Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.

LinuxSecurity.com Feature Extras:

Peter Smith Releases Linux Network Security Online - Thanks so much to Peter Smith for announcing on linuxsecurity.com the release of his Linux Network Security book available free online. "In 2005 I wrote a book on Linux security. 8 years later and the publisher has gone out of business. Now that I'm free from restrictions on reproducing material from the book, I have decided to make the entire book available online."

Securing a Linux Web Server - With the significant prevalence of Linux web servers globally, security is often touted as a strength of the platform for such a purpose. However, a Linux based web server is only as secure as its configuration and very often many are quite vulnerable to compromise. While specific configurations vary wildly due to environments or specific use, there are various general steps that can be taken to insure basic security considerations are in place.


(Mar 13)

Security Report Summary

(Mar 13)

Security Report Summary

(Mar 13)

Security Report Summary

(Mar 12)

Security Report Summary

(Mar 12)

Security Report Summary

(Mar 12)

Security Report Summary

(Mar 11)

Several vulnerabilities have been found in file, a file type classification tool. Aaron Reffett reported a flaw in the way the file utility determined the [More...]

(Mar 10)

Security Report Summary

(Mar 10)

Security Report Summary

(Mar 8)

Florian Weimer of the Red Hat Product Security Team discovered a heap-based buffer overflow flaw in LibYAML, a fast YAML 1.1 parser and emitter library. A remote attacker could provide a YAML document with a specially-crafted tag that, when parsed by an application using libyaml, [More...]


(Mar 13)

A vulnerability in QXmlSimpleReader class can be used to cause a Denial of Service condition.

(Mar 13)

A vulnerability in file could result in Denial of Service.

(Mar 8)

A Vulnerability in LibYAML could result in execution of arbitrary code.


Mandriva: 2014:060: imapsync (Mar 14)

Updated imapsync package fixes security vulnerabilities: Imapsync, by default, runs a release check when executed, which causes imapsync to connect to https://imapsync.lamiral.info/ and send information about the version of imapsync, the operating system and [More...]

Mandriva: 2014:059: php (Mar 14)

Multiple vulnerabilities has been discovered and corrected in php: Fixed bug #66731 (file: infinite recursion (CVE-2014-1943)). Fixed bug #66820 (out-of-bounds memory access in fileinfo [More...]

Mandriva: 2014:058: freeradius (Mar 13)

Updated freeradius package fixes security vulnerability: SSHA processing in freeradius before 2.2.3 runs into a stack-based buffer overflow in the freeradius rlm_pap module if the password source uses an unusually long hashed password (CVE-2014-2015). [More...]

Mandriva: 2014:057: mediawiki (Mar 13)

Updated mediawiki packages fix multiple vulnerabilities: MediaWiki user Michael M reported that the fix for CVE-2013-4568 allowed insertion of escaped CSS values which could pass the CSS validation checks, resulting in XSS (CVE-2013-6451). [More...]

Mandriva: 2014:056: apache-commons-fileupload (Mar 13)

Updated apache-commons-fileupload packages fix security vulnerability: It was discovered that the Apache Commons FileUpload package for Java could enter an infinite loop while processing a multipart request with a crafted Content-Type, resulting in a denial-of-service condition [More...]

Mandriva: 2014:055: owncloud (Mar 13)

Updated owncloud packages fix security vulnerabilities and bugs: Owncloud versions 5.0.15 and 6.0.2 fix several unspecified security vulnerabilities, as well as many other bugs. [More...]

Mandriva: 2014:054: otrs (Mar 13)

Updated otrs package fixes security vulnerability: An attacker could send a specially prepared HTML email to OTRS. If he can then trick an agent into following a special link to display this email, JavaScript code would be executed (CVE-2014-1695). [More...]

Mandriva: 2014:053: libssh (Mar 13)

Updated libssh package fixes security vulnerability: When using libssh before 0.6.3, a libssh-based server, when accepting a new connection, forks and the child process handles the request. The RAND_bytes() function of openssl doesn't reset its state after the [More...]

Mandriva: 2014:052: net-snmp (Mar 13)

Updated net-snmp packages fix two vulnerabilities: Remotely exploitable denial of service vulnerability in Net-SNMP, in the Linux implementation of the ICMP-MIB, making the SNMP agent vulnerable if it is making use of the ICMP-MIB table objects [More...]

Mandriva: 2014:051: file (Mar 13)

Updated file package fixes security vulnerability: It was discovered that file before 5.17 contains a flaw in the handling of indirect magic rules in the libmagic library, which leads to an infinite recursion when trying to determine the file type of certain [More...]

Mandriva: 2014:050: wireshark (Mar 10)

Multiple vulnerabilities was found and corrected in Wireshark: * The NFS dissector could crash. Discovered by Moshe Kaplan (CVE-2014-2281). [More...]

Mandriva: 2014:049: subversion (Mar 10)

A vulnerability has been discovered and corrected in subversion: The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a [More...]

Mandriva: 2014:048: gnutls (Mar 10)

Updated gnutls packages fix security vulnerability: It was discovered that GnuTLS did not correctly handle certain errors that could occur during the verification of an X.509 certificate, causing it to incorrectly report a successful verification. An attacker [More...]

Mandriva: 2014:047: postgresql (Mar 9)

Multiple vulnerabilities has been discovered and corrected in postgresql: Granting a role without ADMIN OPTION is supposed to prevent the grantee from adding or removing members from the granted role, but [More...]


Red Hat: 2014:0292-01: 389-ds-base: Important Advisory (Mar 13)

Updated 389-ds-base packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More...]

Red Hat: 2014:0293-01: udisks: Important Advisory (Mar 13)

Updated udisks packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More...]

Red Hat: 2014:0288-01: gnutls: Important Advisory (Mar 12)

Updated gnutls packages that fix one security issue are now available for Red Hat Enterprise Linux 4 Extended Life Cycle Support, Red Hat Enterprise Linux 5.3, 5.6 and 6.2 Long Life, and Red Hat Enterprise Linux 5.9, 6.3 and 6.4 Extended Update Support. [More...]

Red Hat: 2014:0285-01: kernel: Important Advisory (Mar 12)

Updated kernel packages that fix multiple security issues, several bugs, and add one enhancement are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]

Red Hat: 2014:0289-01: flash-plugin: Moderate Advisory (Mar 12)

An updated Adobe Flash Player package that fixes two security issues is now available for Red Hat Enterprise Linux 5 and 6 Supplementary. The Red Hat Security Response Team has rated this update as having Moderate [More...]

Red Hat: 2014:0284-01: kernel: Important Advisory (Mar 11)

Updated kernel packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 6.4 Extended Update Support. The Red Hat Security Response Team has rated this update as having [More...]

Red Hat: 2014:0266-01: sudo: Moderate Advisory (Mar 10)

An updated sudo package that fixes one security issue is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having Moderate [More...]


(Mar 14)

New samba packages are available for Slackware 14.0, 14.1, and -current to fix security issues. [More Info...]

(Mar 13)

New mutt packages are available for Slackware 13.37, 14.0, 14.1, and -current to fix a security issue. [More Info...]

(Mar 11)

New udisks and udisks2 packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. [More Info...]

(Mar 6)

New sudo packages are available for Slackware 13.0, 13.1, and 13.37 to fix a security issue. [More Info...]


Ubuntu: 2147-1: Mutt vulnerability (Mar 13)

The mutt mail client could be made to crash or run programs as yourlogin if it opened a specially crafted email.

Ubuntu: 2146-1: Sudo vulnerabilities (Mar 13)

Several security issues were fixed in Sudo.

Ubuntu: 2145-1: libssh vulnerability (Mar 12)

A security issue was fixed in libssh.

Ubuntu: 2143-1: cups-filters vulnerabilities (Mar 12)

cups-filters could be made to run programs as the lp user if it processed aspecially crafted file.

Ubuntu: 2144-1: CUPS vulnerabilities (Mar 12)

CUPS could be made to run programs as the lp user if it processed aspecially crafted file.

Ubuntu: 2142-1: UDisks vulnerability (Mar 10)

UDisks could be made to manipulate directories as the administrator.

Ubuntu: 2138-1: Linux kernel vulnerabilities (Mar 7)

Several security issues were fixed in the kernel.

Ubuntu: 2140-1: Linux kernel vulnerabilities (Mar 7)

Several security issues were fixed in the kernel.

Ubuntu: 2139-1: Linux kernel (OMAP4) vulnerabilities (Mar 7)

Several security issues were fixed in the kernel.

Ubuntu: 2141-1: Linux kernel (OMAP4) vulnerabilities (Mar 7)

Several security issues were fixed in the kernel.

Ubuntu: 2134-1: Linux kernel (OMAP4) vulnerabilities (Mar 7)

Several security issues were fixed in the kernel.

Ubuntu: 2137-1: Linux kernel (Saucy HWE) vulnerabilities (Mar 7)

Several security issues were fixed in the kernel.

Ubuntu: 2133-1: Linux kernel vulnerabilities (Mar 7)

Several security issues were fixed in the kernel.

Ubuntu: 2135-1: Linux kernel (Quantal HWE) vulnerabilities (Mar 7)

Several security issues were fixed in the kernel.

Ubuntu: 2136-1: Linux kernel (Raring HWE) vulnerabilities (Mar 7)

Several security issues were fixed in the kernel.

Ubuntu: 2132-1: ImageMagick vulnerabilities (Mar 6)

ImageMagick could be made to crash or run programs if it opened a speciallycrafted image file.

Ubuntu: 2130-1: Tomcat vulnerabilities (Mar 6)

Several security issues were fixed in Tomcat.

Ubuntu: 2131-1: IcedTea Web vulnerability (Mar 6)

IcedTea Web could be made to expose or alter sensitive information.

Ubuntu: 2128-1: Linux kernel vulnerabilities (Mar 6)

Several security issues were fixed in the kernel.

Ubuntu: 2129-1: Linux kernel (EC2) vulnerabilities (Mar 6)

Several security issues were fixed in the kernel.