Scientific Essential and Critical Security Patch Updates
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
perl: Integer overflow leading to buffer overflow in Perl_my_setenv() (CVE-2018-18311) SL7 x86_64 perl-5.16.3-294.el7_6.x86_64.rpm perl-Time-Piece-1.20.1-294.el7_6.x86_64.rpm perl-core-5.16.3-294.el7_6.x86_64.rpm perl-debuginfo-5.16.3-294.el7_6.i686.rpm perl-debuginfo-5.16.3-294.el7_6.x86_64.rpm perl-devel-5.16.3-294.el7_6.i686.rpm perl-devel-5.16.3-294.el7_6.x86 [More...]
libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) SL7 x86_64 libvncserver-0.9.9-13.el7_6.i686.rpm libvncserver-0.9.9-13.el7_6.x86_64.rpm libvncserver-debuginfo-0.9.9-13.el7_6.i686.rpm libvncserver-debuginfo-0.9.9-13.el7_6.x86_64.rpm libvncserver-devel-0.9.9-13.el7_6.i686.rpm [More...]
systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling (CVE-2018-15688) * systemd: stack overflow when calling syslog from a command with long cmdline (CVE-2018-16864) * systemd: stack overflow when receiving many journald entries (CVE-2018-16865) SL7 x86_64 libgudev1-219-62.el7_6.2.i686.rpm libgudev1-219-62.el7_6.2.x86_64.rpm systemd-219-62.el7_6.2.x86_6 [More...]
keepalived: Heap-based buffer overflow when parsing HTTP status codes allows for denial of service or possibly arbitrary code execution (CVE-2018-19115) SL7 x86_64 keepalived-1.3.5-8.el7_6.x86_64.rpm keepalived-debuginfo-1.3.5-8.el7_6.x86_64.rpm - Scientific Linux Development Team
ntp: Stack-based buffer overflow in ntpq and ntpdc allows denial of service or code execution (CVE-2018-12327) SL6 x86_64 ntp-4.2.6p5-15.el6_10.x86_64.rpm ntp-debuginfo-4.2.6p5-15.el6_10.x86_64.rpm ntpdate-4.2.6p5-15.el6_10.x86_64.rpm ntp-perl-4.2.6p5-15.el6_10.x86_64.rpm i386 ntp-4.2.6p5-15.el6_10.i686.rpm ntp-debuginfo-4.2.6p5-15.el6_10.i686.rpm ntpdate-4.2.6 [More...]
This update upgrades Firefox to version 60.4.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 64 and Firefox ESR 60.4 (CVE-2018-12405) * Mozilla: Memory corruption in Angle (CVE-2018-17466) * Mozilla: Use-after-free with select element (CVE-2018-18492) * Mozilla: Buffer overflow in accelerated 2D canvas with Skia (CVE-2018-18493) * Mozilla: Same-origin policy violation using location a [More...]
This update upgrades Firefox to version 60.4.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 64 and Firefox ESR 60.4 (CVE-2018-12405) * Mozilla: Memory corruption in Angle (CVE-2018-17466) * Mozilla: Use-after-free with select element (CVE-2018-18492) * Mozilla: Buffer overflow in accelerated 2D canvas with Skia (CVE-2018-18493) * Mozilla: Same-origin policy violation using location a [More...]
ghostscript: Incorrect free logic in pagedevice replacement (699664) (CVE-2018-16541) * ghostscript: Incorrect "restoration of privilege" checking when running out of stack during exception handling (CVE-2018-16802) * ghostscript: User-writable error exception table (CVE-2018-17183) * ghostscript: Saved execution stacks can leak operator arrays (incomplete fix for CVE-2018-17183) (CVE-2018- [More...]
It was discovered that the ghostscript /invalidaccess checks fail under certain conditions. An attacker could possibly exploit this to bypass the - -dSAFER protection and, for example, execute arbitrary shell commands via a specially crafted PostScript document. (CVE-2018-16509) SL6 x86_64 ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript- [More...]
ghostscript: incomplete fix for CVE-2018-16509 (CVE-2018-16863) Bug Fix(es): * Previously, the flushpage operator has been removed as part of a major clean-up of a non-standard operator. However, flushpage has been found to be used in a few specific use cases. With this update, it has been re- added to support those use cases. SL7 x86_64 ghostscript-9.07-31.el7_6.3.i686.rpm ghosts [More...]
ruby: OpenSSL::X509::Name equality check does not work correctly (CVE-2018-16395) SL7 x86_64 ruby-2.0.0.648-34.el7_6.x86_64.rpm ruby-debuginfo-2.0.0.648-34.el7_6.i686.rpm ruby-debuginfo-2.0.0.648-34.el7_6.x86_64.rpm ruby-libs-2.0.0.648-34.el7_6.i686.rpm ruby-libs-2.0.0.648-34.el7_6.x86_64.rpm rubygem-bigdecimal-1.2.0-34.el7_6.x86_64.rpm rubygem-io-console-0.4.2-3 [More...]
kernel: stack-based buffer overflow in chap_server_compute_md5() in iscsi target (CVE-2018-14633) * kernel: NULL pointer dereference in af_netlink.c:__netlink_ns_capable() allows for denial of service (CVE-2018-14646) Bug Fix(es): See the descriptions in the related Knowledge Article: SL7 x86_64 bpftool-3.10.0-957.1.3.el7.x86_64.rpm kernel-3.10.0-957.1.3.el7.x86_64.rpm kernel [More...]
systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling (CVE-2018-15688) SL7 x86_64 NetworkManager-1.12.0-8.el7_6.x86_64.rpm NetworkManager-adsl-1.12.0-8.el7_6.x86_64.rpm NetworkManager-bluetooth-1.12.0-8.el7_6.x86_64.rpm NetworkManager-debuginfo-1.12.0-8.el7_6.i686.rpm NetworkManager-debuginfo-1.12.0-8.el7_6.x86_64.rpm NetworkManager-glib-1.12.0 [More...]
ghostscript: .tempfile file permission issues (699657) (CVE-2018-15908) * ghostscript: shading_param incomplete type checking (699660) (CVE-2018-15909) * ghostscript: missing type check in type checker (699659) (CVE-2018-16511) * ghostscript: incorrect access checking in temp file handling to disclose contents of files (699658) (CVE-2018-16539) SL7 x86_64 ghostscript-9.07-31.el7_6.1. [More...]
sos-collector: incorrect permissions set on newly created files (CVE-2018-14650) This issue was discovered by Riccardo Schirone (Red Hat Product Security). SL7 noarch sos-collector-1.5-3.el7_6.noarch.rpm - Scientific Linux Development Team
fuse: bypass of the "user_allow_other" restriction when SELinux is active (CVE-2018-10906) SL7 x86_64 fuse-2.9.2-11.el7.x86_64.rpm fuse-debuginfo-2.9.2-11.el7.i686.rpm fuse-debuginfo-2.9.2-11.el7.x86_64.rpm fuse-libs-2.9.2-11.el7.i686.rpm fuse-libs-2.9.2-11.el7.x86_64.rpm fuse-devel-2.9.2-11.el7.i686.rpm fuse-devel-2.9.2-11.el7.x86_64.rpm - Scientific Linux Deve [More...]
python-paramiko: Authentication bypass in auth_handler.py (CVE-2018-1000805) SL7 noarch python-paramiko-2.1.1-9.el7.noarch.rpm python-paramiko-doc-2.1.1-9.el7.noarch.rpm python-paramiko-2.1.1-9.el7.src.rpm - Scientific Linux Development Team
wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar (CVE-2018-0494) SL7 x86_64 wget-1.14-18.el7.x86_64.rpm wget-debuginfo-1.14-18.el7.x86_64.rpm - Scientific Linux Development Team
openssl: Handling of crafted recursive ASN.1 structures can cause a stack overflow and resulting denial of service (CVE-2018-0739) SL7 x86_64 OVMF-20180508-3.gitee3198e672e2.el7.noarch.rpm - Scientific Linux Development Team
wpa_supplicant: Unauthenticated EAPOL-Key decryption in wpa_supplicant (CVE-2018-14526) SL7 x86_64 wpa_supplicant-2.6-12.el7.x86_64.rpm wpa_supplicant-debuginfo-2.6-12.el7.x86_64.rpm - Scientific Linux Development Team