Zhaoyang Wu discovered that cURL, an URL transfer library, contains abuffer overflow in the NTLM authentication code triggered by passwordsthat exceed 2GB in length on 32bit systems.
More info:
https://www.debian.org/security/2018/dsa-4286
More info:
https://wpvulndb.com/vulnerabilities/9122
Michael Kaczmarczik discovered a vulnerability in the web interfacetemplate editing function of Sympa, a mailing list manager. Owner andlistmasters could use this flaw to create or modify arbitrary files inthe server with privileges of sympa user or owner view list config fileseven if edit_list.conf prohibits it.
More info:
https://www.debian.org/security/2018/dsa-4285
Quang Nguyen discovered an integer overflow in the Little CMS 2 colourmanagement library, which could result in denial of service and potentially theexecution of arbitrary code if a malformed IT8 calibration file isprocessed.
More info:
https://www.debian.org/security/2018/dsa-4284
Siemens Ethernet card DoS vulnerabilities CVE-2018-11451 and CVE-2018-11452. Security Advisory. Security Advisory Description. ...
More info:
https://support.f5.com/csp/article/K45062506
Red Hat Enterprise Linux: Updated samba packages that fix several security issues and provide several bugfixes and an enhancement are now available for Red Hat Gluster Storage 3.4 forRed Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impact ofModerate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. CVE-2018-1050,
More info:
http://rhn.redhat.com/errata/RHSA-2018-2613.html
Apache vulnerabilities CVE-2018-1286, CVE-2018-1294, CVE-2018-1316, CVE-2018-1319, and CVE-2018-1324. Security Advisory. ...
More info:
https://support.f5.com/csp/article/K67352212
Apache Tomcat vulnerability CVE-2018-8020. Security Advisory. Security Advisory Description. Apache Tomcat Native 1.2 ...
More info:
https://support.f5.com/csp/article/K10630493
Python vulnerability CVE-2014-9365. Security Advisory. Security Advisory Description. The HTTP clients in the (1) httplib ...
More info:
https://support.f5.com/csp/article/K11068141
OCSP responder vulnerability CVE-2018-8019. Security Advisory. Security Advisory Description. When using an OCSP responder ...
More info:
https://support.f5.com/csp/article/K20224417