The following updates has been released for Arch Linux:
Devuan GNU+Linux 2.0 ASCII Stable released
Devuan GNU+Linux 2.0 ASCII Stable, a systemd-free Debian GNU/Linux 9 fork has been released
KRB5 and Chromium Updates for Arch Linux
The following updates has been released for Arch Linux:
KDE Frameworks 5.47.0 released
KDE Frameworks 5.47.0 has been released
Libvirt, Xen, Curl and 9 more security updates for openSUSE
The following security updates has been released for openSUSE:
NVIDIA 340.107 Linux, Solaris, and FreeBSD driver
NVIDIA has released an update legacy driver for their GeForce 8 and 9 series under Linux
GnuGPG, Firefox and Libvncserver Updates for Debian
The following updates has been released for Debian GNU/Linux:
Initscripts Bug Fix Update for Oracle Linux 6
A bug fix update for initscripts for Oracle Linux 6 has been released
Gnupg2 (SSA:2018-159-01) Update for Slackware
New gnupg2 packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
MozillaFirefox, mozilla-nss Security Update for openSUSE Leap
Updated Firefox packages has been released for openSUSE Leap 42.3 and 15.0 to address a heap buffer overflow rasterizing paths in SVG with Skia
KDE Applications 18.04.2 released
KDE Applications 18.04.2 has been released
GNOME Online Accounts 3.24.5 released
GNOME Online Accounts 3.24.5 has been released. GNOME Online Accounts provides interfaces so that applications and libraries in GNOME can access the user's online accounts. It has providers for Google, ownCloud, Facebook, Flickr, Windows Live, Pocket, Foursquare, Microsoft Exchange, Last.fm, IMAP/SMTP, Jabber, SIP and Kerberos.
Jruby Security Update for Debian 9
Updated jruby packages has been released for Debian GNU/Linux 9 to address several vulnerabilities. They would allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop, write arbitrary files, or run malicious code.
Unbound Security Update for Ubuntu
Ralph Dolmans and Karst Koymans discovered that Unbound did not properly handle certain NSEC records. An attacker could use this to to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick Unbound into accepting a NODATA proof. Updated unbound packages now available for Ubuntu 18.04 LTS, 17.10, 16.04 LTS, and 14.04 LTS
Radare2 Update for Arch Linux
An updated radare2 package is now available for Arch Linux to address multiple issues including arbitrary code execution and denial of service.
MariaDB, xdg-utils and glibc Updates for openSUSE
The following updates has been released for openSUSE:
Cloud-init and Kernel Updates for Oracle Linux
The following updates has been released for Oracle Linux:
Zziplib Security Update for openSUSE
Update zziplib packages has been released for openSUSE Leap 42.3 to address an issue if the size of the central directory is too big
Memcached Security Update for Debian 8 and 9
Updated memcached packages has been released for both Debian GNU/Linux 8 and 9
This update fixes three security issues in memcached: 1) Daniel Shapira reported a heap-based buffer over-read in memcached (CVE-2017-9951). 2) It was reported that memcached listens to UDP by default. A remote attacker can take advantage of it to use the memcached service as a DDoS amplifier (CVE-2018-1000115). 3) An integer overflow was reported in memcached, resulting in resource leaks, data corruption, deadlocks or crashes (CVE-2018-1000127).
Mozilla-Firefox (SSA:2018-157-01) Update for Slackware
New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.