Red Hat Security Advisory 2016-1296-01 – OCaml is a high-level, strongly-typed, functional, and object-oriented programming language from the ML family of languages. The ocaml packages contain two batch compilers, an interactive top level system, parsing tools, a replay debugger, a documentation generator, and a comprehensive library. Security Fix: OCaml versions 4.02.3 and earlier have a runtime bug that, on 64-bit platforms, causes size arguments to internal memmove calls to be sign-extended from 32- to 64-bits before being passed to the memmove function. This leads to arguments between 2GiB and 4GiB being interpreted as larger than they are, causing a buffer overflow. Further, arguments between 4GiB and 6GiB are interpreted as 4GiB smaller than they should be, causing a possible information leak.
Monthly Archives: June 2016
Red Hat Security Advisory 2016-1329-01
Red Hat Security Advisory 2016-1329-01 – Red Hat JBoss Enterprise Application Platform is a platform for Java applications, which integrates the JBoss Application Server with JBoss Hibernate and JBoss Seam. This asynchronous patch is a security update for JGroups package in Red Hat JBoss Enterprise Application Platform 5.2. Security Fix: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Red Hat Security Advisory 2016-1331-01
Red Hat Security Advisory 2016-1331-01 – Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7. This asynchronous patch is a security update for JGroups package in Red Hat JBoss Enterprise Application Platform 6.4. Security Fix: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Red Hat Security Advisory 2016-1330-01
Red Hat Security Advisory 2016-1330-01 – Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7. This asynchronous patch is a security update for JGroups package in Red Hat JBoss Enterprise Application Platform 6.4. Security Fix: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Red Hat Security Advisory 2016-1332-01
Red Hat Security Advisory 2016-1332-01 – Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on Wildfly. This asynchronous patch is a security update for JGroups package in Red Hat JBoss Enterprise Application Platform 7.0. Security Fix: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Red Hat Security Advisory 2016-1328-01
Red Hat Security Advisory 2016-1328-01 – Red Hat JBoss Enterprise Application Platform is a platform for Java applications, which integrates the JBoss Application Server with JBoss Hibernate and JBoss Seam. This asynchronous patch is a security update for JGroups package in Red Hat JBoss Enterprise Application Platform 5.2. Security Fix: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Red Hat Security Advisory 2016-1334-01
Red Hat Security Advisory 2016-1334-01 – Red Hat JBoss Data Grid is a distributed in-memory data grid, based on Infinispan. This asynchronous patch is a security update for JGroups package in Red Hat JBoss Data Grid 6.6. Security Fix: It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Hello
HelloMy name is Angelica Michaeli am interested in having communication with you as a true friend, please write me back using my e-mail([email protected])i can also send my picture directly to you,and also tell you more about meyour new friendAngelica Michael
DSA-3606 libpdfbox-java – security update
It was discovered that pdfbox, a PDF library for Java, was susceptible
to XML External Entity attacks.
CEBA-2016:1284 CentOS 7 iscsi-initiator-utilsBugFix Update
CentOS Errata and Bugfix Advisory 2016:1284 Upstream details at : https://rhn.redhat.com/errata/RHBA-2016-1284.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 8e44f277f695473fd93e4e46f507973bb20c14a3d690493b9d006969831f5a5b iscsi-initiator-utils-6.2.0.873-33.el7_2.1.i686.rpm a7d88b6334ec1042a36046884ebe719e03b3091df515d12d067c6f64c64cfb81 iscsi-initiator-utils-6.2.0.873-33.el7_2.1.x86_64.rpm 7cae04baaf553438ace6f9701329a51abdc43528dfa2401638b2503e2b7388c5 iscsi-initiator-utils-devel-6.2.0.873-33.el7_2.1.i686.rpm 6fecadc15f8a7c8f04a3b5a2d46e7ac2b8e5f9c354735b7a0066e6df8fc7a990 iscsi-initiator-utils-devel-6.2.0.873-33.el7_2.1.x86_64.rpm af5742161fda1c7f00655a89c6c4925ac5efe6eb7c8ef9594662ddef6e08fa6a iscsi-initiator-utils-iscsiuio-6.2.0.873-33.el7_2.1.x86_64.rpm Source: 7ca5655ec1d1f797b03a756bce5708199e191f4088fa402a95525f1f9c934a19 iscsi-initiator-utils-6.2.0.873-33.el7_2.1.src.rpm