CentOS Errata and Bugfix Advisory 2014:1356 Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-1356.html The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 3e4301b534eb11741fb80f5887918e06b0821db1f66e37fe3e957a9d5e9bf761 dhclient-4.2.5-27.el7.centos.2.x86_64.rpm 51fb0535e6774e7039ef4df7f7e75eb207d1e43e99f0eed0c8d93b8bec81ae06 dhcp-4.2.5-27.el7.centos.2.x86_64.rpm b6a505aede47fce36b74eac93f6872006a62740fc0b2cdc446479033e7cbad8d dhcp-common-4.2.5-27.el7.centos.2.x86_64.rpm 4c05a088cbf3b4863c3dc19e2cae76ed21cff85a13555d226a9fd0c6d7f9c238 dhcp-devel-4.2.5-27.el7.centos.2.i686.rpm e0237ed75f9677081fdf7c0d34790c2326b9fcd6f2a6833a4e648b28891856b0 dhcp-devel-4.2.5-27.el7.centos.2.x86_64.rpm 9558d6ddf3b9089f47b8a1c3d199c5b8dd9cdef0335004e40e9c4c6ebbce91c7 dhcp-libs-4.2.5-27.el7.centos.2.i686.rpm ef59a01c7a91817de77a0f4aa9087bcafb1061a3df8027c741b2930c41347c6c dhcp-libs-4.2.5-27.el7.centos.2.x86_64.rpm Source: 59564ace4f214466eea874f05efcd80b10db1a9c2497d4135783826d7ece57a0 dhcp-4.2.5-27.el7.centos.2.src.rpm
Category Archives: Security
Security
CVE-2014-6054 (debian_linux, libvncserver, ubuntu_linux)
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSetScaleFactor or (2) SetScale message.
Bugzilla Vulnerability Puts Bug Collections in Harm’s Way
A vulnerability in the account creation process in Bugzilla, bug-tracking software developed and licensed by Mozilla, exposes vulnerabilities collected by the system. Mozilla is expected to patch the vulnerability today.
Experts Laud Changes to iPhone, Android Encryption
The changes that both Google and Apple have made to their mobile operating systems to encrypt the data on users’ devices have generated praise from the security and privacy communities and vitriol and criticism from the law enforcement and political worlds in equal measure.
CA Technologies GNU Bash Shellshock
CA Technologies is investigating multiple GNU Bash vulnerabilities, referred to as the “Shellshock” vulnerabilities, which were publicly disclosed on September 24-27, 2014. CVE identifiers CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277, and CVE-2014-6278 have been assigned to these vulnerabilities. These vulnerabilities could allow a local or remote attacker to utilize specially crafted input to execute arbitrary commands or code.
Gentoo Linux Security Advisory 201410-01
Gentoo Linux Security Advisory 201410-1 – Multiple parsing flaws in Bash could allow remote attackers to inject code or cause a Denial of Service condition. Versions less than 4.2_p52 are affected.
Debian Security Advisory 3046-1
Debian Linux Security Advisory 3046-1 – It was reported that MediaWiki, a website engine for collaborative work, allowed to load user-created CSS on pages where user-created JavaScript is not allowed. A wiki user could be tricked into performing actions by manipulating the interface from CSS, or JavaScript code being executed from CSS, on security-wise sensitive pages like Special:Preferences and Special:UserLogin. This update removes the separation of CSS and JavaScript module allowance.
Debian Security Advisory 3045-1
Debian Linux Security Advisory 3045-1 – Several vulnerabilities were discovered in qemu, a fast processor emulator.
Debian Security Advisory 3044-1
Debian Linux Security Advisory 3044-1 – Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware.
Debian Security Advisory 3042-1
Debian Linux Security Advisory 3042-1 – Stefano Zacchiroli discovered a vulnerability in exuberant-ctags, a tool files cause ctags to enter an infinite loop until it runs out of disk space, resulting in denial of service.