Arch Linux Security - Recent advisorieshttps://security.archlinux.org/Arch Linux recent advsisories RSS feedhttp://www.rssboard.org/rss-specificationpython-feedgenWed, 03 Nov 2021 07:28:22 +0000[ASA-202109-4] element-desktop: information disclosurehttps://security.archlinux.org/ASA-202109-4<pre>A remote attacker able to compromise a user account could disclose encryption keys for messages previously sent by the Matrix client.</pre>Tue, 14 Sep 2021 08:53:47 +0000[ASA-202109-5] element-web: information disclosurehttps://security.archlinux.org/ASA-202109-5<pre>A remote attacker able to compromise a user account could disclose encryption keys for messages previously sent by the Matrix client.</pre>Tue, 14 Sep 2021 08:53:47 +0000[ASA-202109-6] chromium: arbitrary code executionhttps://security.archlinux.org/ASA-202109-6<pre>A remote attacker could execute arbitrary code through crafted web content.</pre>Tue, 14 Sep 2021 08:55:55 +0000[ASA-202110-1] apache: directory traversalhttps://security.archlinux.org/ASA-202110-1<pre>A remote attacker could trick the HTTP server into executing arbitrary executables in its file system through path traversal.</pre>Thu, 21 Oct 2021 09:30:04 +0000[ASA-202110-2] chromium: multiple issueshttps://security.archlinux.org/ASA-202110-2<pre>A remote attacker could execute arbitrary code or disclose sensitive information through crafted web content.</pre>Thu, 21 Oct 2021 09:33:49 +0000[ASA-202110-3] virtualbox: multiple issueshttps://security.archlinux.org/ASA-202110-3<pre>A malicious virtual machine guest could escape its confinement to run arbitrary code on the host system, disclose sensitive information, or crash VirtualBox.</pre>Thu, 21 Oct 2021 09:35:44 +0000[ASA-202110-4] nodejs: url request injectionhttps://security.archlinux.org/ASA-202110-4<pre>A remote attacker could inject HTTP requests through crafted queries.</pre>Thu, 21 Oct 2021 09:38:56 +0000[ASA-202110-5] nodejs-lts-fermium: multiple issueshttps://security.archlinux.org/ASA-202110-5<pre>Incorrect use of the https API could lead to expired certificates being accepted. Furthermore a remote attacker could execute arbitrary code or inject HTTP requests through crafted queries.</pre>Thu, 21 Oct 2021 09:39:36 +0000[ASA-202110-6] nodejs-lts-erbium: multiple issueshttps://security.archlinux.org/ASA-202110-6<pre>Incorrect use of the https API could lead to expired certificates being accepted. Furthermore a remote attacker could execute arbitrary code or inject HTTP requests through crafted queries.</pre>Thu, 21 Oct 2021 09:42:05 +0000[ASA-202110-7] chromium: multiple issueshttps://security.archlinux.org/ASA-202110-7<pre>A remote attacker could execute arbitrary code through crafted web content. Google is aware that exploits for two of the security issues exist in the wild.</pre>Fri, 29 Oct 2021 09:07:47 +0000[ASA-202110-8] opera: multiple issueshttps://security.archlinux.org/ASA-202110-8<pre>A remote attacker could execute arbitrary code or disclose sensitive information through crafted web content.</pre>Fri, 29 Oct 2021 09:09:47 +0000[ASA-202110-9] webkit2gtk: multiple issueshttps://security.archlinux.org/ASA-202110-9<pre>A remote attacker could execute arbitrary code or escape the confinements of the security sandbox through crafted web content.</pre>Fri, 29 Oct 2021 09:12:03 +0000[ASA-202110-10] wpewebkit: multiple issueshttps://security.archlinux.org/ASA-202110-10<pre>A remote attacker could execute arbitrary code or escape the confinements of the security sandbox through crafted web content.</pre>Fri, 29 Oct 2021 09:14:13 +0000[ASA-202110-11] freerdp: arbitrary code executionhttps://security.archlinux.org/ASA-202110-11<pre>A malicious RDP server or gateway could cause remote code execution on a connected client.</pre>Fri, 29 Oct 2021 09:15:11 +0000[ASA-202110-12] bind: denial of servicehttps://security.archlinux.org/ASA-202110-12<pre>A malicious DNS client could trigger queries to broken authoritative DNS servers, resulting in high CPU usage and service degradation of the BIND server.</pre>Fri, 29 Oct 2021 09:17:03 +0000