An update that fixes two vulnerabilities is now available.
An update that fixes 20 vulnerabilities is now available.
An update that solves three vulnerabilities and has 5 fixes is now available.
This update upgrades Thunderbird to version 60.8.0. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by […]
Several security issues were fixed in Squid.
A system hardening measure could be bypassed.
An update that fixes one vulnerability is now available.
Zipios could be made to crash or consume system resources if it received specially crafted input.
This update upgrades Thunderbird to version 60.8.0. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins by […]
Several security issues were fixed in Exiv2.
vim/neovim: ‘:source!’ command allows arbitrary command execution via modelines (CVE-2019-12735) SL6 x86_64 vim-X11-7.4.629-5.el6_10.2.x86_64.rpm vim-common-7.4.629-5.el6_10.2.x86_64.rpm vim-debuginfo-7.4.629-5.el6_10.2.x86_64.rpm vim-enhanced-7.4.629-5.el6_10.2.x86_64.rpm vim-filesystem-7.4.629-5.el6_10.2.x86_64.rpm vim-minimal-7.4.629-5.el6_10.2.x86_64.rpm i386 [More…]
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Vulnerabilities have been identified in libspring-java, a modular Java/J2EE application framework.
An update that solves one vulnerability and has 11 fixes is now available.
An update that fixes three vulnerabilities is now available.
Firefox could be made to crash or run programs as your login if it opened a malicious website.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
Harsh Jaiswal discovered a remote shell execution vulnerability in ruby-mini-magick, a Ruby library providing a wrapper around ImageMagick or GraphicsMagick, exploitable when using MiniMagick::Image.open with specially crafted URLs coming from unsanitized user input.
security update
An update that contains security fixes can now be installed.
#### Update to v1.48 * New API: – `snapd_client_get_connections_async` – `snapd_client_get_connections_finish` – `snapd_client_get_connections_sync` – `snapd_client_get_interfaces2_async` – `snapd_client_get_interfaces2_finish` – `snapd_client_get_interfaces2_sync` – `snapd_client_get_snap_conf_async`
– New upstream version (60.8.0)
#### Update to v1.48 * New API: – `snapd_client_get_connections_async` – `snapd_client_get_connections_finish` – `snapd_client_get_connections_sync` – `snapd_client_get_interfaces2_async` – `snapd_client_get_interfaces2_finish` – `snapd_client_get_interfaces2_sync` – `snapd_client_get_snap_conf_async`
– Update to 2.8 fixes rhbz#1581180 rhbz#1603993 rhbz#1674893 and rhbz#1524335 – Removed upstreamed patch – Bug 1524335 – CVE-2017-17459 fossil: Command injection via malicious ssh URLs [fedora-all] – Bug 1581180 – Update fossil version to 2.6 (currently is 2.2) – Bug 1603993 – fossil: FTBFS in Fedora rawhide – Bug 1674893 – fossil: FTBFS in […]
update to 2.1.10, security fix for CVE-2019-12781
security update
security update
This update upgrades Firefox to version 60.8.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 (CVE-2019-11709) * Mozilla: Sandbox escape via installation of malicious language pack (CVE-2019-9811) * Mozilla: Script injection within domain through inner window reuse (CVE-2019-11711) * Mozilla: Cross-origin POST requests can be made with NPAPI plugins […]
Multiple vulnerabilities were discovered in the HyperLogLog implementation of Redis, a persistent key-value database, which could result in denial of service or potentially the execution of arbitrary code.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing, information disclosure, denial of service or cross-site request forgery.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Reading Time: ~ 2 min. Magecart Attacks See Spike in Automation The latest attack in the long string of Magecart breaches has apparently affected over 900 e-commerce sites in under 24 hours. This increase over the previous attack, which affected 700 sites, suggests that its authors are working on improving the automation of these information-stealing […]
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:1763
Upstream details at : https://access.redhat.com/errata/RHSA-2019:1765
An update that fixes one vulnerability is now available.
An update that solves 11 vulnerabilities and has two fixes is now available.
An update that contains security fixes can now be installed.
security update
This update provides ffmpeg version 4.1.4, which fixes several security vulnerabilities and other bugs which were corrected upstream References: – https://bugs.mageia.org/show_bug.cgi?id=25109
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
Two vulnerabilities were discovered in the DOSBox emulator, which could result in the execution of arbitrary code on the host running DOSBox when running a malicious executable in the emulator.
Two security vulnerabilities were discovered in openjpeg2, a JPEG 2000 image library. CVE-2016-9112
The urllib library in Python ships support for a second, not well known URL scheme for accessing local files (“local_file://”). This scheme can be used to circumvent protections that try to block local file access
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for the virt:8.0.0 module is now available for Red Hat Enterprise Linux 8 Advanced Virtualization. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Upstream details at : https://access.redhat.com/errata/RHSA-2019:1726
An update that solves one vulnerability and has one errata is now available.
