An update that fixes one vulnerability is now available.
patchlevel 213 Security fixes for CVE-2022-2819, CVE-2022-2816, CVE-2022-2817
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
security update
An update that solves one vulnerability and has two fixes is now available.
Several security issues were fixed in Libxslt.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
New vim packages are available for Slackware 15.0 and -current to fix a security issue.
Multiple vulnerabilities have been discovered in Apache Tomcat, the worst of which could result in denial of service.
Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution.
A vulnerability has been found in libcroco which could result in denial of service.
KiCad is a suite of programs for the creation of printed circuit boards. It includes a schematic editor, a PCB layout tool, support tools and a 3D viewer to display a finished & fully populated PCB.
An update that fixes three vulnerabilities is now available.
The container sles-15-sp3-chost-byos-v20220818-x86-64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20220818-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20220818-x86_64-gen2 was updated. The following patches have been included in this update:
Code execution via malicious map file (CVE-2021-43518) References: – https://bugs.mageia.org/show_bug.cgi?id=30717 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JIYZ7EVY6NZBM7FQF6GVUARYO6MKSEAT/
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
The container suse/sles12sp5 was updated. The following patches have been included in this update:
The container suse/sles12sp4 was updated. The following patches have been included in this update:
rsync could be made to crash or run programs if it received specially crafted input.
PostgreSQL could be made to run programs when creating or updating extensions.
An update that fixes 14 vulnerabilities is now available.
A command injection vulnerability was found in FreeCAD, a parametric 3D modeler, when importing DWG files with crafted filenames. For Debian 10 buster, this problem has been fixed in version
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
security update
security update
security update
security update
security update
security update
The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-32792
USN-5526-1 introduced a regression in PyJWT.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-32792
The container suse/sles12sp4 was updated. The following patches have been included in this update:
Update to yara-4.2.3 —- Update to 4.2.0 —- Update to 4.2.2
Update to yara-4.2.3 —- Update to 4.2.0 —- Update to 4.2.2
security update
An update that solves one vulnerability, contains one feature and has 7 fixes is now available.
An update that fixes 22 vulnerabilities is now available.
An update that contains security fixes can now be installed.
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
Several security issues were fixed in WebKitGTK.
An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for collectd-libpod-stats is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for collectd-libpod-stats is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Multiple vulnerabilities have been discovered in libarchive, the worst of which could result in arbitrary code execution.
Multiple vulnerabilities have been discovered in QEMU, the worst of which could result in remote code execution (guest sandbox escape).
Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution.
Multiple vulnerabilities have been discovered in the GNU C Library, the worst of which could result in denial of service.
Multiple vulnerabilities have been discovered in Xen, the worst of which could result in remote code execution (guest sandbox escape).
The 5.18.17 stable kernel update contains a number of important fixes across the tree.
security update
The container bci/bci-micro was updated. The following patches have been included in this update:
A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit (CVE-2022-34526) References: – https://bugs.mageia.org/show_bug.cgi?id=30716
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service. (CVE-2022-32189) References:
A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. (CVE-2022-27337) References:
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected. (CVE-2022-34265)
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. (CVE-2022-29970) References: – https://bugs.mageia.org/show_bug.cgi?id=30542
security update
An update that fixes one vulnerability is now available.
Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling, cache poisoning or information disclosure.
The container bci/rust was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/bci-micro was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:
An update that fixes 5 vulnerabilities is now available.
Booth could be made to be stop working under certain circumstances.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
security update
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/ruby was updated. The following patches have been included in this update:
security update
security update
Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.
An update that fixes three vulnerabilities is now available.
