Red Hat Enterprise Linux: Updated cman packages that fix one bug are now available for Red Hat Enterprise
Linux 5.
Monthly Archives: August 2016
RHBA-2016:1656-1: Red Hat Certification bug fix and enhancement update
Red Hat Enterprise Linux: An updated redhat-certification package that fixes several bugs and adds various
enhancements is now available for Red Hat Enterprise Linux 6 and Red Hat
Enterprise Linux 7.
RHBA-2016:1651-1: Red Hat Gluster Storage 3.1 vdsm Update
Red Hat Enterprise Linux: Updated vdsm packages that fix several bugs are now available for Red Hat
Gluster Storage 3.1.
Epic Games Forums Hacked, SQL Injection Vulnerability Blamed
A SQL injection vulnerability is being blamed in the hack of 800,000 users accounts for popular gaming forums run by Epic Games.
WordPress Mail Master 1.0 Local File Inclusion
WordPress Mail Masta plugin version 1.0 suffers from a local file inclusion vulnerability.
VideoIQ Camera Remote File Disclosure
VideoIQ Camera suffers from a file disclosure vulnerability.
Lynis Auditing Tool 2.3.3
Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.
Red Hat Security Advisory 2016-1652-01
Red Hat Security Advisory 2016-1652-01 – KVM is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm-rhev package provides the user-space component for running virtual machines using KVM in environments managed by Red Hat Enterprise Virtualization Manager. Security Fix: Quick emulator built with the virtio framework is vulnerable to an unbounded memory allocation issue. It was found that a malicious guest user could submit more requests than the virtqueue size permits. Processing a request allocates a VirtQueueElement and therefore causes unbounded memory allocation on the host controlled by the guest.
Red Hat Security Advisory 2016-1654-01
Red Hat Security Advisory 2016-1654-01 – KVM is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm-rhev package provides the user-space component for running virtual machines using KVM in environments managed by Red Hat Enterprise Virtualization Manager. Security Fix: Quick Emulator built with the Block driver for iSCSI images support is vulnerable to a heap buffer overflow issue. It could occur while processing iSCSI asynchronous I/O ioctl calls. A user inside guest could use this flaw to crash the Qemu process resulting in DoS or potentially leverage it to execute arbitrary code with privileges of the Qemu process on the host.