[slackware-security] lftp (SSA:2018-214-01)

2018-08-02 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] lftp (SSA:2018-214-01) New lftp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--+

[SECURITY] [DSA 4260-1] libmspack security update

2018-08-02 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-4260-1 secur...@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 02, 2018

Executable installers are vulnerable^WEVIL (case 55): escalation of privilege with VMware Player 12.5.9

2018-08-02 Thread Stefan Kanthak
Hi @ll, the executable installer of VMware Player 12.5.9, published in January 2018, available from , is vulnerable. JFTR: VMware Player 12.5.9 is the last version which runs on 32-bit Windows, and the last