Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service, information leak
or data loss.
Monthly Archives: December 2015
Vuln: Libxml2 'parser.c' Buffer Overflow Vulnerability
Libxml2 ‘parser.c’ Buffer Overflow Vulnerability
Vuln: libxml2 'parser.c' Out of Bounds Read Multiple Information Disclosure Vulnerabilities
libxml2 ‘parser.c’ Out of Bounds Read Multiple Information Disclosure Vulnerabilities
GLSA 201512-01: Dnsmasq: Denial of Service
GLSA 201512-02: IPython: User-assisted execution of arbitrary code
DSA-3425 tryton-server – security update
Cédric Krier discovered a vulnerability in the server-side of Tryton, an
application framework written in Python. An authenticated malicious
user can write arbitrary values in record fields due missed checks of
access permissions when multiple records are written.
RHSA-2015:2658-1: Important: bind97 security update
Red Hat Enterprise Linux: Updated bind97 packages that fix one security issue are now available for
Red Hat Enterprise Linux 5.
Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-8000
RHSA-2015:2657-1: Critical: firefox security update
Red Hat Enterprise Linux: Updated firefox packages that fix multiple security issues are now
available for Red Hat Enterprise Linux 5, 6, and 7.
Red Hat Product Security has rated this update as having Critical security
impact. Common Vulnerability Scoring System (CVSS) base scores, which give
detailed severity ratings, are available for each vulnerability from the
CVE links in the References section.
CVE-2015-7201, CVE-2015-7205, CVE-2015-7210, CVE-2015-7212, CVE-2015-7213, CVE-2015-7214, CVE-2015-7222
RHSA-2015:2656-1: Important: bind security update
Red Hat Enterprise Linux: Updated bind packages that fix one security issue are now available for Red
Hat Enterprise Linux 5.
Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-8000
RHSA-2015:2655-1: Important: bind security update
Red Hat Enterprise Linux: Updated bind packages that fix one security issue are now available for Red
Hat Enterprise Linux 6 and 7.
Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-8000