security update
security update
Upstream update including security & bug fixes as well as feature enhancements. From the upstream [release notes](https://github.com/git/git/raw/v2.38.1/Documen tation/RelNotes/2.30.6.txt): CVE-2022-39253 ————– When relying on the `–local` clone optimization, Git dereferences symbolic links in the source repository before creating hardlinks (or copies) of the dereferenced link in the
The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in OpenSSL.
Several security issues were fixed in OpenSSL.
**PHP version 8.0.25** (27 Oct 2022) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**) (cmb) **Hash:** * Fixed bug php#81738: buffer overflow in hash_update() on long parameter. (**CVE-2022-37454**) (nicky at mouha dot be) **Session:** * Fixed bug [GH-9583](https://github.com/php/php-src/issues/9583)
**PHP version 8.0.25** (27 Oct 2022) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**) (cmb) **Hash:** * Fixed bug php#81738: buffer overflow in hash_update() on long parameter. (**CVE-2022-37454**) (nicky at mouha dot be) **Session:** * Fixed bug [GH-9583](https://github.com/php/php-src/issues/9583)
New upstream release fixing CVE-2022-3515
New upstream release fixing CVE-2022-3515
security update
Libtasn1 could cause a crash when processing certain inputs.
An update that fixes one vulnerability is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes 6 vulnerabilities is now available.
security update
security update
security update
Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2021-43980
It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For the stable distribution (bullseye), these problems have been fixed in
A security issue was discovered in Chromium, which could result in the execution of arbitrary code. For the stable distribution (bullseye), this problem has been fixed in
It was discovered that libxml2, the GNOME XML library, was vulnerable to integer overflows and memory corruption. CVE-2022-40303
A heap use-after-free vulnerability after overeager destruction of a shared DTD in the XML_ExternalEntityParserCreate function in Expat, an XML parsing C library, may result in denial of service or potentially the execution of arbitrary code.
Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version
It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For Debian 10 buster, these problems have been fixed in version
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:
An issue has been found in openvswitch, a software-based, Ethernet virtual switch.
An issue has been found in ncurses, a collection of shared libraries for terminal handling. This issue is about an out-of-bounds read in convert_strings in the
security update
Multiple vulnerabilities were discovered in Django, a popular Python-based web development framework: * CVE-2020-24583: Fix incorrect permissions on intermediate-level
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
security update
An update that fixes four vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
This is the October 2022 release of .NET Core 3.1 This updates .NET Core 3.1 SDK to 3.1.424 and Runtime to 3.1.30. This includes fixes for CVE-2022-41032
added patches to fix CVE-2022-41751
– New version 4.4.3-P1 (rhbz#2132240) – Fix for CVE-2022-2928 (rhbz#2132429) – Fix for CVE-2022-2929 (rhbz#2132430)
Update to 1.12.24 * Fix CVE-2022-42010, CVE-2022-42011, CVE-2022-42012
This is the October 2022 release of .NET Core 3.1 This updates .NET Core 3.1 SDK to 3.1.424 and Runtime to 3.1.30. This includes fixes for CVE-2022-41032
added patches to fix CVE-2022-41751
An update that fixes four vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
security update
An incomplete fix was discovered in Pillow.
Several security issues were fixed in MySQL.
An update that fixes four vulnerabilities is now available.
An update for pki-core is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for libksba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Update to maintenance release 3.0.8
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container suse/pcp was updated. The following patches have been included in this update:
An update that solves 7 vulnerabilities, contains one feature and has one errata is now available.
Security fix for CVE-2022-2476
– Update to 20.10.20. – Mitigates CVE-2022-39253
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/dotnet-runtime was updated. The following patches have been included in this update:
The container bci/dotnet-runtime was updated. The following patches have been included in this update:
An update that solves three vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626) * OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628) * OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-2022-21619) * OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624 [More…]
This update upgrades Firefox to version 102.4.0 ESR. * Mozilla: Same-origin policy violation could have leaked cross-origin URLs (CVE-2022-42927) * Mozilla: Memory Corruption in JS Engine (CVE-2022-42928) * Mozilla: Denial of Service via window.print (CVE-2022-42929) * Mozilla: Memory safety bugs fixed in Firefox 106 and Firefox ESR 102.4 (CVE-2022-42932) For more details about the securit […]
OpenJDK: improper MultiByte conversion can lead to buffer overflow (JGSS, 8286077) (CVE-2022-21618) * OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626) * OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628) * OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-202 [More…]
security update
Security fix for CVE-2022-38784
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update for java-17-openjdk is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
