Security fix for console video game music emu vulnerability in the fully optional audacious-plugins-exotic subpackage: CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961
Monthly Archives: January 2017
audacious-3.8.2-1.fc25 audacious-plugins-3.8.2-1.fc25
Update from 3.8.1 to 3.8.2.
Also fixes console video game music emu vulnerability in the fully optional audacious-plugins-exotic subpackage: CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961
DSA-3769 libphp-swiftmailer – security update
Dawid Golunski from LegalHackers discovered that PHP Swift Mailer, a
mailing solution for PHP, did not correctly validate user input. This
allowed a remote attacker to execute arbitrary code by passing
specially formatted email addresses in specific email headers.
DSA-3770 mariadb-10.0 – security update
Several issues have been discovered in the MariaDB database server. The
vulnerabilities are addressed by upgrading MariaDB to the new upstream
version 10.0.29. Please see the MariaDB 10.0 Release Notes for further
details:
NetBSD-SA2017-001 Memory leak in connect(2)
DiskSavvy Enterprise 9.1.14 / 9.3.14 GET Buffer Overflow
This Metasploit module exploits a stack-based buffer overflow vulnerability in the web interface of DiskSavvy Enterprise versions 9.1.14 and 9.3.14, caused by improper bounds checking of the request path in HTTP GET requests sent to the built-in web server. This Metasploit module has been tested successfully on Windows XP SP3 and Windows 7 SP1.
SunOS 5.11 Remote ICMP Weakness Kernel Denial Of Service
SunOS version 5.11 remote ICMP weakness kernel denial of service exploit.
ntopng Web Interface 2.4.160627 Cross Site Request Forgery
ntopng Web Interface version 2.4.160627 suffers from a cross site request forgery token bypass vulnerability.
Gentoo Linux Security Advisory 201701-48
Gentoo Linux Security Advisory 201701-48 – Multiple vulnerabilities have been found in Quagga, the worst of which could allow remote attackers to execute arbitrary code. Versions less than 1.1.0-r2 are affected.
Red Hat Security Advisory 2017-0180-01
Red Hat Security Advisory 2017-0180-01 – The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix: It was discovered that the RMI registry and DCG implementations in the RMI component of OpenJDK performed deserialization of untrusted inputs. A remote attacker could possibly use this flaw to execute arbitrary code with the privileges of RMI registry or a Java RMI application. This issue was addressed by introducing whitelists of classes that can be deserialized by RMI registry or DCG. These whitelists can be customized using the newly introduced sun.rmi.registry.registryFilter and sun.rmi.transport.dgcFilter security properties.