DSA-4444 linux – security update

Multiple researchers have discovered vulnerabilities in the way theIntel processor designs have implemented speculative forwarding of datafilled into temporary microarchitectural structures (buffers). Thisflaw could allow an attacker controlling an unprivileged process toread sensitive information, including from the kernel and all otherprocesses running on the system or cross guest/host boundaries to readhost memory. More info: https://www.debian.org/security/2019/dsa-4444

DSA-4445 drupal7 – security update

It was discovered that incomplete validation in a Phar processinglibrary embedded in Drupal, a fully-featured content managementframework, could result in information disclosure. More info: https://www.debian.org/security/2019/dsa-4445

DSA-4443 samba – security update

Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberosextension used in Sambas Active Directory support was susceptible toman-in-the-middle attacks caused by incomplete checksum validation. More info: https://www.debian.org/security/2019/dsa-4443
Translate »