LWN.net Logo

Thursday's security updates

Debian has updated libxslt (denial of service), postgresql-8.4 (guessable random numbers), and postgresql-9.1 (multiple vulnerabilities including remote database file corruption).

Mandriva has updated apache (multiple vulnerabilities), apache-mod_security (access rules bypass), arpwatch (insecure privilege dropping), and automake (code execution).

openSUSE has updated bind (12.1: multiple vulnerabilities), ruby (11.4: denial of service), dhcp (12.1, 12.2; 12.3: denial of service), nrpe (code execution), jakarta-commons-httpclient (12.2, 12.3: insecure SSL certificate checking), and jakarta-commons-httpclient3 (12.1: insecure SSL certificate checking).

Oracle has updated firefox (OL5: multiple vulnerabilities).

SUSE has updated rails (multiple vulnerabilities), rubygem-json_pure (code execution), rubygem-extlib (denial of service), rubygem-crack (denial of service), and puppet (SLE11: multiple vulnerabilities).

Ubuntu has updated Oneiric backport kernel (10.04: multiple vulnerabilities), postgresql (multiple vulnerabilities including remote database file corruption), and libav (12.04, 12.10: code execution).


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds