Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that fixes 5 vulnerabilities is now available.

Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences–>Advanced–>HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in […]

Update to 2.34.6: * Fix accessibility not working when the Bubblewrap sandbox is enabled. * Fix rendering of scrollbars when overlay scrollbars are disabled. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22620 —- Update to 2.34.5: * Improve VP8 codec selection when using GStreamer 1.20. * Fix connecting to the accessiblity bus […]

An update that fixes 12 vulnerabilities is now available.

Results that surprised us in The State of Enterprise Open Source report

– Upstream update to 2.4.0 – Fixed CVE-2021-42072 (RHBZ 2022094) – BuildDepends added: gmock-devel, gulrak-filesystem-devel – Address the issue from pull request #1, thanks aekoroglu.

– Upstream update to 2.4.0 – Fixed CVE-2021-42072 (RHBZ 2022094) – BuildDepends added: gmock-devel, gulrak-filesystem-devel – Address the issue from pull request #1, thanks aekoroglu.

Security fix for CVE-2021-4115

containerd would allow unintended access to files over the network.

Several security issues were fixed in PHP.

HAProxy could be made to stop responding if it received specially crafted network traffic.

security update

Security update for php. See changelog for details. References: – https://bugs.mageia.org/show_bug.cgi?id=30056 – https://www.php.net/ChangeLog-8.php#8.0.16

OpenShift Logging bug fix and security update (5.2.8) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for cyrus-sasl is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for cyrus-sasl is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update to 6.0.2

An update that fixes one vulnerability, contains one feature is now available.

Several security issues were fixed in GNU C Library.

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

An update is now available for Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

OpenShift Logging bug fix and security update (5.3.5) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for rh-maven36-httpcomponents-client is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences–>Advanced–>HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in […]

The container trento/trento-db was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220222-gen2 was updated. The following patches have been included in this update:

Nmap Basics: What Is Nmap & How Is It Used?>

Several security issues were fixed in QEMU.

Several security issues were fixed in WebKitGTK.

Several security issues were fixed in MariaDB.

policykit-1 could be made to crash if it received specially crafted data.

The 5.16.11 stable kernel update contains a number of important fixes across the tree.

One issue have been discovered in ujson: ultra fast JSON encoder and decoder for Python. CVE-2021-45958

It was discovered that the SQL plugin in cyrus-sasl2, a library implementing the Simple Authentication and Security Layer, is prone to a SQL injection attack. An authenticated remote attacker can take advantage of this flaw to execute arbitrary SQL commands and for

An update for openshift-gitops-applicationset-container, openshift-gitops-container, openshift-gitops-kam-delivery-container, and openshift-gitops-operator-container is now available for Red Hat OpenShift GitOps 1.3 on OCP 4.7-4.9. (GitOps v1.3.4)

Security fix for CVE-2022-0554 —- Security fixes for CVE-2022-0714, CVE-2022-0729 —- Security fix for CVE-2022-0696 —- Security fix for CVE-2022-0629 —- Security fix for CVE-2022-0572 —- Security fixes for CVE-2022-0408, CVE-2022-0413, CVE-2022-0393, CVE-2022-0417, CVE-2022-0443 —- Security fix for CVE-2022-0685

Several issues have been found in htmldoc, an HTML processor that generates indexed HTML, PS, and PDF.

# New in release OpenJDK 11.0.14.1 (2022-02-08): Live versions of these release notes can be found at: * https://bitly.com/openjdk110141 * https://builds.shipilev.net/backports-monitor/release-notes-11.0.14.1.txt # Changes * [JDK-8218546](https://bugs.openjdk.java.net/browse/JDK-8218546): Unable to connect to https://google.com using java.net.HttpClient —- # New

virtiofsd: Drop membership of all supplementary groups (CVE-2022-0358)

Security fix for CVE-2021-0561

Security fix for https://www.gnutls.org/security-new.html#GNUTLS-SA-2022-01-17

The newest upstream commit — Security fixes for CVE-2022-0714, CVE-2022-0729

The 5.16.11 stable kernel update contains a number of important fixes across the tree.

security update

An update for python-pillow is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for python-pillow is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for cyrus-sasl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Red Hat OpenShift Container Platform release 3.11.634 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for cyrus-sasl is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for python-pillow is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

c3p0 could be made to crash if it opened a specially crafted file.

An update is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

security update

security update

security update

security update

security update

An update for sg-core-container is now available for Service Telemetry Framework 1.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in Expat.

An update for the ruby:2.6 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the ruby:2.6 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

The container suse/sles12sp5 was updated. The following patches have been included in this update:

New expat packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.

Update to 2.54.3. Cherry pick misc SELinux policy fixes. Fixes for CVE-2021-44731, CVE-2021-44730, CVE-2021-4120.

**phpMyAdmin 5.1.3** – 2022-02-11 This version primarily addresses a regression that caused the navigation pane to not function correctly when multiple pages of tables were shown. Version 5.1.3 includes a security hardening improvement. The issue, reported by Rafael Pedrero, could allow users to cause an error that would reveal the path on disk where phpMyAdmin […]

Update to 2.54.3. Cherry pick misc SELinux policy fixes. Fixes for CVE-2021-44731, CVE-2021-44730, CVE-2021-4120.

New version 3.2.8 Security fix for CVE-2021-33582 Security fix for CVE-2021-32056

It was discovered that Twisted, a Python event-based framework for internet applications, is affected by HTTP request splitting vulnerabilities, and may expose sensitive data when following redirects. An attacker may bypass validation checks and retrieve

The container suse/sles12sp4 was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update:

Update to 2.34.6: * Fix accessibility not working when the Bubblewrap sandbox is enabled. * Fix rendering of scrollbars when overlay scrollbars are disabled. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22620

Security fix for CVE-2021-4115

New version 3.2.8 Security fix for CVE-2021-33582 Security fix for CVE-2021-32056

security update

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 5 vulnerabilities and has two fixes is now available.

Several security issues were fixed in libarchive.

An update that fixes three vulnerabilities is now available.

An update that fixes 43 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

The container suse/sles12sp5 was updated. The following patches have been included in this update:

security update