One of the security fixes released as DLA 3315 introduced a regression in the processing WAV files with variable bitrate encoding. Updated sox packages are available to correct this issue.
Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing.
The newest upstream commit Security fixes for CVE-2023-1175, CVE-2023-1170, CVE-2023-1264.
Update to 1.15.4 * Fix CVE-2023-28100 and CVE-2023-28101
Update to 102.9.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2023-11/ ; https://www.thunderbird.net/en- US/thunderbird/102.9.0/releasenotes/
Denial of service using crafted input. (CVE-2022-40152) References: – https://bugs.mageia.org/show_bug.cgi?id=31665 – https://lists.suse.com/pipermail/sle-security-updates/2023-March/013995.html
Remote code execution on feed enrichment. If “Extract full content from HTML5 and Google AMP” has been enabled for one or more feed subscriptions it is possible for a an attacker to inject a script command that runs with user priveleges. (CVE-2023-1350)
An out-of-bounds write vulnerability exists in TPM2.0’s Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in
A potential buffer overflow exists in the file src/w_help.c at line 55. Specifically, the length of the string returned by getenv(“LANG”) may become very long and cause a buffer overflow while executing the sprintf() function. This vulnerability could potentially allow an attacker to execute arbitrary code or cause a denial-of-service condition.
Some mod_proxy configurations on Apache HTTP Server allow a HTTP request smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225
CVE-2022-37454: Fix buffer overflows in _sha3 module
Update to OWSLib-0.28.1, fixes CVE-2023-27476.
Security fix for CVE-2022-41717
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing.
One of the security fixes released as DSA 5356 introduced a regression in the processing of specific WAV files. Updated sox packages are available to correct this issue.
Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing.
The container bci/python was updated. The following patches have been included in this update:
security update
security update
security update
The container suse/sles/15.5/virt-operator was updated. The following patches have been included in this update:
The container suse/sles/15.5/libguestfs-tools was updated. The following patches have been included in this update:
The container suse/sles/15.5/virt-launcher was updated. The following patches have been included in this update:
The container suse/sles/15.5/virt-handler was updated. The following patches have been included in this update:
The container suse/sles/15.5/virt-exportserver was updated. The following patches have been included in this update:
The container suse/sles/15.5/virt-exportproxy was updated. The following patches have been included in this update:
Several buffer overflows were found which allow an attacker to make tcpdump crash.
Sebastian Krahmer found a problem in the modprobe utility that could beexploited by local users to run arbitrary commands as root if themachine is running a kernel with kmod enabled.
Proton reported on bugtraq that tcsh did not handle in-here documentscorrectly. The version of tcsh that is distributed with Debian GNU/Linux2.2r0 also suffered from this problem.
The version of gnupg that was distributed in Debian GNU/Linux 2.2 hada logic error in the code that checks for valid signatures which couldcause false positive results:
Emacs could be made to crash or run programs as your login if it opened a specially crafted file.
Several security issues were fixed in OpenJPEG.
security update
The container sles-15-sp4-chost-byos-v20230310-arm64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp4-chost-byos-v20230310-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp4-chost-byos-v20230310-x86_64-gen2 was updated. The following patches have been included in this update:
It was discovered that there was a potential remote denial of service vulnerability in redis, a popular key-value database. Authenticated users could have used string matching commands (like
Security fix for CVE-2023-25193 Update of HarfBuzz to 7.0.1 version (#2169172) Update of freetype to 2.13.0 version (#2168496) —- Security fix for CVE-2023-25193, Update to 7.0.1 version (#2169172)
Security fix for CVE-2023-25193 Update of HarfBuzz to 7.0.1 version (#2169172) Update of freetype to 2.13.0 version (#2168496) —- Security fix for CVE-2023-25193, Update to 7.0.1 version (#2169172)
Several security issues were fixed in XStream.
The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:
The container ses/7.1/ceph/ceph was updated. The following patches have been included in this update:
The container ses/7.1/cephcsi/cephcsi was updated. The following patches have been included in this update:
Several security issues were fixed in Twig.
Several security issues were fixed in Protocol Buffers.
update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225
An issue has been found in mpv, a video player based on MPlayer/mplayer2. Due to a use after free an attacker coudl execute arbitrary code or crash the program via the ao_c parameter.
Several vulnerabilities have been discovered in imagemagick that may lead to a privilege escalation, denial of service or information leaks. CVE-2020-19667
High CVE-2023-1213: Use after free in Swiftshader. Reported by Jaehun Jeong(@n3sk) of Theori on 2023-01-30 High CVE-2023-1214: Type Confusion in V8. Reported by Man Yue Mo of GitHub Security Lab on 2023-02-03
A change in the libreswan 4.2 Traffic Selector parsing code introduced a missing check that would reject palformed Traffic Selector payloads. As such, in such case the code stumbles on to hit a double free, leading to a crash and restart of the pluto daemon. No remote code execution. (CVE-2023-23009)
This kernel-linus update is based on upstream 5.15.98 and fixes atleast the following security issues: A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1
Update to 5.9.10 for CVE-2023-26463
Security fix for CVE-2022-43272
Apply upstream libtiff fix for CVE-2022-4645
Release of stargz snapshotter v0.14.2 https://github.com/containerd/stargz- snapshotter/releases/tag/v0.14.2 This release uses containerd v1.7.0-rc.1 so this release fixes GHSA-hmfx-3pcx-653p (CVE-2023-25173) and GHSA-259w-8hf6-59c2 (CVE-2023-25153). This release uses Go 1.20.1 so this release fixes CVE-2022-41717 .
Update to python-werkzeug-2.2.3.
Backport patch for CVE-2023-25587.
security update
Several security issues were fixed in SnakeYAML.
The container bci/openjdk-devel was updated. The following patches have been included in this update:
The container bci/openjdk-devel was updated. The following patches have been included in this update:
**Redis 6.2.11** – Released Tue Feb 28 12:00:00 IST 2023 Upgrade urgency: SECURITY, contains fixes to security issues. Security Fixes: * (**CVE-2023-25155**) Specially crafted SRANDMEMBER, ZRANDMEMBER, and HRANDFIELD commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. * (**CVE-2022-36021**) String matching
Backport of upstream fix for CVE-2022-29718.
Security fix for CVE-2023-23931 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and
The container bci/bci-init was updated. The following patches have been included in this update:
The container bci/openjdk was updated. The following patches have been included in this update:
The container bci/openjdk was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
OpenShift API for Data Protection (OADP) 1.1.2 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Logging Subsystem 5.4.12 – Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
security update
Several security issues were fixed in Sofia-SIP.
The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Red Hat OpenShift Container Platform release 4.11.30 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for rh-mysql80-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
An update for pesign is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for libjpeg-turbo is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for Jenkins and Jenkins-2-plugins is now available for OpenShift Developer Tools and Services for OCP 4.12. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update for pesign is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for pesign is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Build of libtpms 0.9.6 with fixes for CVE-2023-1017 & CVE-2023-1018
Recently two problems have been found in the glibc suite, which could beused to trick setuid applications to run arbitrary code.
