LWN.net Logo

Thursday's security advisories

Debian has updated file (regression in previous security fix), libjakarta-poi-java (denial of service), and kernel (multiple vulnerabilities).

Fedora has updated openssl (F15: code execution) and grub2 (F16: insecure permissions in bootloader configuration).

Mandriva has updated php (2010.1 & 2011.; ES 5.0: multiple vulnerabilities) and roundcubemail (ES 5.0: multiple vulnerabilities).

openSUSE has updated cifs-utils (information leak), puppet (multiple vulnerabilities), and epiphany, libsoup (insecure SSL handling).

Red Hat has updated php (RHEL 5&6: code execution) and php53 (RHEL 5.6: code execution).

SUSE has updated java-1_5_0-ibm (SLE 10: multiple vulnerabilities), java-1_6_0-ibm (SLE 10&11: multiple vulnerabilities), and php5 (SLE 11: multiple vulnerabilities).


(Log in to post comments)

Thursday's security advisories

Posted May 10, 2012 19:32 UTC (Thu) by pranith (subscriber, #53092) [Link]

Previously:

Debian has updated icedove (regression in previous security update)

Now again:

Debian has updated file (regression in previous security fix)

Has the security patch vetting process gone awry in Debian recently?

Thursday's security advisories

Posted May 15, 2012 20:20 UTC (Tue) by ballombe (subscriber, #9523) [Link]

Sometimes it is better to introduce minor regressions than to let a vulnerability unpatched.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds