security update
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 xorg-x11-server-Xephyr-1.20.4-19.el7_9.x86_64.rpm xorg- [More…]
xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 xorg-x11-server-Xephyr-1.20.4-19.el7_9.x86_64.rpm xorg- [More…]
An update that fixes one vulnerability is now available.
Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, create open redirects, bypass authorization access, or perform Cross-Site Request Forgery (CSRF) or Cross-Site Scripting (XSS) attacks.
Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, create open redirects, bypass authorization access, or perform Cross-Site Request Forgery (CSRF) or Cross-Site Scripting (XSS) attacks.
Several bugs were discovered in PostgreSQL, a relational database server system. This new LTS minor version update fixes over 25 bugs that were reported in the last several months. The complete and detailed list of issues could be found at: https://www.postgresql.org/docs/release/11.18.
Several bugs were discovered in PostgreSQL, a relational database server system. This new LTS minor version update fixes over 25 bugs that were reported in the last several months. The complete and detailed list of issues could be found at: https://www.postgresql.org/docs/release/11.18.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
security update
security update
An update that fixes 6 vulnerabilities is now available.
An update for libksba is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for device-mapper-multipath is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An issue was discovered in Dropbear, a relatively small SSH server and client. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it was possible for an SSH server to change the login process in its favor. This attack can bypass
There were a couple of secuity issues found in sysstat, system performance tools for Linux, which are as follows: CVE-2019-16167
Update to 4.19.0, fixes CVE-2021-46848.
libiberty: Heap/stack buffer overflow in the dlang_lname function in d-demangle.c (CVE-2021-3826) binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcopy.c via a crafted file (CVE-2022-38533)
libiberty: Heap/stack buffer overflow in the dlang_lname function in d-demangle.c (CVE-2021-3826) binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcopy.c via a crafted file (CVE-2022-38533)
LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-3599) LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in
LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-3599) LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in
In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y. (CVE-2022-44638) References:
In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y. (CVE-2022-44638) References:
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
Maddie Stone reported a heap-based buffer overflow flaw in pixman, a pixel-manipulation library for X and cairo, which could result in denial of service or potentially the execution of arbitrary code.
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
security update
security update
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update:
The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:
The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:
The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
A vulnerability has been found in lesspipe which could result in arbitrary code execution.
A vulnerability has been found in lesspipe which could result in arbitrary code execution.
This is the October 2022 monthly update for .NET 6. It updates the SDK to 6.0.110 and the Runtime to 6.0.10. This update includes a fix for CVE 2022-41032
This is the October 2022 monthly update for .NET 6. It updates the SDK to 6.0.110 and the Runtime to 6.0.10. This update includes a fix for CVE 2022-41032
– url: use IDN decoded names for HSTS checks (CVE-2022-42916) – http_proxy: restore the protocol pointer on error (CVE-2022-42915) – netrc: replace fgets with Curl_get_line (CVE-2022-35260) – fix POST following PUT confusion (CVE-2022-32221)
– url: use IDN decoded names for HSTS checks (CVE-2022-42916) – http_proxy: restore the protocol pointer on error (CVE-2022-42915) – netrc: replace fgets with Curl_get_line (CVE-2022-35260) – fix POST following PUT confusion (CVE-2022-32221)
security update
security update
Several security issues were fixed in OpenJDK.
Zstandard could be made to expose sensitive information
Zstandard could be made to expose sensitive information
An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for linux-firmware is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.
An update for linux-firmware is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.
For Debian 10 buster, these problems have been fixed in version 2:8.1.0875-5+deb10u3. We recommend that you upgrade your vim packages.
An update that fixes 7 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes 7 vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has two fixes is now available.
security update
It was discovered that there was a potential out-of-bounds write vulnerability in pixman, a pixel-manipulation library used in many Linux graphical applications.
It was discovered that there was a potential out-of-bounds write vulnerability in pixman, a pixel-manipulation library used in many Linux graphical applications.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
It was discovered that there was a information disclosure utility in sudo, a tool used to provide limited superuser privileges to specific users.
security update
Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. CVE-2022-40303
Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. CVE-2022-40303
New sudo packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
security update
updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209
updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209
# New in release OpenJDK 19.0.1 (2022-10-18) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-19.0.1.html) * This update depends on [FEDORA-2022- 10bb6f119e](https://bodhi.fedoraproject.org/updates/FEDORA-2022-10bb6f119e) ## CVEs Fixed – CVE-2022-21618 – CVE-2022-21619 – CVE-2022-21624 –
Security fix for CVE-2022-3705 2139842 – vim upgrade broke :! for displaying terminal output
Security fix for CVE-2022-3705 2139842 – vim upgrade broke :! for displaying terminal output
updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
– Updated to 106.0.3 —- – New upstream version (106.0.1)
– Updated to 106.0.3 —- – New upstream version (106.0.1)
security update
**PHP version 8.1.12** (27 Oct 2022) **Core:** * Fixes segfault with Fiber on FreeBSD i386 architecture. (David Carlier) **Fileinfo:** * Fixed bug [GH-8805](https://github.com/php/php-src/issues/8805) (finfo returns wrong mime type for woff/woff2 files). (Anatol) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**)
**PHP version 8.1.12** (27 Oct 2022) **Core:** * Fixes segfault with Fiber on FreeBSD i386 architecture. (David Carlier) **Fileinfo:** * Fixed bug [GH-8805](https://github.com/php/php-src/issues/8805) (finfo returns wrong mime type for woff/woff2 files). (Anatol) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**)
# New in release OpenJDK 17.0.5 (2022-10-18) * [Release announcement](https://bit.ly/openjdk1705) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-17.0.5.html) ## Security Fixes – JDK-8282252: Improve BigInteger/Decimal validation – JDK-8285662: Better permission resolution – JDK-8286077, CVE-2022-21618: Wider
# New in release OpenJDK 11.0.17 (2022-10-18) * [Release announcement](https://bit.ly/openjdk11017) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-11.0.7.html) ## Security Fixes – JDK-8282252: Improve BigInteger/Decimal validation – JDK-8285662: Better permission resolution – JDK-8286077, CVE-2022-21618: Wider
# New in release OpenJDK 17.0.5 (2022-10-18) * [Release announcement](https://bit.ly/openjdk1705) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-17.0.5.html) ## Security Fixes – JDK-8282252: Improve BigInteger/Decimal validation – JDK-8285662: Better permission resolution – JDK-8286077, CVE-2022-21618: Wider
# New in release OpenJDK 8u352 (2022-10-18) * [Release announcement](https://bit.ly/openjdk8u352) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes- openjdk8u352.html) ## Security Fixes * JDK-8282252: Improve BigInteger/Decimal validation * JDK-8285662: Better permission resolution * JDK-8286511: Improve
