No Image

RHSA-2018:0316-1: Important: httpd24-apr security update

2018-02-14 KENNETH 0

RHSA-2018:0316-1: Important: httpd24-apr security update Red Hat Enterprise Linux: An update for httpd24-apr is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-12613 Source: RHSA-2018:0316-1: Important: httpd24-apr security update

No Image

RHBA-2018:0297-1: openstack-neutron bug fix advisory

2018-02-14 KENNETH 0

RHBA-2018:0297-1: openstack-neutron bug fix advisory Red Hat Enterprise Linux: Updated OpenStack Networking packages that resolve various issues are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Source: RHBA-2018:0297-1: openstack-neutron bug fix advisory

No Image

USN-3544-2: Firefox regressions

2018-02-13 KENNETH 0

USN-3544-2: Firefox regressions Ubuntu Security Notice USN-3544-2 12th February, 2018 firefox regressions A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary USN-3544-1 caused some regressions in Firefox. Software description firefox – Mozilla Open Source web browser Details USN-3544-1 fixed vulnerabilities in Firefox. The update caused a webcompatibility regression and a tab crash during printing in somecircumstances. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, spoof the origin in audio capture prompts, trick the user in to providing HTTP credentials for another origin, spoof the addressbar contents, or execute arbitrary code. [ more… ]

No Image

USN-3568-1: WavPack vulnerabilities

2018-02-13 KENNETH 0

USN-3568-1: WavPack vulnerabilities Ubuntu Security Notice USN-3568-1 12th February, 2018 wavpack vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary WavPack could be made to crash if it opened a specially crafted file. Software description wavpack – audio codec (lossy and lossless) – encoder and decoder Details Hanno Böck discovered that WavPack incorrectly handled certainWV files. An attacker could possibly use this to cause a denialof service. This issue only affected Ubuntu 14.04 LTS and Ubuntu16.04 LTS. (CVE-2016-10169) Joonun Jang discovered that WavPack incorrectly handled certainRF64 files. An attacker could possibly use this to cause a denialof service. This issue only affected Ubuntu 17.10. (CVE-2018-6767) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libwavpack1 5.1.0-2ubuntu0.1 wavpack 5.1.0-2ubuntu0.1 Ubuntu [ more… ]

No Image

USN-3566-1: PHP vulnerabilities

2018-02-13 KENNETH 0

USN-3566-1: PHP vulnerabilities Ubuntu Security Notice USN-3566-1 12th February, 2018 php5 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in PHP. Software description php5 – HTML-embedded scripting language interpreter Details It was discovered that PHP incorrectly handled the PHAR 404 error page. Aremote attacker could possibly use this issue to conduct cross-sitescripting (XSS) attacks. (CVE-2018-5712) It was discovered that PHP incorrectly handled memory when unserializingcertain data. A remote attacker could use this issue to cause PHP to crash,resulting in a denial of service, or possibly execute arbitrary code.(CVE-2017-12933) It was discovered that PHP incorrectly handled 'front of' and 'back of'date directives. A remote attacker could possibly use this issue to obtainsensitive information. (CVE-2017-16642) Update instructions The problem can be corrected by updating your system to the following [ more… ]