LWN.net Logo

Security advisories for Tuesday

CentOS has updated libpng (C5; C4: code execution) and C4: libpng10 (code execution).

Debian has updated libarchive (arbitrary code execution).

Fedora has updated drupal7-field_permissions (F16; F15: missing permissions), F16: rocksndiamonds (arbitrary file overwrite), F16: httpd (multiple vulnerabilities), and F16: libpng (code execution).

Gentoo has updated quagga (multiple vulnerabilities).

Oracle has updated libpng (OL6; OL5; OL4: code execution).

Red Hat has updated RHEL 4,5,6: libpng (code execution), RHEL 5: samba (symbolic link vulnerability), RHEL 5: initscripts (network traffic sniffing), RHEL 5: sos (key disclosure), RHEL 5: ibutils (code execution), RHEL 5: nfs-utils (user-controlled /etc/mtab corruption), RHEL 5: sudo (group-related vulnerabilities), RHEL 5: busybox (code execution), RHEL 5: util-linux (denial of service), RHEL 5: krb5 (privilege escalation), RHEL 5: kexec-tools (information disclosure), RHEL 5: conga (cross-site scripting), RHEL 5: kernel (denial of service), RHEL 5: boost (denial of service), RHEL 5: kvm (denial of service), RHEL 5: vixie-cron (modification time changes), RHEL 5: xorg-x11 (xserver locking vulnerability), RHEL 5: cups (heap corruption), and RHEL 5: imagemagick (privilege escalation).

Scientific Linux has updated SL4,5,6: libpng (code execution).


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds