No Image

RHSA-2018:3531-1: Important: thunderbird security update

2018-11-09 KENNETH 0

RHSA-2018:3531-1: Important: thunderbird security update Red Hat Enterprise Linux: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2018-12389, CVE-2018-12390, CVE-2018-12392, CVE-2018-12393 Source: RHSA-2018:3531-1: Important: thunderbird security update

No Image

USN-3813-1: pyOpenSSL vulnerabilities

2018-11-08 KENNETH 0

USN-3813-1: pyOpenSSL vulnerabilities pyopenssl vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in pyOpenSSL. Software Description pyopenssl – Python wrapper around the OpenSSL library Details It was discovered that pyOpenSSL incorrectly handled memory when handling X509 objects. A remote attacker could use this issue to cause pyOpenSSL to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-1000807) It was discovered that pyOpenSSL incorrectly handled memory when performing operations on a PKCS #12 store. A remote attacker could possibly use this issue to cause pyOpenSSL to consume resources, resulting in a denial of service. (CVE-2018-1000808) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS python-openssl – 0.15.1-2ubuntu0.2 python3-openssl – 0.15.1-2ubuntu0.2 To update your system, [ more… ]

No Image

RHSA-2018:3522-1: Important: spice-server security update

2018-11-08 KENNETH 0

RHSA-2018:3522-1: Important: spice-server security update Red Hat Enterprise Linux: An update for spice-server is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-7506 Source: RHSA-2018:3522-1: Important: spice-server security update

No Image

RHSA-2018:3521-1: Critical: java-11-openjdk security update

2018-11-08 KENNETH 0

RHSA-2018:3521-1: Critical: java-11-openjdk security update Red Hat Enterprise Linux: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2018-3136, CVE-2018-3139, CVE-2018-3149, CVE-2018-3150, CVE-2018-3169, CVE-2018-3180, CVE-2018-3183 Source: RHSA-2018:3521-1: Critical: java-11-openjdk security update

No Image

USN-3812-1: nginx vulnerabilities

2018-11-08 KENNETH 0

USN-3812-1: nginx vulnerabilities nginx vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in nginx. Software Description nginx – small, powerful, scalable web/proxy server Details It was discovered that nginx incorrectly handled the HTTP/2 implementation. A remote attacker could possibly use this issue to cause excessive memory consumption, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843) Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2 implementation. A remote attacker could possibly use this issue to cause excessive CPU usage, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16844) It was discovered that nginx incorrectly handled the ngx_http_mp4_module [ more… ]