python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 python3-3.6.8-19.el7_9.x86_64.rpm python3-debuginfo-3.6.8-19.el7_9.i686.rpm python3-debuginfo-3.6.8-19.el7_9.x86_64.rpm python3-libs-3.6.8-19.el7_9.i686.rpm [More…]
python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 python-2.7.5-93.el7_9.x86_64.rpm python-debuginfo-2.7.5-93.el7_9.i686.rpm python-debuginfo-2.7.5-93.el7_9.x86_64.rpm python-libs-2.7.5-93.el7_9.i686.rpm [More…]
**MariaDB 10.5.20** Release notes: https://mariadb.com/kb/en/mariadb-10-5-20-release-notes/
An update for openshift-gitops-kam is now available for Red Hat OpenShift GitOps 1.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Sebastian Krause discovered that manipulated inline images can force PyPDF2, a pure Python PDF library, into an infinite loop, if a maliciously crafted PDF file is processed.
New packages of am-utils are available for all Red Hat Linux platforms. This version includes an important security fix for a buffer overrun problem which is being actively exploited on the Internet.
An update for python is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for python3 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
A couple of security issues were discovered in ruby2.5, the Ruby interpreter, and are as follows – CVE-2021-33621
It was discovered that jupyter-core, the core common functionality for Jupyter projects, could execute arbitrary code in the current working directory while loading configuration files.
The container bci/python was updated. The following patches have been included in this update:
security update
security update
security update
An update for python is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Several security issues were fixed in Netatalk.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Update to 1.14.8
– fix more POST-after-PUT confusion (CVE-2023-28322) – fix IDN wildcard match (CVE-2023-28321)
Security fix for CVE-2023-24329
emacs: command injection vulnerability in htmlfontify.el (CVE-2022-48339) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 emacs-24.3-23.el7_9.1.x86_64.rpm emacs-common-24.3-23.el7_9.1.x86_64.rpm emacs-debuginfo-24.3-23.el7_9.1.x86_64.rpm emacs-nox-24.3-23.el7_9.1.x8 [More…]
Several security issues were fixed in libxml2.
Red Hat OpenShift Container Platform release 4.10.61 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.
Red Hat OpenShift Container Platform release 4.10.61 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.
An update for python-flask is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Several security issues were fixed in LibreOffice.
security update
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
An update for curl is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.
Perl could be made to install modules from untrusted sources.
security update
Two vulnerabilities were fixed in GNU cpio, a program to manage archives of files. CVE-2019-14866
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:
Latest MariaDB minor maintenance release 10.3.39 included a fix for the following security vulnerability: CVE-2022-47015
Rebase to upstream version 3.0.9
Alvaro Mu’±oz from the GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert, a tool and library used to convert notebooks to various other formats via Jinja templates.
Red Hat OpenShift Container Platform release 4.13.1 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13.
Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS). The updated image includes security fixes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Red Hat OpenShift Container Platform release 4.13.1 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.13.
Red Hat OpenShift Container Platform release 4.11.42 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.
Red Hat OpenShift Container Platform release 4.13.1 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13.
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/bci-init was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
security update
CUPS could be made to crash or run programs if it received specially crafted network traffic.
The container suse/sles12sp4 was updated. The following patches have been included in this update:
Update to version 24.1.
Security fix for CVE-2023-0341: update to 0.12.6 (close RHBZ#2162811)
include latest dbx update (may 9th, black lotus edition). —- drop ASSERT from NestedInterruptTplLib (rhbz#2183336).
Updated images are now available for Red Hat Advanced Cluster Security (RHACS). The updated image includes security and bug fixes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Several security issues were fixed in libvirt.
The container bci/python was updated. The following patches have been included in this update:
The container bci/php-apache was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container suse/registry was updated. The following patches have been included in this update:
security update
LuaTeX (TeX Live) could be made to run programs as your login if it compiled a specially crafted TeX file.
hawk could be made to crash if it opened a specially crafted file.
nth-check could be made to crash if it opened a specially crafted file.
Jhead could be made to crash if it opened a specially crafted file.
The container bci/openjdk-devel was updated. The following patches have been included in this update:
Multiple vulnerabilities have been found in Apache Tomcat, the worst of which could result in denial of service.
security update
Multiple vulnerabilities were found in sssd, a set of daemons to manage access to remote directories and authentication mechanisms, which could lead to privilege escalation.
Several security issues were fixed in Sudo.
Jhead could be made to crash if it opened a specially crafted file.
Linux PTP could be made to crash, run arbitrary code, or expose sensitive information if it received specially crafted input.
Update bottles to 51.6 and release final dependency vkbasalt-cli
Update bottles to 51.6 and release final dependency vkbasalt-cli
security update
security update
An update that fixes 43 vulnerabilities is now available.
Update to 1.19.1. Fixes CVE-2023-32067, CVE-2023-31130, CVE-2023-31147, CVE-2023-31124
Update to 0.10.5 (CVE-2023-1667 CVE-2023-2283)
Cross-site scripting (XSS) vulnerabilities were found in rainloop, a web-based email client, which could lead to information disclosure including passphrase leak.
security update
security update
Several vulnerabilities were discovered in libraw, a library for reading RAW files obtained from digital photo cameras, which may result in denial of service or the execution of arbitrary code if specially crafted files are processed.
It was discovered that sysstat, a system performance tools for Linux, incompletely fixed CVE-2022-39377 (as published in DLA-3188-1), which could lead to crashes and possibly remote code execution.
Jose Gomez discovered that the Catalog API endpoint in the Docker registry implementation did not sufficiently enforce limits, which could result in denial of service.
Buffer Overflow vulnerabilities were found in libraw, a raw image decoder library, which could lead to application crash or privilege escalation.
– Update the sequoia-openpgp crate to version 1.16.0. – Update the nettle crate to version 7.3.0. – Update the nettle-sys crate to version 2.2.0. – Update the buffered-reader crate to version 1.2.0. Version 1.16.0 of the sequoia-openpgp crate fixes some issues in parsing code, which could lead to attempted out-of- bounds accesses that result in […]
– Update the sequoia-openpgp crate to version 1.16.0. – Update the nettle crate to version 7.3.0. – Update the nettle-sys crate to version 2.2.0. – Update the buffered-reader crate to version 1.2.0. Version 1.16.0 of the sequoia-openpgp crate fixes some issues in parsing code, which could lead to attempted out-of- bounds accesses that result in […]
– Update the sequoia-openpgp crate to version 1.16.0. – Update the nettle crate to version 7.3.0. – Update the nettle-sys crate to version 2.2.0. – Update the buffered-reader crate to version 1.2.0. Version 1.16.0 of the sequoia-openpgp crate fixes some issues in parsing code, which could lead to attempted out-of- bounds accesses that result in […]
