssh before version 0.9.4-1 is vulnerable to denial of service.

  ArchLinux: 202004-10: wireshark-cli: arbitrary code execution (Apr 10)
 

The package wireshark-cli before version 3.2.3-1 is vulnerable to arbitrary code execution.

  ArchLinux: 202004-9: chromium: multiple issues (Apr 10)
 

The package chromium before version 81.0.4044.92-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass and insufficient validation.

  ArchLinux: 202004-8: firefox: multiple issues (Apr 10)
 

The package firefox before version 75.0-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and access restriction bypass.

  ArchLinux: 202004-7: haproxy: arbitrary code execution (Apr 10)
 

The package haproxy before version 2.1.4-1 is vulnerable to arbitrary code execution.

 
  SciLinux: SLSA-2020-1488-1 Important: thunderbird on SL6.x i386/x86_64SciLinux: SLSA-2020- (Apr 16)
 

Mozilla: Use-after-free while running the nsDocShell destructor (CVE-2020-6819) * Mozilla: Use-after-free when handling a ReadableStream (CVE-2020-6820) * Mozilla: Uninitialized memory could be read when using the WebGL copyTexSubImage method (CVE-2020-6821) * Mozilla: Memory safety bugs fixed in Firefox 75 and Firefox ESR 68.7 (CVE-2020-6825) * Mozilla: Out of bounds write in GMPDecodeDat [More...]

 
  openSUSE: 2020:0534-1: moderate: gnuhealthopenSUSE: 2020:0534-1: moderate: gnuhealth (Apr 17)
 

An update that contains security fixes can now be installed.

  openSUSE: 2020:0524-1: important: gitopenSUSE: 2020:0524-1: important: git (Apr 16)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:0523-1: moderate: ansibleopenSUSE: 2020:0523-1: moderate: ansible (Apr 16)
 

An update that solves 8 vulnerabilities and has two fixes is now available.

  openSUSE: 2020:0522-1: moderate: mp3gainopenSUSE: 2020:0522-1: moderate: mp3gain (Apr 15)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2020:0519-1: important: chromiumopenSUSE: 2020:0519-1: important: chromium (Apr 15)
 

An update that fixes 26 vulnerabilities is now available.

  openSUSE: 2020:0520-1: important: MozillaThunderbirdopenSUSE: 2020:0520-1: important: Mozi (Apr 15)
 

An update that fixes 5 vulnerabilities is now available.

  openSUSE: 2020:0513-1: moderate: ansible (Apr 12)
 

An update that solves 8 vulnerabilities and has two fixes is now available.

  openSUSE: 2020:0511-1: moderate: permissions (Apr 12)
 

An update that contains security fixes can now be installed.

  openSUSE: 2020:0512-1: important: chromium (Apr 12)
 

An update that fixes three vulnerabilities is now available.

  openSUSE: 2020:0510-1: moderate: libssh (Apr 12)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:0507-1: important: python-PyYAML (Apr 11)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:0506-1: moderate: mgetty (Apr 11)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2020:0501-1: moderate: gmp, gnutls, libnettle (Apr 11)
 

An update that solves one vulnerability and has three fixes is now available.

  openSUSE: 2020:0500-1: moderate: nagios (Apr 11)
 

An update that fixes 5 vulnerabilities is now available.

  openSUSE: 2020:0494-1: important: ceph (Apr 10)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2020:0493-1: important: MozillaFirefox (Apr 10)
 

An update that fixes 5 vulnerabilities is now available.

  openSUSE: 2020:0490-1: moderate: gnuhealth (Apr 9)
 

An update that contains security fixes can now be installed.

  openSUSE: 2020:0491-1: moderate: exim (Apr 9)
 

An update that solves one vulnerability and has one errata is now available.

 
  Mageia 2020-0175: git security updateMageia 2020-0175: git security update (Apr 16)
 

With a crafted URL that contains a newline in it, the credential helper machinery can be fooled to give credential information for a wrong host. The attack has been made impossible by forbidding a newline character in any value passed via the credential protocol (CVE-2020-5260).

  Mageia 2020-0174: chromium-browser-stable security updateMageia 2020-0174: chromium-browse (Apr 16)
 

Chromium-browser 81.0.4044.92 fixes security issues: Multiple flaws were found in the way Chromium 80.0.3987.149 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code,

  Mageia 2020-0173: golang security updateMageia 2020-0173: golang security update (Apr 15)
 

Updated golang packages fix security vulnerability: An integer overflow vulnerability was found in the Go crypto/x509 and golang.org/x/crypto/cryptobyte libraries on 32-bit architectures. A remote attacker could exploit this by supplying a crafted x.509 certificate, or

  Mageia 2020-0172: wireshark security updateMageia 2020-0172: wireshark security update (Apr 15)
 

Updated wireshark packages fix security vulnerability: The BACapp dissector could crash (CVE-2020-11647). References:

  Mageia 2020-0171: libssh security updateMageia 2020-0171: libssh security update (Apr 15)
 

Updated libssh packages fix security vulnerability: A malicious client or server could crash the counterpart implemented with libssh AES-CTR ciphers are used and don't get fully initialized. It will crash when it tries to cleanup the AES-CTR ciphers when

  Mageia 2020-0170: thunderbird security updateMageia 2020-0170: thunderbird security update (Apr 15)
 

The updated packages fix security vulnerabilities: Use-after-free while running the nsDocShell destructor. (CVE-2020-6819) Use-after-free when handling a ReadableStream. (CVE-2020-6820)

  Mageia 2020-0169: krb5-appl security updateMageia 2020-0169: krb5-appl security update (Apr 15)
 

Updated krb5-appl packages fix security vulnerability: A vulnerability was found where incorrect bounds checks in the telnet servers (telnetd) handling of short writes and urgent data, could lead to information disclosure and corruption of heap data. An unauthenticated

  Mageia 2020-0168: gnutls security updateMageia 2020-0168: gnutls security update (Apr 15)
 

Updated gnutls packages fix security vulnerability: A flaw was reported in the DTLS protocol implementation in GnuTLS. The DTLS client would not contribute any randomness to the DTLS negotiation, breaking the security guarantees of the DTLS protocol (CVE-2020-11501).

  Mageia 2020-0167: mediawiki security updateMageia 2020-0167: mediawiki security update (Apr 15)
 

Updated mediawiki packages fix security vulnerability: In MediaWiki before 1.31.7, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki

  Mageia 2020-0166: apache security updateMageia 2020-0166: apache security update (Apr 15)
 

Updated apache packages fix security vulnerabilities: In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within

  Mageia 2020-0165: tor security updateMageia 2020-0165: tor security update (Apr 15)
 

Updated tor package fixes security vulnerabilities: Tor before 0.3.5.10 allows remote attackers to cause a Denial of Service (CPU consumption) (CVE-2020-10592).

  Mageia 2020-0164: libvncserver security updateMageia 2020-0164: libvncserver security upda (Apr 15)
 

Updated libvncserver packages fix security vulnerability: In libvncserver, through libvncclient/cursor.c, there is a possibility of a heap overflow, as reported by Pavel Cheremushkin (CVE-2019-15690).