The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:
xwayland 22.1.8 – Security fix for CVE-2023-0494
security update
The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update:
The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update:
The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update:
The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update:
The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:
The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:
This update fixes multiple file format validation vulnerabilities that could result in memory access violations such as buffer overflows and floating point exceptions. It also fixes a regression in hcom parsing introduced when fixing CVE-2017-11358.
Add upstream fix for CVE-2022-47021
Add upstream fix for CVE-2022-47021
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
security update
security update
security update
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/ruby was updated. The following patches have been included in this update:
The container suse/rmt-server was updated. The following patches have been included in this update:
The container suse/rmt-nginx was updated. The following patches have been included in this update:
security update
security update
security update
Helmut Grohne discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check
This release fixes various issues in shim bootloader and updates it to a supported version. Older versions of the shim may eventually be blocked by Secure Boot, so it is strongly advised for Secure Boot enabled systems to upgrade to this newer version to keep the system bootable.
I discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check handlers for gssapi,
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:
An update that fixes two vulnerabilities is now available.
Red Hat OpenShift Container Platform release 4.11.26 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
The container bci/python was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
Jan-Niklas Sohn, working with Trend Micro Zero Day Initiative, discovered a vulnerability in the X.Org X server. A potential use after free mighty result in local privilege escalation if
It was discovered that there were a number of issues in graphite-web, a tool provide realtime graphing of system statistics etc. A series of cross-site scripting (XSS) vulnerabilties existed that
NULL pointer dereferences in op_get_data() and op_open1() in opusfile.c (CVE-2022-47021) References: – https://bugs.mageia.org/show_bug.cgi?id=31505
security update
Ikeda Soji reported that libhtml-stripscripts-perl, a Perl module for removing scripts from HTML, is prone to a regular expression denial of service, due to catastrophic backtracking for HTML content with specially crafted style attributes.
EditorConfig Core C could be made to crash or run programs if it received specially crafted input.
Several security issues were fixed in Thunderbird.
USN-5825-1 caused some minor regressions in PAM.
USN-5816-1 caused some minor regressions in Firefox.
Security fix for CVE-2022-4510
# New in release [OpenJDK 8u362](https://bit.ly/openjdk8u362) (2023-01-17) ## CVEs Fixed – CVE-2023-21830 – CVE-2023-21843 ## Security Fixes – JDK-8285021: Improve CORBA communication – JDK-8286496: Improve Thread labels – JDK-8288516: Enhance font creation – JDK-8289350: Better media supports – JDK-8293554: Enhanced DH Key Exchanges – JDK-8293598: Enhance InetAddress
# New in release [OpenJDK 11.0.18](https://bit.ly/openjdk11018) (2023-01-17) ## CVEs Fixed – CVE-2023-21835 – CVE-2023-21843 ## Security Fixes – JDK-8286070: Improve UTF8 representation – JDK-8286496: Improve Thread labels – JDK-8287411: Enhance DTLS performance – JDK-8288516: Enhance font creation – JDK-8289350: Better media supports – JDK-8293554: Enhanced DH Key Exchanges
# New in release [OpenJDK 17.0.6](https://bit.ly/openjdk1706) (2023-01-17) ## CVEs Fixed – CVE-2023-21835 – CVE-2023-21843 ## Security Fixes – JDK-8286070: Improve UTF8 representation – JDK-8286496: Improve Thread labels – JDK-8287411: Enhance DTLS performance – JDK-8288516: Enhance font creation – JDK-8289350: Better media supports – JDK-8293554: Enhanced DH Key Exchanges
# New in release OpenJDK 19.0.2 (2023-01-17) ## CVEs Fixed * CVE-2023-21835 * CVE-2023-21843 ## Security Fixes – JDK-8286070: Improve UTF8 representation – JDK-8286496: Improve Thread labels – JDK-8287411: Enhance DTLS performance – JDK-8288516: Enhance font creation – JDK-8293554: Enhanced DH Key Exchanges – JDK-8293598: Enhance InetAddress address handling – JDK-8293717: Objective
Rebase to sudo 1.9.12p2 – security fix for CVE-2023-22809
An update that fixes one vulnerability is now available.
The 6.1.9 stable kernel update contains a number of important fixes across the tree.
Update to version 1.23.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.23.0 Additionally, this update was built with a version of golang that addresses CVE-2022-41717, and it fixes the installation of icon files.
The 6.1.9 stable kernel update contains a number of important fixes across the tree.
Update to version 1.23.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.23.0 Additionally, this update was built with a version of golang that addresses CVE-2022-41717, and it fixes the installation of icon files.
Several security issues were fixed in LibTIFF.
Several security issues were fixed in Long Range ZIP.
Several security issues were fixed in Apache HTTP Server.
The newest upstream commit Security fix for CVE-2023-0288
Update to 109.0.5414.119. Fixes the following security issues: CVE-2023-0471 CVE-2023-0472 CVE-2023-0473 CVE-2023-0474
New openssh packages are available for Slackware 15.0 and -current to fix security issues.
security update
security update
security update
security update
The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:
Rebuild for CVE-2022-41717 in golang.
Fix CVE-2022-47021
new upstream version
Rebuild for CVE-2022-41717 in golang.
Update to pgadmin4-6.19. —- Backport fix for CVE-2023-22298.
Several security issues were fixed in Vim.
An update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed
Several security issues were fixed in Slurm.
Update to 2.53.15
Several vulnerabilities have been fixed in the libstb library. CVE-2018-16981
Brief introduction CVE-2020-21529
python-future could be made to crash if it received specially crafted input.
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
The container bci/ruby was updated. The following patches have been included in this update:
The container bci/openjdk was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
security update
security update
The components for Red Hat OpenShift support for Windows Container 7.0.0 are now available. This product release includes bug fixes and a moderate security update for the following packages: windows-machine-config-operator and
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
