No Image

RHSA-2017:2425-1: Moderate: rh-postgresql95-postgresql security update

2017-08-08 KENNETH 0

RHSA-2017:2425-1: Moderate: rh-postgresql95-postgresql security update RHN Satellite and Proxy: An update for rh-postgresql95-postgresql is now available for Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. This update applies only to Satellite 5.7 instances using either embedded or managed PostgreSQL databases. There are manual steps required in order to finish the migration from postgresql92-postgresql to rh-postgresql95-postgresql. If these steps are not undertaken, the affected Satellite will continue to use PostgreSQL 9.2. postgresql92-postgresql will be upgraded automatically to rh-postgresql95-postgresql as part of an upgrade to Satellite 5.8. CVE-2016-5423, CVE-2016-5424, CVE-2017-7484, CVE-2017-7485, CVE-2017-7486 Source: RHSA-2017:2425-1: Moderate: rh-postgresql95-postgresql security update

Windows 10 Tip: See your 3D creations take life in Remix 3D

2017-08-08 KENNETH 0

Windows 10 Tip: See your 3D creations take life in Remix 3D Last week, we announced new capabilities in Remix 3D – Parts and Remixes – an all-new way to experience the relationship between 3D content and see how it can transform and take new life when shared with a creative community. Here’s how to get started with Parts and Remixes: On any model page on Remix3D.com, you’ll see two new tabs: Parts and Remixes. Simply click on Parts and scroll down to see the individual parts that make up the model. A dog with a party hat and party favor may have three parts: the dog model, the hat model and the party favor model. But what if someone remixes that dog and adds a birthday cake? That would appear under Remixes. The Remixes tab is a way to [ more… ]

No Image

USN-3212-4: LibTIFF vulnerabilities

2017-08-08 KENNETH 0

USN-3212-4: LibTIFF vulnerabilities Ubuntu Security Notice USN-3212-4 7th August, 2017 tiff vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file. Software description tiff – Tag Image File Format (TIFF) library Details USN-3212-1 fixed several issues in LibTIFF. This updateprovides a subset of corresponding update for Ubuntu 12.04 ESM. Mei Wang discovered a multiple integer overflows in LibTIFF whichallows remote attackers to cause a denial of service (crash) orexecute arbitrary code via a crafted TIFF image, which triggersan out-of-bounds write. (CVE-2016-3945) It was discovered that LibTIFF is vulnerable to a heap bufferoverflow in the resulting in DoS or code executionvia a crafted BitsPerSample value. (CVE-2017-5225) Original advisory details: It was discovered that LibTIFF incorrectly handled [ more… ]

No Image

USN-3339-2: OpenVPN vulnerability

2017-08-08 KENNETH 0

USN-3339-2: OpenVPN vulnerability Ubuntu Security Notice USN-3339-2 7th August, 2017 openvpn vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in OpenVPN. Software description openvpn – virtual private network software Details USN-3339-1 fixed several issues in OpenVPN. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Guido Vranken discovered that OpenVPN incorrectly handled an HTTP proxy with NTLM authentication. A remote attacker could use this issue to cause OpenVPN clients to crash, resulting in a denial of service, or possibly expose sensitive memory contents. (CVE-2017-7520) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: openvpn 2.2.1-8ubuntu1.5 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the [ more… ]

No Image

USN-3379-1: Shotwell vulnerability

2017-08-08 KENNETH 0

USN-3379-1: Shotwell vulnerability Ubuntu Security Notice USN-3379-1 7th August, 2017 shotwell vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Shotwell could be made to expose sensitive information over the network. Software description shotwell – digital photo organizer Details It was discovered that Shotwell is vulnerable to an information disclosurein the web publishing plugins resulting in potential password and oauth tokenplaintext transmission. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.04: shotwell 0.22.0+git20160108.r1.f2fb1f7-0ubuntu3.1 shotwell-common 0.22.0+git20160108.r1.f2fb1f7-0ubuntu3.1 Ubuntu 16.04 LTS: shotwell 0.22.0+git20160108.r1.f2fb1f7-0ubuntu1.1 shotwell-common 0.22.0+git20160108.r1.f2fb1f7-0ubuntu1.1 Ubuntu 14.04 LTS: shotwell 0.18.0-0ubuntu4.5 shotwell-common 0.18.0-0ubuntu4.5 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-1000024 Source: USN-3379-1: Shotwell vulnerability