Red Hat Security Advisory 2016-1968-01 – This release of Red Hat JBoss BRMS 6.3.3 serves as a replacement for Red Hat JBoss BRMS 6.3.2, and includes bug fixes and enhancements, which are documented in the Release Notes of the patch linked to in the References section. Security Fix: A security flaw was found in the way Business Process Editor displays the business process details to the user. A remote, authenticated attacker with privilege to create business processes could use this flaw to conduct stored XSS attacks against other users.
Monthly Archives: September 2016
Red Hat Security Advisory 2016-1969-01
Red Hat Security Advisory 2016-1969-01 – This release of Red Hat JBoss BPM Suite 6.3.3 serves as a replacement for Red Hat JBoss BPM Suite 6.3.2, and includes bug fixes and enhancements, which are documented in the Release Notes of the patch linked to in the References section. Security Fix: A security flaw was found in the way Business Process Editor displays the business process details to the user. A remote, authenticated attacker with privilege to create business processes could use this flaw to conduct stored XSS attacks against other users.
Ubuntu Security Notice USN-3092-1
Ubuntu Security Notice 3092-1 – Stefan Metzmacher discovered that Samba incorrectly handled certain flags in SMB2/3 client connections. A remote attacker could use this issue to disable client signing and impersonate servers by performing a man in the middle attack. Samba has been updated to 4.3.11 in Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. In addition to the security fix, the updated packages contain bug fixes, new features, and possibly incompatible changes. Various other issues were also addressed.
Bugtraq: Cisco Security Advisory: Cisco IOS XE Software NAT Denial of Service Vulnerability
Cisco Security Advisory: Cisco IOS XE Software NAT Denial of Service Vulnerability
Bugtraq: Cisco Security Advisory: Cisco IOS and IOS XE Software Internet Key Exchange Version 1 Fragmentation Denial of Service Vulnerability
Cisco Security Advisory: Cisco IOS and IOS XE Software Internet Key Exchange Version 1 Fragmentation Denial of Service Vulnerability
Bugtraq: Cisco Security Advisory: Cisco IOS and IOS XE Software Multicast Routing Denial of Service Vulnerabilities
Cisco Security Advisory: Cisco IOS and IOS XE Software Multicast Routing Denial of Service Vulnerabilities
Bugtraq: Cisco Security Advisory: Cisco IOS and IOS XE Software Smart Install Memory Leak Vulnerability
Cisco Security Advisory: Cisco IOS and IOS XE Software Smart Install Memory Leak Vulnerability
RHBA-2016:1954-1: ovirt-hosted-engine-setup bug fix update for RHV 4.0.4
Red Hat Enterprise Linux: An updated ovirt-hosted-engine-setup package that fixes several bugs is now
available.
RHBA-2016:1953-1: ovirt-host-deploy bug fix update for RHV 4.0.4
Red Hat Enterprise Linux: Updated ovirt-host-deploy packages are now available.
RHBA-2016:1952-1: ovirt-log-collector bug fix update for RHV 4.0.4
Red Hat Enterprise Linux: Updated ovirt-log-collector packages that fix several bugs are now available.