Difference between revisions of "Security Advisories"
(wordpress advisory) |
(→Recent Advisories: fixed chromium) |
||
Line 16: | Line 16: | ||
=== September 2016 === | === September 2016 === | ||
+ | * [03 October 2016] [https://lists.archlinux.org/pipermail/arch-security/2016-September/000729.html ASA-201610-1] {{pkg|chromium}} arbitrary code execution | ||
* [30 September 2016] [https://lists.archlinux.org/pipermail/arch-security/2016-September/000728.html ASA-201609-32] {{pkg|wordpress}} multiple issues | * [30 September 2016] [https://lists.archlinux.org/pipermail/arch-security/2016-September/000728.html ASA-201609-32] {{pkg|wordpress}} multiple issues | ||
* [30 September 2016] [https://lists.archlinux.org/pipermail/arch-security/2016-September/000727.html ASA-201609-31] {{pkg|c-ares}} arbitrary code execution | * [30 September 2016] [https://lists.archlinux.org/pipermail/arch-security/2016-September/000727.html ASA-201609-31] {{pkg|c-ares}} arbitrary code execution |
Revision as of 21:26, 3 October 2016
Security Advisories are published by the community driven Arch CVE Monitoring Team to the public arch-security list. All published advisories can be found below, however if you want to be up-to-date its recommended to subscribe to the list. All assigned CVE's are tracked at the relevant CVE page CVE, by the ACMT.
Contents
- 1 Scheduled Advisories
- 2 Recent Advisories
- 2.1 September 2016
- 2.2 August 2016
- 2.3 July 2016
- 2.4 June 2016
- 2.5 May 2016
- 2.6 April 2016
- 2.7 March 2016
- 2.8 February 2016
- 2.9 January 2016
- 2.10 December 2015
- 2.11 November 2015
- 2.12 October 2015
- 2.13 September 2015
- 2.14 August 2015
- 2.15 July 2015
- 2.16 June 2015
- 2.17 May 2015
- 2.18 Apr 2015
- 2.19 Mar 2015
- 2.20 Feb 2015
- 2.21 Jan 2015
- 2.22 Dec 2014
- 2.23 Nov 2014
- 2.24 Oct 2014
- 2.25 Sep 2014
- 3 Publishing a new advisory
Scheduled Advisories
Recent Advisories
Here is an archive of security advisories posted to the arch-security list.
September 2016
- [03 October 2016] ASA-201610-1 chromium arbitrary code execution
- [30 September 2016] ASA-201609-32 wordpress multiple issues
- [30 September 2016] ASA-201609-31 c-ares arbitrary code execution
- [28 September 2016] ASA-201609-30 openssl denial of service
- [28 September 2016] ASA-201609-29 bind denial of service
- [27 September 2016] ASA-201609-28 lib32-openssl denial of service
- [26 September 2016] ASA-201609-27 wireshark-cli denial of service
- [26 September 2016] ASA-201609-26 lib32-gnutls certificate verification bypass
- [26 September 2016] ASA-201609-25 gnutls certificate verification bypass
- [26 September 2016] ASA-201609-24 lib32-openssl multiple issues
- [26 September 2016] ASA-201609-23 openssl multiple issues
- [22 September 2016] ASA-201609-22 firefox multiple issues
- [22 September 2016] ASA-201609-21 tomcat7 proxy injection
- [22 September 2016] ASA-201609-20 irssi arbitrary code execution
- [20 September 2016] ASA-201609-19 curl denial of service
- [20 September 2016] ASA-201609-18 lib32-curl denial of service
- [20 September 2016] ASA-201609-17 lib32-jansson denial of service
- [18 September 2016] ASA-201609-16 php multiple issues
- [17 September 2016] ASA-201609-15 jansson denial of service
- [17 September 2016] ASA-201609-14 lib32-libgcrypt information disclosure
- [17 September 2016] ASA-201609-13 chromium multiple issues
- [15 September 2016] ASA-201609-12 lib32-flashplugin multiple issues
- [15 September 2016] ASA-201609-11 flashplugin multiple issues
- [14 September 2016] ASA-201609-10 mariadb multiple issues
- [13 September 2016] ASA-201609-9 powerdns denial of service
- [13 September 2016] ASA-201609-8 libtorrent-rasterbar denial of service
- [10 September 2016] ASA-201609-7 tomcat8 proxy injection
- [09 September 2016] ASA-201609-6 graphicsmagick multiple issues
- [09 September 2016] ASA-201609-5 file-roller directory traversal
- [09 September 2016] ASA-201609-4 wordpress multiple issues
- [04 September 2016] ASA-201609-3 thunderbird arbitrary code execution
- [01 September 2016] ASA-201609-2 webkit2gtk multiple issues
- [01 September 2016] ASA-201609-1 chromium multiple issues
August 2016
- [30 August 2016] ASA-201608-22 mupdf arbitrary code execution
- [30 August 2016] ASA-201608-21 mupdf arbitrary code execution
- [27 August 2016] ASA-201608-20 wireshark-cli denial of service
- [26 August 2016] ASA-201608-19 mediawiki multiple issues
- [22 August 2016] ASA-201608-18 libgcrypt information disclosure
- [21 August 2016] ASA-201608-17 linux-lts information disclosure
- [17 August 2016] ASA-201608-16 chromium multiple issues
- [17 August 2016] ASA-201608-15 linux-zen information disclosure
- [14 August 2016] ASA-201608-14 postgresql multiple issues
- [14 August 2016] ASA-201608-13 linux-grsec information disclosure
- [14 August 2016] ASA-201608-12 linux information disclosure
- [11 August 2016] ASA-201608-11 websvn cross-site scripting
- [10 August 2016] ASA-201608-10 jq arbitrary code execution
- [08 August 2016] ASA-201608-9 curl multiple issues
- [08 August 2016] ASA-201608-8 libupnp arbitrary filesystem access
- [08 August 2016] ASA-201608-7 lib32-glibc denial of service
- [08 August 2016] ASA-201608-6 glibc denial of service
- [05 August 2016] ASA-201608-5 jre7-openjdk-headless multiple issues
- [05 August 2016] ASA-201608-4 jre7-openjdk multiple issues
- [05 August 2016] ASA-201608-3 jdk7-openjdk multiple issues
- [05 August 2016] ASA-201608-2 firefox multiple issues
- [02 August 2016] ASA-201608-1 openssh information leakage
July 2016
- [30 July 2016] ASA-201607-14 libidn denial of service
- [29 July 2016] ASA-201607-13 imagemagick information leakage
- [24 July 2016] ASA-201607-12 chromium multiple issues
- [22 July 2016] ASA-201607-11 python2-django cross site scripting
- [22 July 2016] ASA-201607-10 python-django cross site scripting
- [21 July 2016] ASA-201607-9 drupal proxy injection
- [20 July 2016] ASA-201607-8 bind denial of service
- [18 July 2016] ASA-201607-7 lib32-flashplugin multiple issues
- [18 July 2016] ASA-201607-6 flashplugin multiple issues
- [17 July 2016] ASA-201607-5 gimp arbitrary code execution
- [10 July 2016] ASA-201607-4 thunderbird arbitrary code execution
- [05 July 2016] ASA-201607-3 libreoffice-fresh arbitrary code execution
- [05 July 2016] ASA-201607-2 xerces-c denial of service
- [05 July 2016] ASA-201607-1 libarchive arbitrary code execution
June 2016
- [25 June 2016] ASA-201606-25 phpmyadmin multiple issues
- [25 June 2016] ASA-201606-24 libpurple arbitrary code execution
- [25 June 2016] ASA-201606-23 libdwarf arbitrary code execution
- [25 June 2016] ASA-201606-22 xerces-c arbitrary code execution
- [25 June 2016] ASA-201606-21 vlc arbitrary code execution
- [25 June 2016] ASA-201606-20 chromium arbitrary code execution
- [20 June 2016] ASA-201606-19 wget arbitrary file upload
- [20 June 2016] ASA-201606-18 lib32-flashplugin multiple issues
- [19 June 2016] ASA-201606-17 lib32-glibc denial of service
- [19 June 2016] ASA-201606-16 glibc denial of service
- [19 June 2016] ASA-201606-15 flashplugin multiple issues
- [13 June 2016] ASA-201606-14 lib32-expat multiple issues
- [13 June 2016] ASA-201606-13 expat multiple issues
- [10 June 2016] ASA-201606-12 lib32-gnutls arbitrary file overwrite
- [10 June 2016] ASA-201606-11 haproxy denial of service
- [10 June 2016] ASA-201606-10 gnutls arbitrary file overwrite
- [8 June 2016] ASA-201606-9 qemu-arch-extra multiple issues
- [8 June 2016] ASA-201606-8 qemu multiple issues
- [8 June 2016] ASA-201606-7 firefox multiple issues
- [8 June 2016] ASA-201606-6 subversion multiple issues
- [5 June 2016] ASA-201606-5 chromium multiple issues
- [4 June 2016] ASA-201606-4 ntp distributed denial of service amplification
- [4 June 2016] ASA-201606-3 webkit2gtk arbitrary code execution
- [1 June 2016] ASA-201606-2 nginx-mainline denial of service
- [1 June 2016] ASA-201606-1 nginx denial of service
May 2016
- [28 May 2016] ASA-201605-28 chromium multiple issues
- [26 May 2016] ASA-201605-27 libxml2 multiple issues
- [24 May 2016] ASA-201605-26 libndp man-in-the-middle
- [19 May 2016] ASA-201605-25 bugzilla cross-site scripting
- [18 May 2016] ASA-201605-24 p7zip arbitrary code execution
- [18 May 2016] ASA-201605-23 lib32-expat arbitrary code execution
- [18 May 2016] ASA-201605-22 expat arbitrary code execution
- [15 May 2016] ASA-201605-21 thunderbird arbitrary code execution
- [13 May 2016] ASA-201605-20 lib32-glibc multiple issues
- [13 May 2016] ASA-201605-19 glibc multiple issues
- [12 May 2016] ASA-201605-18 lib32-flashplugin arbitrary code execution
- [12 May 2016] ASA-201605-17 libksba denial of service
- [12 May 2016] ASA-201605-16 flashplugin arbitrary code execution
- [12 May 2016] ASA-201605-15 chromium multiple issues
- [10 May 2016] ASA-201605-14 cacti sql injection
- [10 May 2016] ASA-201605-13 squid multiple issues
- [06 May 2016] ASA-201605-12 mencoder denial of service
- [06 May 2016] ASA-201605-11 mplayer denial of service
- [06 May 2016] ASA-201605-10 mercurial arbitrary code execution
- [06 May 2016] ASA-201605-9 latex2rtf arbitrary code execution
- [06 May 2016] ASA-201605-8 gd arbitrary code execution
- [05 May 2016] ASA-201605-7 chromium multiple issues
- [05 May 2016] ASA-201605-6 imagemagick arbitrary code execution
- [05 May 2016] ASA-201605-5 quassel-core denial of service
- [04 May 2016] ASA-201605-4 lib32-openssl multiple issues
- [04 May 2016] ASA-201605-3 openssl multiple issues
- [04 May 2016] ASA-201605-2 jasper multiple issues
- [04 May 2016] ASA-201605-1 imlib2 multiple issues
April 2016
- [30 April 2016] ASA-201604-15 firefox multiple issues
- [23 April 2016] ASA-201604-14 squid multiple issues
- [23 April 2016] ASA-201604-13 samba multiple issues
- [23 April 2016] ASA-201604-12 thunderbird multiple issues
- [22 April 2016] ASA-201604-11 pgpdump denial of service
- [17 April 2016] ASA-201604-10 chromium multiple issues
- [17 April 2016] ASA-201604-9 libtasn1 denial of service
- [14 April 2016] ASA-201604-8 lhasa arbitrary code execution
- [10 April 2016] ASA-201604-7 flashplugin arbitrary code execution
- [06 April 2016] ASA-201604-6 mercurial arbitrary code execution
- [04 April 2016] ASA-201604-5 optipng arbitrary code execution
- [02 April 2016] ASA-201604-4 squid denial of service
- [01 April 2016] ASA-201604-3 jre7-openjdk-headless sandbox escape
- [01 April 2016] ASA-201604-2 jre7-openjdk sandbox escape
- [01 April 2016] ASA-201604-1 jdk7-openjdk sandbox escape
March 2016
- [29 March 2016] ASA-201603-27 jre8-openjdk-headless sandbox escape
- [29 March 2016] ASA-201603-26 jre8-openjdk sandbox escape
- [29 March 2016] ASA-201603-25 jdk8-openjdk sandbox escape
- [26 March 2016] ASA-201603-24 chromium multiple issues
- [24 March 2016] ASA-201603-23 expat arbitrary code execution
- [24 March 2016] ASA-201603-22 botan multiple issues
- [20 March 2016] ASA-201603-21 thunderbird multiple issues
- [20 March 2016] ASA-201603-20 git remote command execution
- [14 March 2016] ASA-201603-19 dropbear command injection
- [12 March 2016] ASA-201603-18 pcre arbitrary code execution
- [12 March 2016] ASA-201603-17 wireshark-gtk denial of service
- [12 March 2016] ASA-201603-16 wireshark-qt denial of service
- [12 March 2016] ASA-201603-15 wireshark-cli denial of service
- [12 March 2016] ASA-201603-14 pidgin-otr arbitrary code execution
- [12 March 2016] ASA-201603-13 bind denial of service
- [11 March 2016] ASA-201603-12 openssh command injection
- [11 March 2016] ASA-201603-11 lib32-flashplugin arbitrary code execution
- [11 March 2016] ASA-201603-10 flashplugin arbitrary code execution
- [10 March 2016] ASA-201603-9 perl improper input validation
- [10 March 2016] ASA-201603-8 exim privilege escalation
- [9 March 2016] ASA-201603-7 bind denial of service
- [9 March 2016] ASA-201603-6 libotr arbitrary code execution
- [9 March 2016] ASA-201603-5 chromium multiple issues
- [9 March 2016] ASA-201603-4 firefox multiple issues
- [7 March 2016] ASA-201603-3 lib32-openssl multiple issues
- [7 March 2016] ASA-201603-2 openssl multiple issues
- [3 March 2016] ASA-201603-1 chromium multiple issues
February 2016
- [28 February 2016] ASA-201602-24 cacti SQL injection
- [28 February 2016] ASA-201602-23 lib32-glibc unbound stack usage
- [28 February 2016] ASA-201602-22 glibc unbound stack usage
- [25 February 2016] ASA-201602-21 lib32-libssh2 man-in-the-middle
- [25 February 2016] ASA-201602-20 libssh2 man-in-the-middle
- [24 February 2016] ASA-201602-19 libgcrypt secret key extraction
- [23 February 2016] ASA-201602-18 libssh man-in-the-middle
- [21 February 2016] ASA-201602-17 chromium multiple issues
- [21 February 2016] ASA-201602-16 thunderbird multiple issues
- [17 February 2016] ASA-201602-15 lib32-glibc multiple issues
- [17 February 2016] ASA-201602-14 glibc multiple issues
- [13 February 2016] ASA-201602-13 nghttp2 denial of service
- [13 February 2016] ASA-201602-12 firefox same-origin policy bypass
- [10 February 2016] ASA-201602-11 botan multiple issues
- [10 February 2016] ASA-201602-10 kscreenlocker access restriction bypass
- [6 February 2016] ASA-201602-9 lib32-libsndfile multiple issues
- [6 February 2016] ASA-201602-8 libsndfile multiple issues
- [4 February 2016] ASA-201602-7 libbsd denial of service
- [3 February 2016] ASA-201602-6 lib32-nettle improper cryptographic calculations
- [3 February 2016] ASA-201602-5 nettle improper cryptographic calculations
- [2 February 2016] ASA-201602-4 lib32-curl man-in-the-middle
- [2 February 2016] ASA-201602-3 curl man-in-the-middle
- [2 February 2016] ASA-201602-2 python2-django permission bypass
- [2 February 2016] ASA-201602-1 python-django permission bypass
January 2016
- [29 January 2016] ASA-201601-33 lib32-openssl man-in-the-middle
- [29 January 2016] ASA-201601-32 openssl man-in-the-middle
- [27 January 2016] ASA-201601-31 nginx denial of service
- [25 January 2016] ASA-201601-30 blueman privilege escalation
- [25 January 2016] ASA-201601-29 mbedtls man-in-the-middle
- [25 January 2016] ASA-201601-28 chromium multiple issues
- [25 January 2016] ASA-201601-27 privoxy denial of service
- [25 January 2016] ASA-201601-26 linux-lts privilege escalation
- [25 January 2016] ASA-201601-25 ecryptfs-utils privilege escalation
- [25 January 2016] ASA-201601-24 python2-rsa signature forgery
- [25 January 2016] ASA-201601-23 python-rsa signature forgery
- [21 January 2016] ASA-201601-22 libdwarf denial of service
- [21 January 2016] ASA-201601-21 bind denial of service
- [20 January 2016] ASA-201601-20 linux privilege escalation
- [17 January 2016] ASA-201601-19 ntp time alteration
- [17 January 2016] ASA-201601-18 roundcubemail remote code execution
- [17 January 2016] ASA-201601-17 ffmpeg information leakage
- [17 January 2016] ASA-201601-16 syncthing information leakage
- [17 January 2016] ASA-201601-15 keybase information leakage
- [17 January 2016] ASA-201601-14 hub information leakage
- [17 January 2016] ASA-201601-13 go-ipfs information leakage
- [17 January 2016] ASA-201601-12 docker information leakage
- [16 January 2016] ASA-201601-11 go information leakage
- [14 January 2016] ASA-201601-10 php multiple issues
- [14 January 2016] ASA-201601-9 openssh multiple issues
- [13 January 2016] ASA-201601-8 libxslt denial of service
- [11 January 2016] ASA-201601-7 dhcpcd denial of service
- [09 January 2016] ASA-201601-6 wireshark-qt denial of service
- [09 January 2016] ASA-201601-5 wireshark-gtk denial of service
- [09 January 2016] ASA-201601-4 wireshark-cli denial of service
- [09 January 2016] ASA-201601-3 gajim man-in-the-middle
- [09 January 2016] ASA-201601-2 wordpress cross-side scripting
- [02 January 2016] ASA-201601-1 rtmpdump multiple issues
December 2015
- [28 December 2015] ASA-201512-19 openvpn out-of-bound read
- [28 December 2015] ASA-201512-18 libpng buffer overflow
- [28 December 2015] ASA-201512-17 flashplugin, lib32-flashplugin multiple issues
- [25 December 2015] ASA-201512-16 nghttp2 use-after-free
- [25 December 2015] ASA-201512-15 mediawiki multiple issues
- [25 December 2015] ASA-201512-14 thunderbird multiple issues
- [22 December 2015] ASA-201512-13 claws-mail buffer overflow
- [17 December 2015] ASA-201512-12 python2-pyamf XML external entity injection
- [17 December 2015] ASA-201512-11 ruby unsafe tainted string usage
- [16 December 2015] ASA-201512-10 bind denial of service
- [15 December 2015] ASA-201512-9 firefox multiple issues
- [10 December 2015] ASA-201512-8 keepassx information disclosure
- [09 December 2015] ASA-201512-7 flashplugin multiple issues
- [09 December 2015] ASA-201512-6 libxml2 multiple issues
- [09 December 2015] ASA-201512-5 chromium multiple issues
- [05 December 2015] ASA-201512-4 nodejs denial of service
- [05 December 2015] ASA-201512-3 python-django python2-django information leakage
- [05 December 2015] ASA-201512-2 openssl lib32-openssl multiple issues
- [02 December 2015] ASA-201512-1 chromium multiple issues
November 2015
- [18 November 2015] ASA-201511-11 jenkins multiple issues
- [17 November 2015] ASA-201511-10 lib32-libpng multiple issues
- [17 November 2015] ASA-201511-9 libpng multiple issues
- [13 November 2015] ASA-201511-8 chromium information leakage
- [12 November 2015] ASA-201511-7 putty arbitrary code execution
- [12 November 2015] ASA-201511-6 powerdns denial of service
- [11 November 2015] ASA-201511-5 flashplugin multiple issues
- [06 November 2015] ASA-201511-4 nspr arbitrary code execution
- [06 November 2015] ASA-201511-3 nss arbitrary code execution
- [04 November 2015] ASA-201511-2 firefox multiple issues
- [03 November 2015] ASA-201511-1 unzip multiple issues
October 2015
- [30 October 2015] ASA-201510-26 mariadb denial of service
- [30 October 2015] ASA-201510-25 lldpd denial of service
- [30 October 2015] ASA-201510-24 wordpress multiple issues
- [30 October 2015] ASA-201510-23 phpmyadmin content spoofing
- [27 October 2015] ASA-201510-22 vorbis-tools denial of service
- [23 October 2015] ASA-201510-21 drupal open redirect
- [23 October 2015] ASA-201510-20 jre8-openjdk-headless multiple issues
- [23 October 2015] ASA-201510-19 jre8-openjdk multiple issues
- [23 October 2015] ASA-201510-18 jdk8-openjdk multiple issues
- [23 October 2015] ASA-201510-17 jre7-openjdk-headless multiple issues
- [23 October 2015] ASA-201510-16 jre7-openjdk multiple issues
- [23 October 2015] ASA-201510-15 jdk7-openjdk multiple issues
- [22 October 2015] ASA-201510-14 ntp multiple issues
- [19 October 2015] ASA-201510-13 spice multiple issues
- [18 October 2015] ASA-201510-12 flashplugin arbitrary code execution
- [18 October 2015] ASA-201510-11 miniupnpc arbitrary code execution
- [16 October 2015] ASA-201510-10 firefox cross-origin restriction bypass
- [15 October 2015] ASA-201510-9 mbedtls arbitrary code execution
- [14 October 2015] ASA-201510-8 chromium multiple issues
- [14 October 2015] ASA-201510-7 flashplugin multiple issues
- [10 October 2015] ASA-201510-6 gdk-pixbuf2 multiple issues
- [08 October 2015] ASA-201510-5 opensmtpd multiple issues
- [08 October 2015] ASA-201510-4 bugzilla unauthorized account creation
- [05 October 2015] ASA-201510-3 nodejs denial of service
- [05 October 2015] ASA-201510-2 hostapd denial of service
- [05 October 2015] ASA-201510-1 libunwind denial of service
September 2015
- [28 September 2015] ASA-201509-11 chromium cross-origin bypass
- [25 September 2015] ASA-201509-10 rpcbind denial of service
- [23 September 2015] ASA-201509-9 firefox multiple issues
- [22 September 2015] ASA-201509-8 flashplugin multiple issues
- [21 September 2015] ASA-201509-7 wordpress multiple issues
- [13 September 2015] ASA-201509-6 icedtea-web multiple issues
- [13 September 2015] ASA-201509-5 libvdpau lib32-libvdpau multiple issues
- [13 September 2015] ASA-201509-4 openldap denial of service
- [07 September 2015] ASA-201509-3 powerdns denial of service
- [03 September 2015] ASA-201509-2 bind denial of service
- [02 September 2015] ASA-201509-1 chromium multiple issues
August 2015
- [28 August 2015] ASA-201508-12 firefox multiple issues
- [26 August 2015] ASA-201508-11 pcre arbitrary code execution
- [26 August 2015] ASA-201508-10 jasper denial of service
- [25 August 2015] ASA-201508-9 django denial of service
- [25 August 2015] ASA-201508-8 gnutls denial of service
- [16 August 2015] ASA-201508-7 glibc denial of service
- [14 August 2015] ASA-201508-6 freeradius insufficient CRL validation
- [14 August 2015] ASA-201508-5 subversion authentication bypass
- [12 August 2015] ASA-201508-4 firefox multiple issues
- [11 August 2015] ASA-201508-3 ppp denial of service
- [07 August 2015] ASA-201508-2 wordpress multiple issues
- [07 August 2015] ASA-201508-1 firefox information leakage
July 2015
- [29 July 2015] ASA-201507-23 pacman silent downgrade
- [29 July 2015] ASA-201507-22 bind denial of service
- [29 July 2015] ASA-201507-21 qemu multiple issues
- [24 July 2015] ASA-201507-20 crypto++ private key recovery
- [24 July 2015] ASA-201507-19 libuser privilege escalation
- [23 July 2015] ASA-201507-18 chromium multiple issues
- [23 July 2015] ASA-201507-17 openssh authentication limits bypass
- [22 July 2015] ASA-201507-16 jre7-openjdk multiple issues
- [17 July 2015] ASA-201507-15 apache multiple issues
- [16 July 2015] ASA-201507-14 lib32-flashplugin arbitrary code execution
- [16 July 2015] ASA-201507-13 flashplugin arbitrary code execution
- [13 July 2015] ASA-201507-12 lib32-openssl man-in-the-middle
- [12 July 2015] ASA-201507-11 lib32-krb5 multiple issues
- [12 July 2015] ASA-201507-10 krb5 multiple issues
- [11 July 2015] ASA-201507-9 thunderbird multiple issues
- [09 July 2015] ASA-201507-8 openssl man-in-the-middle
- [08 July 2015] ASA-201507-7 flashplugin remote code execution
- [07 July 2015] ASA-201507-6 bind denial of service
- [07 July 2015] ASA-201507-5 ntp denial of service
- [04 July 2015] ASA-201507-4 openssh XSECURITY restrictions bypass
- [04 July 2015] ASA-201507-3 haproxy information leakage
- [03 July 2015] ASA-201507-2 firefox remote code execution
- [03 July 2015] ASA-201507-1 wesnoth information leakage
June 2015
- [24 June 2015] ASA-201506-5 flashplugin remote code execution
- [22 June 2015] ASA-201506-4 curl information leakage
- [12 June 2015] ASA-201506-3 openssl multiple issues
- [10 June 2015] ASA-201506-2 cups multiple issues
- [01 June 2015] ASA-201506-1 pcre buffer overflow
May 2015
- [28 May 2015] ASA-201505-20 curl information leakage
- [26 May 2015] ASA-201505-19 webkitgtk2 man-in-the-middle
- [26 May 2015] ASA-201505-18 webkitgtk man-in-the-middle
- [26 May 2015] ASA-201505-17 postgresql multiple issues
- [26 May 2015] ASA-201505-16 pgbouncer denial of service
- [26 May 2015] ASA-201505-15 nbd denial of service
- [21 May 2015] ASA-201505-14 chromium multiple issues
- [18 May 2015] ASA-201505-13 thunderbird multiple issues
- [14 May 2015] ASA-201505-12 wireshark-gtk multiple issues
- [14 May 2015] ASA-201505-11 wireshark-qt multiple issues
- [14 May 2015] ASA-201505-10 wireshark-cli multiple issues
- [14 May 2015] ASA-201505-9 qemu arbitrary code execution
- [13 May 2015] ASA-201505-8 tomcat6 denial of service
- [13 May 2015] ASA-201505-7 firefox multiple issues
- [08 May 2015] ASA-201505-6 docker multiple issues
- [08 May 2015] ASA-201505-5 libtasn1 arbitrary code execution
- [08 May 2015] ASA-201505-4 mariadb-clients multiple issues
- [08 May 2015] ASA-201505-3 mariadb multiple issues
- [03 May 2015] ASA-201505-2 clamav multiple issues
- [01 May 2015] ASA-201505-1 squid weak certificate validation
Apr 2015
- [30 Apr 2015] ASA-201504-32 perl-xml-libxml xml external entity injection
- [29 Apr 2015] ASA-201504-31 dovecot denial of service
- [29 Apr 2015] ASA-201504-30 chromium multiple issues
- [24 Apr 2015] ASA-201504-29 wpa_supplicant arbitrary code execution
- [24 Apr 2015] ASA-201504-28 curl multiple issues
- [24 Apr 2015] ASA-201504-27 powerdns-recursor denial of service
- [24 Apr 2015] ASA-201504-26 powerdns denial of service
- [23 Apr 2015] ASA-201504-25 glibc arbitrary code execution
- [22 Apr 2015] ASA-201504-24 firefox arbitrary code execution
- [20 Apr 2015] ASA-201504-23 jre8-openjdk-headless multiple issues
- [20 Apr 2015] ASA-201504-22 jre8-openjdk multiple issues
- [20 Apr 2015] ASA-201504-21 jdk8-openjdk multiple issues
- [20 Apr 2015] ASA-201504-20 tcpdump denial of service
- [18 Apr 2015] ASA-201504-19 chromium multiple issues
- [17 Apr 2015] ASA-201504-18 flashplugin multiple issues
- [17 Apr 2015] ASA-201504-17 jre7-openjdk-headless multiple issues
- [17 Apr 2015] ASA-201504-16 jre7-openjdk multiple issues
- [17 Apr 2015] ASA-201504-15 jdk7-openjdk multiple issues
- [15 Apr 2015] ASA-201504-14 php multiple issues
- [14 Apr 2015] ASA-201504-13 ruby permissive certificate matching
- [11 Apr 2015] ASA-201504-12 icecast denial of service
- [10 Apr 2015] ASA-201504-11 mediawiki multiple issues
- [09 Apr 2015] ASA-201504-10 libssh2 out-of-bounds read
- [08 Apr 2015] ASA-201504-9 chrony denial of service
- [08 Apr 2015] ASA-201504-8 ntp multiple issues
- [07 Apr 2015] ASA-201504-7 tor multiple issues
- [04 Apr 2015] ASA-201504-6 thunderbird multiple issues
- [04 Apr 2015] ASA-201504-5 java-batik xml external entity injection
- [04 Apr 2015] ASA-201504-4 firefox certificate verification bypass
- [03 Apr 2015] ASA-201504-3 libtasn1 stack overflow
- [02 Apr 2015] ASA-201504-2 chromium remote code execution
- [01 Apr 2015] ASA-201504-1 firefox multiple issues
Mar 2015
- [31 Mar 2015] ASA-201503-26 musl arbitrary code execution
- [28 Mar 2015] ASA-201503-25 php zip integer overflow
- [25 Mar 2015] ASA-201503-24 vorbis-tools denial of service
- [24 Mar 2015] ASA-201503-23 util-linux command injection
- [23 Mar 2015] ASA-201503-22 cpio directory traversal
- [21 Mar 2015] ASA-201503-21 firefox multiple issues
- [20 Mar 2015] ASA-201503-20 tcpdump multiple issues
- [20 Mar 2015] ASA-201503-19 xerces-c denial of service
- [20 Mar 2015] ASA-201503-18 drupal multiple issues
- [19 Mar 2015] ASA-201503-17 lib32-openssl multiple issues
- [19 Mar 2015] ASA-201503-16 openssl multiple issues
- [17 Mar 2015] ASA-201503-15 libxfont multiple issues
- [17 Mar 2015] ASA-201503-14 ecryptfs-utils hard-coded passphrase salt
- [17 Mar 2015] ASA-201503-13 ettercap-gtk multiple issues
- [17 Mar 2015] ASA-201503-12 ettercap multiple issues
- [16 Mar 2015] ASA-201503-11 flashplugin multiple issues
- [16 Mar 2015] ASA-201503-10 librsync checksum collision
- [15 Mar 2015] ASA-201503-9 unzip arbitrary code execution
- [12 Mar 2015] ASA-201503-8 e2fsprogs arbitrary code execution
- [11 Mar 2015] ASA-201503-7 python2-django python-django cross site scripting
- [09 Mar 2015] ASA-201503-6 mutt denial of service
- [05 Mar 2015] ASA-201503-5 chromium multiple issues
- [05 Mar 2015] ASA-201503-4 grep denial of service
- [02 Mar 2015] ASA-201503-3 lib32-elfutils directory traversal
- [02 Mar 2015] ASA-201503-2 elfutils directory traversal
- [02 Mar 2015] ASA-201503-1 putty information disclosure
Feb 2015
- [25 Feb 2015] ASA-201502-15 thunderbird multiple issues
- [25 Feb 2015] ASA-201502-14 firefox multiple issues
- [23 Feb 2015] ASA-201502-13 samba arbitrary code execution
- [17 Feb 2015] ASA-201502-12 krb5 multiple issues
- [11 Feb 2015] ASA-201502-11 xorg-server information leak and denial of service
- [10 Feb 2015] ASA-201502-10 dbus denial of service
- [09 Feb 2015] ASA-201502-9 pigz remote write to arbitrary file
- [09 Feb 2015] ASA-201502-8 glibc multiple issues
- [05 Feb 2015] ASA-201502-7 ntp multiple issues
- [05 Feb 2015] ASA-201502-6 clamav arbitrary code execution
- [05 Feb 2015] ASA-201502-5 chromium multiple issues
- [05 Feb 2015] ASA-201502-4 postgresql multiple issues
- [05 Feb 2015] ASA-201502-3 mantisbt multiple issues
- [05 Feb 2015] ASA-201502-2 flashplugin remote code execution
- [03 Feb 2015] ASA-201502-1 privoxy denial of service
Jan 2015
- [28 Jan 2015] ASA-201501-24 patch multiple issues
- [27 Jan 2015] ASA-201501-23 jasper arbitrary code execution
- [26 Jan 2015] ASA-201501-22 flashplugin multiple issues
- [25 Jan 2015] ASA-201501-21 chromium multiple issues
- [23 Jan 2015] ASA-201501-20 jre7-openjdk-headless multiple issues
- [23 Jan 2015] ASA-201501-19 jre7-openjdk multiple issues
- [23 Jan 2015] ASA-201501-18 jdk7-openjdk multiple issues
- [23 Jan 2015] ASA-201501-17 php remote code execution
- [23 Jan 2015] ASA-201501-16 jre8-openjdk-headless multiple issues
- [23 Jan 2015] ASA-201501-15 jre8-openjdk multiple issues
- [23 Jan 2015] ASA-201501-14 jdk8-openjdk multiple issues
- [20 Jan 2015] ASA-201501-13 polarssl remote code execution
- [19 Jan 2015] ASA-201501-12 libssh denial of service
- [19 Jan 2015] ASA-201501-11 tinyproxy denial of service
- [19 Jan 2015] ASA-201501-10 samba privilege elevation
- [19 Jan 2015] ASA-201501-9 curl url request injection
- [15 Jan 2015] ASA-201501-8 flashplugin multiple issues
- [14 Jan 2015] ASA-201501-7 thunderbird multiple issues
- [14 Jan 2015] ASA-201501-6 firefox multiple issues
- [14 Jan 2015] ASA-201501-5 cpio heap buffer overflow
- [13 Jan 2015] ASA-201501-4 libevent heap overflow
- [10 Jan 2015] ASA-201501-3 unzip arbitrary code execution
- [09 Jan 2015] ASA-201501-2 openssl multiple issues
- [07 Jan 2015] ASA-201501-1 imagemagick multiple issues
Dec 2014
- [22 Dec 2014] ASA-201412-24 ntp multiple issues
- [18 Dec 2014] ASA-201412-23 php use after free
- [18 Dec 2014] ASA-201412-22 jasper arbitrary code execution
- [18 Dec 2014] ASA-201412-21 glibc arbitrary code execution
- [16 Dec 2014] ASA-201412-20 unrtf arbitrary code execution
- [16 Dec 2014] ASA-201412-19 dokuwiki cross-site scripting
- [16 Dec 2014] ASA-201412-18 nss signature forgery
- [16 Dec 2014] ASA-201412-17 subversion denial of service
- [15 Dec 2014] ASA-201412-16 docker multiple issues
- [15 Dec 2014] ASA-201412-15 python2 multiple issues
- [12 Dec 2014] ASA-201412-14 xorg-server multiple issues
- [12 Dec 2014] ASA-201412-13 flashplugin multiple issues
- [12 Dec 2014] ASA-201412-12 nvidia arbitrary code execution
- [12 Dec 2014] ASA-201412-11 nvidia-340xx arbitrary code execution
- [12 Dec 2014] ASA-201412-10 nvidia-304xx arbitrary code execution
- [09 Dec 2014] ASA-201412-9 powerdns-recursor denial of service
- [09 Dec 2014] ASA-201412-8 unbound denial of service
- [08 Dec 2014] ASA-201412-7 bind denial of service
- [08 Dec 2014] ASA-201412-6 mantisbt multiple issues
- [04 Dec 2014] ASA-201412-5 antiword buffer overflow
- [03 Dec 2014] ASA-201412-4 graphviz format string vulnerability
- [03 Dec 2014] ASA-201412-3 firefox multiple issues
- [02 Dec 2014] ASA-201412-2 openvpn denial of service
- [01 Dec 2014] ASA-201412-1 gnupg denial of service
Nov 2014
- [28 Nov 2014] ASA-201411-31 libksba denial of service
- [28 Nov 2014] ASA-201411-32 icecast information leak
- [28 Nov 2014] ASA-201411-33 libjpeg-turbo denial of service
- [26 Nov 2014] ASA-201411-30 flac arbitrary code execution
- [26 Nov 2014] ASA-201411-29 pcre heap buffer overflow
- [23 Nov 2014] ASA-201411-28 dbus denial of service
- [21 Nov 2014] ASA-201411-27 glibc command execution
- [20 Nov 2014] ASA-201411-26 chromium multiple issues
- [20 Nov 2014] ASA-201411-25 drupal session hijacking and denial of service
- [20 Nov 2014] ASA-201411-24 wireshark-qt denial of service
- [20 Nov 2014] ASA-201411-23 wireshark-gtk denial of service
- [20 Nov 2014] ASA-201411-22 wireshark-cli denial of service
- [20 Nov 2014] ASA-201411-21 clamav denial of service
- [19 Nov 2014] ASA-201411-20 avr-binutils multiple issues
- [19 Nov 2014] ASA-201411-19 mingw-w64-binutils multiple issues
- [19 Nov 2014] ASA-201411-18 arm-none-eabi-binutils multiple issues
- [19 Nov 2014] ASA-201411-17 binutils multiple issues
- [17 Nov 2014] ASA-201411-16 ruby denial of service
- [17 Nov 2014] ASA-201411-15 linux-lts local denial of service, privilege escalation
- [17 Nov 2014] ASA-201411-14 linux local denial of service, privilege escalation
- [13 Nov 2014] ASA-201411-13 php denial of service
- [13 Nov 2014] ASA-201411-12 imagemagick denial of service
- [13 Nov 2014] ASA-201411-11 flashplugin remote code execution
- [12 Nov 2014] ASA-201411-10 gnutls out-of-bounds memory write
- [12 Nov 2014] ASA-201411-9 file denial of service through out-of-bounds read
- [12 Nov 2014] ASA-201411-8 mantisbt arbitrary code execution and unrestricted access
- [11 Nov 2014] ASA-201411-7 curl out-of-bounds read
- [10 Nov 2014] ASA-201411-6 kdebase-workspace local privilege escalation
- [09 Nov 2014] ASA-201411-5 konversation denial of service
- [06 Nov 2014] ASA-201411-4 polarssl multiple issues
- [05 Nov 2014] ASA-201411-3 mantisbt sql injection
- [03 Nov 2014] ASA-201411-2 aircrack-ng multiple vulnerabilities
- [01 Nov 2014] ASA-201411-1 tnftp arbitrary command execution
Oct 2014
- [29 Oct 2014] ASA-201410-14 wget arbitrary filesystem access
- [27 Oct 2014] ASA-201410-13 ejabberd circumvention of encryption
- [24 Oct 2014] ASA-201410-12 libxml2 Denial of service
- [24 Oct 2014] ASA-201410-11 ctags Denial of service
- [23 Oct 2014] ASA-201410-10 libvncserver Remote code execution and Remote DoS
- [22 Oct 2014] ASA-201410-9 libpurple Remote DoS and Information leakage
- [20 Oct 2014] ASA-201410-8 wpa_supplicant, hostapd Arbitrary command execution
- [16 Oct 2014] ASA-201410-7 drupal SQL Injection
- [16 Oct 2014] ASA-201410-6 openssl Memory leak and poodle mitigation
- [15 Oct 2014] ASA-201410-4 zeromq Man-in-the-middle downgrade and replay attack
- [8 Oct 2014] ASA-201410-5 rsyslog Denial of service
- [4 Oct 2014] ASA-201410-3 mediawiki Cross-site Scripting (XSS) and UI redressing
- [2 Oct 2014] ASA-201410-2 jenkins Multiple issues
- [1 Oct 2014] ASA-201410-1 rsyslog Remote denial of service
Sep 2014
- [29 Sep 2014] ASA-201409-5 libvirt Out-of-bounds read access
- [29 Sep 2014] ASA-201409-4 mediawiki Cross-site Scripting (XSS)
- [26 Sep 2014] ASA-201409-3 python2 Information leakage through integer overflow
- [26 Sep 2014] ASA-201409-2 bash Remote code execution
- [25 Sep 2014] ASA-201409-1 nss Signature forgery attack
Publishing a new advisory
We try to always wait for the vulnerability to have been fixed in the corresponding package before issuing an advisory. In case of an extremely critical vulnerability, we may issue an advisory before the package has been fixed, but only if a work-around exists.
If you want to publish a new advisory, please check that:
- the corresponding Arch Linux package is really vulnerable ;
- the tracking Procedure has been completed;
- no Arch Linux Security Advisory for this vulnerability has been published yet ;
- no upcoming Security Advisory for this vulnerability has been claimed in the "Scheduled Advisories" list of this page, as it would mean that someone is already working on an advisory ;
- the current maintainer has been notified, either by flagging the package ouf-of-date if an upstream release fixing the issue exists and/or by creating a new bug-tracker entry (see the exact procedure here).
You may then:
- add a line in the "Scheduled Advisories" list of this page, indicating that you are going to publish an advisory soon ;
- use the following template as an example to write the advisory ;
- ensure that every line in the advisory is properly wrapped after 72 characters
- send the advisory to the arch-security mailing-list (note that it would be nice if you could send a PGP-signed e-mail, but it is not required).
- move the published advisory from "Scheduled Advisories" to "Recent Advisories"
- adapt the CVE tracking page for the fixed package and add a link to the appropriate ASA.
Templates
Subject: [ASA-<YYYYMM-N>] <Package>: <Vulnerability Type> Body: Arch Linux Security Advisory ASA-YYYYMM-N ========================================= Severity: Low, Medium, High, Critical Date : YYYY-MM-DD CVE-ID : <CVE-ID> Package : <package> Type : <Vulnerability Type> Remote : <Yes/No> Link : https://wiki.archlinux.org/index.php/CVE Summary ======= The package <package> before version <Arch Linux fixed version> is vulnerable to <Vulnerability type>. Resolution ========== Upgrade to <Arch Linux fixed version>. # pacman -Syu "<package>>=<Arch Linux fixed version>" The problem has been fixed upstream in version <upstream fixed version>. Workaround ========== <Is there a way to mitigate this vulnerability without upgrading?> Description =========== <Long description, for example from original advisory>. Impact ====== < What is it that an attacker can do? Does this need existing pre-conditions to be exploited (valid credentials, physical access)? Is this remotely exploitable? >. References ========== <CVE-Link> <Upstream report> <Arch Linux Bug-Tracker>
Vim-Snippet
Vim-Snippet for vim-ultisnips plugin for easy completing the archlinux template. Just install vim-ultisnips and copy the text below in your ~/.vim/UltiSnips/all.snippets
you can jump through the tabstops with CTRL+j
.
snippet archsec "arch security form" Arch Linux Security Advisory ASA-`date -I -u | egrep -o '[0-9]{4}'``date -I -u | egrep -o '[0-9]{2}' | sed '3q;d'`-${1} ========================================${1/./=/g} Severity: ${2} Date : `date -I -u` CVE-ID : $3 Package : $4 Type : $5 Remote : ${6} Link : https://wiki.archlinux.org/index.php/CVE Summary ======= The package $4 before version $7 is vulnerable to $5 ${8} Resolution ========== Upgrade to $7. # pacman -Syu "$4>=$7" ${9:The problems have been fixed upstream in version ${7/-\d+$/./}} Workaround ========== ${10:None.} Description =========== ${3/(CVE-....-....)(\s?)/- $1(?2: : )()\n\n/g} Impact ====== A${6/(Yes)|(No)/(?1: remote )(?2: local )/}attacker is able to ${12} References ========== ${3/(CVE-....-....)(\s?)/https:\/\/access.redhat.com\/security\/cve\/$1\n/g} ${13} endsnippet