GNOME Online Accounts 3.24.5 released

Published by Alien 0

GNOME Online Accounts 3.24.5 has been released. GNOME Online Accounts provides interfaces so that applications and libraries in GNOME can access the user's online accounts. It has providers for Google, ownCloud, Facebook, Flickr, Windows Live, Pocket, Foursquare, Microsoft Exchange, Last.fm, IMAP/SMTP, Jabber, SIP and Kerberos.

Jruby Security Update for Debian 9

Published by Alien 0

Updated jruby packages has been released for Debian GNU/Linux 9 to address several vulnerabilities. They would allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop, write arbitrary files, or run malicious code.

Unbound Security Update for Ubuntu

Published by Alien 0

Ralph Dolmans and Karst Koymans discovered that Unbound did not properly handle certain NSEC records. An attacker could use this to to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick Unbound into accepting a NODATA proof. Updated unbound packages now available for Ubuntu 18.04 LTS, 17.10, 16.04 LTS, and 14.04 LTS

Radare2 Update for Arch Linux

Published by Alien 0

An updated radare2 package is now available for Arch Linux to address multiple issues including arbitrary code execution and denial of service.

Zziplib Security Update for openSUSE

Published by Alien 0

Update zziplib packages has been released for openSUSE Leap 42.3 to address an issue if the size of the central directory is too big

Memcached Security Update for Debian 8 and 9

Published by Alien 0

Updated memcached packages has been released for both Debian GNU/Linux 8 and 9 This update fixes three security issues in memcached: 1) Daniel Shapira reported a heap-based buffer over-read in memcached (CVE-2017-9951). 2) It was reported that memcached listens to UDP by default. A remote attacker can take advantage of it to use the memcached service as a DDoS amplifier (CVE-2018-1000115). 3) An integer overflow was reported in memcached, resulting in resource leaks, data corruption, deadlocks or crashes (CVE-2018-1000127).