[slackware-security] mozilla-firefox (SSA:2017-023-01)

2017-01-23 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] mozilla-firefox (SSA:2017-023-01) New mozilla-firefox packages are available for Slackware 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--+ p

APPLE-SA-2017-01-23-7 iTunes for Windows 12.5.5

2017-01-23 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2017-01-23-7 iTunes for Windows 12.5.5 iTunes for Windows 12.5.5 is now available and addresses the following: WebKit Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corr

APPLE-SA-2017-01-23-6 iCloud for Windows 6.1.1

2017-01-23 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2017-01-23-6 iCloud for Windows 6.1.1 iCloud for Windows 6.1.1 is now available and addresses the following: WebKit Available for: Windows 7 and later Impact: Processing maliciously crafted web content may lead to arbitrary code execution

APPLE-SA-2017-01-23-2 macOS 10.12.3

2017-01-23 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2017-01-23-2 macOS 10.12.3 macOS 10.12.3 is now available and addresses the following: apache_mod_php Available for: macOS Sierra 10.12.2 Impact: Multiple issues in PHP Description: Multiple issues were addressed by updating to PHP versio

APPLE-SA-2017-01-23-5 Safari 10.0.3

2017-01-23 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2017-01-23-5 Safari 10.0.3 Safari 10.0.3 is now available and addresses the following: Safari Available for: OS X Yosemite v10.10.5, OS X El Capitan v10.11.6, and macOS Sierra 10.12.3 Impact: Visiting a malicious website may lead to addre

APPLE-SA-2017-01-23-4 tvOS 10.1.1

2017-01-23 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2017-01-23-4 tvOS 10.1.1 tvOS 10.1.1 is now available and addresses the following: Kernel Available for: Apple TV (4th generation) Impact: An application may be able to execute arbitrary code with kernel privileges Description: A buffer o

APPLE-SA-2017-01-23-3 watchOS 3.1.3

2017-01-23 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2017-01-23-3 watchOS 3.1.3 watchOS 3.1.3 is now available and addresses the following: Accounts Available for: All Apple Watch models Impact: Uninstalling an app did not reset the authorization settings Description: An issue existed which

APPLE-SA-2017-01-23-1 iOS 10.2.1

2017-01-23 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 APPLE-SA-2017-01-23-1 iOS 10.2.1 iOS 10.2.1 is now available and addresses the following: Auto Unlock Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later Impact: Auto Unlock may unlock when Apple W

ESA-2016-150: RSA® Security Analytics Reflected Cross-Site Scripting Vulnerability

2017-01-23 Thread EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 ESA-2016-150: RSA® Security Analytics Reflected Cross-Site Scripting Vulnerability EMC Identifier: ESA-2016-150 CVE Identifier: CVE-2016-8215 Severity Rating: CVSSv3 Base Score: 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) Affected Products: RSA

ESA-2016-146: EMC Avamar Data Store and Avamar Virtual Edition Privilege Escalation Vulnerability

2017-01-23 Thread EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 ESA-2016-146: EMC Avamar Data Store and Avamar Virtual Edition Privilege Escalation Vulnerability EMC Identifier: ESA-2016-146 CVE Identifier: CVE-2016-8214 Severity Rating: CVSSv3 Base Score: 6.7 (AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) Affected pr

Microsoft Remote Desktop Client for Mac Remote Code Execution - Update

2017-01-23 Thread Filippo Cavallarin
Advisory ID: SGMA16-004 Title: Microsoft Remote Desktop Client for Mac Remote Code Execution Product: Microsoft Remote Desktop Client for Mac Version: 8.0.36 and probably prior Vendor:www.microsoft.com Type: Ar