DSA-4255 ant – security update

Danny Grander reported that the unzip and untar tasks in ant, a Javabased build tool like make, allow the extraction of files outside atarget directory. An attacker can take advantage of this flaw bysubmitting a specially crafted Zip or Tar archive to an ant build tooverwrite any file writable by the user running ant. More info: https://www.debian.org/security/2018/dsa-4255

DSA-4254 slurm-llnl – security update

Several vulnerabilities were discovered in the Simple Linux Utility forResource Management (SLURM), a cluster resource management and jobscheduling system. The Common Vulnerabilities and Exposures projectidentifies the following problems: More info: https://www.debian.org/security/2018/dsa-4254

vCMP vulnerability CVE-2018-5531

vCMP vulnerability CVE-2018-5531. Security Advisory. Security Advisory Description. Through undisclosed methods, adjacent ... More info: https://support.f5.com/csp/article/K64721111

RHSA-2018:2241-1: Moderate: java-1.8.0-openjdk security update

Red Hat Enterprise Linux: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux6.Red Hat Product Security has rated this update as having a security impact ofModerate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. CVE-2018-2952 More info: http://rhn.redhat.com/errata/RHSA-2018-2241.html
Translate »