No Image

USN-3462-1: Pacemaker vulnerabilities

2017-10-24 KENNETH 0

USN-3462-1: Pacemaker vulnerabilities Ubuntu Security Notice USN-3462-1 24th October, 2017 pacemaker vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Pacemaker. Software description pacemaker – Cluster resource manager Details Jan Pokorný and Alain Moulle discovered that Pacemaker incorrectly handledthe IPC interface. A local attacker could possibly use this issue toexecute arbitrary code with root privileges. (CVE-2016-7035) Alain Moulle discovered that Pacemaker incorrectly handled authentication.A remote attacker could possibly use this issue to shut down connections,leading to a denial of service. This issue only affected Ubuntu 16.04 LTS.(CVE-2016-7797) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: pacemaker 1.1.14-2ubuntu1.2 Ubuntu 14.04 LTS: pacemaker 1.1.10+git20130802-1ubuntu2.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, [ more… ]

No Image

USN-3454-2: libffi vulnerability

2017-10-24 KENNETH 0

USN-3454-2: libffi vulnerability Ubuntu Security Notice USN-3454-2 24th October, 2017 libffi vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary A security issue was fixed in libffi. Software description libffi – Foreign Function Interface library (development files, 32bit) Details USN-3454-1 fixed a vulnerability in libffi. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that libffi incorrectly enforced an executable stack. An attacker could possibly use this issue, in combination with another vulnerability, to facilitate executing arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: libffi6 3.0.11~rc1-5ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2017-1000376 Source: USN-3454-2: libffi vulnerability

No Image

RHEA-2017:3012-1: new packages: devtoolset-7-dwz

2017-10-24 KENNETH 0

RHEA-2017:3012-1: new packages: devtoolset-7-dwz Red Hat Enterprise Linux: New devtoolset-7-dwz packages are now available as a part of Red Hat Developer Toolset 7.0 for Red Hat Enterprise Linux. Source: RHEA-2017:3012-1: new packages: devtoolset-7-dwz

No Image

RHEA-2017:3013-1: new packages: devtoolset-7-memstomp

2017-10-24 KENNETH 0

RHEA-2017:3013-1: new packages: devtoolset-7-memstomp Red Hat Enterprise Linux: New devtoolset-7-memstomp packages are now available as a part of Red Hat Developer Toolset 7.0 for Red Hat Enterprise Linux. Source: RHEA-2017:3013-1: new packages: devtoolset-7-memstomp

No Image

RHEA-2017:3014-1: new packages: devtoolset-7-make

2017-10-24 KENNETH 0

RHEA-2017:3014-1: new packages: devtoolset-7-make Red Hat Enterprise Linux: New devtoolset-7-make packages are now available as a part of Red Hat Developer Toolset 7.0 for Red Hat Enterprise Linux. Source: RHEA-2017:3014-1: new packages: devtoolset-7-make