Ocaml Update for openSUSE

Published by Alien 0

An ocaml update has been released for openSUSE Leap 42.3 to address an integer overflow in the caml_ba_deserialize function. This allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.

Elfutils Security Update for Ubuntu

Published by Alien 0

Updated elfutils packages has been released for both Ubuntu 14.04 LTS and 16.04 LTS. This addresses an issue where elfutils could be made to crash or consume resources if it opened a specially crafted file.

Git Security Update for Arch Linux

Published by Alien 0

A git security update has been released for Arch Linux. This update address two security issues: 1) CVE-2018-11233 (information disclosure). A security issue has been found in git before 2.17.1, where the code that sanify-check paths in is_ntfs_dotgit() could have been tricked into reading random pieces of memory. 2) CVE-2018-11235 (arbitrary code execution). With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name.

Linux Mint 19 Beta released

Published by Alien 0

A beta version of the upcoming Linux Mint 19 is now available in Cinnamon, Xfce, and MATE editions. This is going to be a long term support release which will be supported until 2023

Exempi Security Update for Ubuntu

Published by Alien 0

It was discovered that Exempi incorrectly handled certain media files. If a user or automated system were tricked into opening a specially crafted file, a remote attacker could cause Exempi to hang or crash, resulting in a denial of service, or possibly execute arbitrary code. Updated packages are now available for Ubuntu Linux 14.04 LTS, 16.04 LTS, and 17.10