RHSA-2016:0055-1: Critical: java-1.8.0-oracle security update

Red Hat Enterprise Linux: Updated java-1.8.0-oracle packages that fix several security issues are now
available for Oracle Java for Red Hat Enterprise Linux 6 and 7.

Red Hat Product Security has rated this update as having Critical security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-7575, CVE-2015-8126, CVE-2015-8472, CVE-2016-0402, CVE-2016-0448, CVE-2016-0466, CVE-2016-0475, CVE-2016-0483, CVE-2016-0494

RHSA-2016:0054-1: Important: java-1.7.0-openjdk security update

Red Hat Enterprise Linux: Updated java-1.7.0-openjdk packages that fix multiple security issues are
now available for Red Hat Enterprise Linux 5 and 7.

Red Hat Product Security has rated this update as having Important security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-4871, CVE-2015-7575, CVE-2016-0402, CVE-2016-0448, CVE-2016-0466, CVE-2016-0483, CVE-2016-0494

RHSA-2016:0053-1: Critical: java-1.7.0-openjdk security update

Red Hat Enterprise Linux: Updated java-1.7.0-openjdk packages that fix multiple security issues are
now available for Red Hat Enterprise Linux 6.

Red Hat Product Security has rated this update as having Critical security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-4871, CVE-2015-7575, CVE-2016-0402, CVE-2016-0448, CVE-2016-0466, CVE-2016-0483, CVE-2016-0494

USN-2878-1: Perl vulnerability

Ubuntu Security Notice USN-2878-1

21st January, 2016

perl vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 15.10
  • Ubuntu 15.04

Summary

Perl incorrectly handled the taint attribute.

Software description

  • perl
    – Practical Extraction and Report Language

Details

David Golden discovered that the canonpath function in the Perl File::Spec
module did not properly preserve the taint attribute. An attacker could
possibly use this issue to bypass the taint protection mechanism.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 15.10:
perl

5.20.2-6ubuntu0.1
Ubuntu 15.04:
perl

5.20.2-2ubuntu0.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2015-8607

USN-2879-1: rsync vulnerability

Ubuntu Security Notice USN-2879-1

21st January, 2016

rsync vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 15.10
  • Ubuntu 15.04
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

rsync could be made to write files outside of the expected directory.

Software description

  • rsync
    – fast, versatile, remote (and local) file-copying tool

Details

It was discovered that rsync incorrectly handled invalid filenames. A
malicious server could use this issue to write files outside of the
intended destination directory.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 15.10:
rsync

3.1.1-3ubuntu0.15.10.1
Ubuntu 15.04:
rsync

3.1.1-3ubuntu0.15.04.1
Ubuntu 14.04 LTS:
rsync

3.1.0-2ubuntu0.2
Ubuntu 12.04 LTS:
rsync

3.0.9-1ubuntu1.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2014-9512