LWN.net Logo

Security advisories for Tuesday

Security advisories for Tuesday
[Security] Posted Jul 3, 2012 17:58 UTC (Tue) by ris

CentOS has updated C5: libtiff (code execution).

Debian has updated libapache-mod-security (cross-site scripting).

Fedora has updated F17: accountsservice (file permission bypass), F16: php (multiple vulnerabilities), F16: php-eaccelerator (multiple vulnerabilities), F16: maniadrive (multiple vulnerabilities), vte (F17; F16: denial of service) and F16: boost (ordered_malloc() overflow).

openSUSE has updated kernel (multiple vulnerabilities) and chromium, v8 (multiple vulnerabilities).

Oracle has updated enterprise kernel (OL6; OL5: multiple vulnerabilities), OL6: kernel (multiple vulnerabilities), OL6: libvirt (unintended access to USB devices), OL6: libguestfs (unintended file access), OL6: rsyslog (denial of service), OL6: busybox (code execution), OL6: php-pecl-apc (cross-site scripting), OL6: 389-ds-base (denial of service), OL6: abrt, libreport, btparser, python-meh (information leak), OL6: mysql (temporary denial of service), OL6: net-snmp (denial of service), OL6: qt (multiple vulnerabilities), OL6: openssh (denial of service), OL6: openldap (denial of service), OL6: cifs-utils (file existence disclosure flaw), OL6: xorg-x11-server (xserver locking vulnerabilities), OL6: sos (privilege escalation), OL6: nss, nss-util, nspr (multiple vulnerabilities) and OL6: sblim-cim-client2 (predictable hash collisions).

Red Hat has updated libtiff (code execution).

SUSE has updated cobbler (remote code execution).

Ubuntu has updated libreoffice (code execution), openoffice.org (code execution) and nova (privilege escalation).

Comments (none posted)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds