DSA-4286 curl – security update

Zhaoyang Wu discovered that cURL, an URL transfer library, contains abuffer overflow in the NTLM authentication code triggered by passwordsthat exceed 2GB in length on 32bit systems. More info: https://www.debian.org/security/2018/dsa-4286

DSA-4285 sympa – security update

Michael Kaczmarczik discovered a vulnerability in the web interfacetemplate editing function of Sympa, a mailing list manager. Owner andlistmasters could use this flaw to create or modify arbitrary files inthe server with privileges of sympa user or owner view list config fileseven if edit_list.conf prohibits it. More info: https://www.debian.org/security/2018/dsa-4285

DSA-4284 lcms2 – security update

Quang Nguyen discovered an integer overflow in the Little CMS 2 colourmanagement library, which could result in denial of service and potentially theexecution of arbitrary code if a malformed IT8 calibration file isprocessed. More info: https://www.debian.org/security/2018/dsa-4284

RHSA-2018:2613-1: Moderate: samba security, bug fix and enhancement update

Red Hat Enterprise Linux: Updated samba packages that fix several security issues and provide several bugfixes and an enhancement are now available for Red Hat Gluster Storage 3.4 forRed Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impact ofModerate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. CVE-2018-1050, More info: http://rhn.redhat.com/errata/RHSA-2018-2613.html
Translate »