Security fix for CVE-2021-39360
## 2021-10-12, Version 14.18.1 ‘Fermium’ (LTS), @danielleadams This is a security release. ### Notable changes * **CVE-2021-22959**: HTTP Request Smuggling due to spaced in headers (Medium) * The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). More details will […]
The package nodejs-lts-erbium before version 12.22.7-1 is vulnerable to multiple issues including arbitrary code execution, url request injection and certificate verification bypass.
The package nodejs-lts-fermium before version 14.18.1-1 is vulnerable to multiple issues including arbitrary code execution, url request injection and certificate verification bypass.
The package nodejs before version 16.11.1-1 is vulnerable to url request injection.
Several security issues were fixed in Mailman.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
fix memory leak when verbose mode is on
Security fix for CVE-2021-3618
libcaca could be made to crash if it received a specially crafted image.
Tenable discovered that in Babel, a set of tools for internationalizing Python applications, Babel.Locale allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. This
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
security update
An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for the redis:6 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
The security update of smarty3, the compiling PHP template engine, issued as DLA 2618-1 introduced a regression in the smarty_security class when secure directories are evaluated. Updated smarty3 packages are now available to correct this issue.
An update for the redis:5 module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
Update to upstream stable release 2.9.4, includes a fix for CVE-2021-3802 (#2003650, #2003649)
Several security issues were fixed in strongSwan.
An update for the redis:5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update is now available for Red Hat Quay 3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Several security issues were fixed in strongSwan.
The container suse/sle15 was updated. The following patches have been included in this update:
Red Hat OpenShift Container Platform release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Red Hat OpenShift Container Platform release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes one vulnerability is now available.
Ardour could be made to crash or possibly arbitrary code execute if it received a specially crafted XML file.
A security issue was fixed in nginx.
DLA-2743-1 was issued for CVE-2017-5715, affecting amd64-microcode, processor microcode firmware for AMD CPUs. However, the binaries for the resulting upload weren’t built and published, thereby preventing the users to upgrade to a fixed version.
security update
https://lib.openmpt.org/libopenmpt/2021/10/04/security- updates-0.5.12-0.4.24-0.3.33/
The newest upstream commit Security fix for CVE-2021-3796 Security fix for CVE-2021-3778
https://lib.openmpt.org/libopenmpt/2021/10/04/security- updates-0.5.12-0.4.24-0.3.33/
Two security issues have been discovered in LibreOffice’s support for digital signatures in ODF documents, which could result in incorrect signature indicators/timestamps being presented.
Two security issue have been discovered in nghttp2: server, proxy and client implementing HTTP/2. CVE-2018-1000168
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes 20 vulnerabilities is now available.
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
security update
security update
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Richard Weinberger reported that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not check for duplicate filenames within a directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem if a malformed
An update that solves 6 vulnerabilities and has 44 fixes is now available.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
security update
USN-5091-1 introduced a regression in the Linux kernel for Microsoft Azure cloud systems.
security update
Red Hat Advanced Cluster Management for Kubernetes 2.2.9 General Availability release images, which provide security updates, one or more container updates, and bug fixes. Red Hat Product Security has rated this update as having a security impact
Fix CVE-2021-29063 regular expression denial of service References: – https://bugs.mageia.org/show_bug.cgi?id=29537 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/3M5O55E7VUDMXCPQR6MQTOIFDKHP36AA/
Security fix for CVE-2021-41617
Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform Cross-Site Scripting (XSS) attacks or impersonate other users.
An update for httpd is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat
The container suse/sles12sp4 was updated. The following patches have been included in this update:
Red Hat 3scale API Management 2.11.0 Release – Container Images A security update for Red Hat 3scale API Management is now available from the Red Hat Container Catalog. Red Hat Product Security has rated this update as having a security impact
Squashfs-Tools could be made to overwrite files.
The container suse/sle15 was updated. The following patches have been included in this update:
An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that fixes 25 vulnerabilities is now available.
An update for libxml2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
An update that fixes 21 vulnerabilities is now available.
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
– New upstream update (93.0) – Fixed NSS package dependency (NSS 3.70) —- – New upstream release (93.0)
Two security issues were found in TIFF, a widely used format for storing image data, as follows: CVE-2020-19131
Update to f13cbcf (dr_wav 0.13.2) Fix a possible buffer overflow. —- Update to 8900af1 with dr_mp3 0.6.31 Fix a bug in dr_mp3 when loading from memory.
Upgrade Grafana to upstream version 7.5.10 —- rebuild to resolve CVE-2021-34558
Update to f13cbcf (dr_wav 0.13.2) Fixes a possible buffer overflow. —- Update to 8900af1 with dr_mp3 0.6.31 Fix a bug in dr_mp3 when loading from memory.
An update that solves three vulnerabilities and has one errata is now available.
The container caasp/v4/kured was updated. The following patches have been included in this update:
The container caasp/v4/kucero was updated. The following patches have been included in this update:
The container caasp/v4/kubernetes-client was updated. The following patches have been included in this update:
The container caasp/v4/hyperkube was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
security update
Due to a data race in the crossbeam-deque in the crossbeam crate, one or more tasks in the worker queue could have been be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this could have caused a double free and a memory leak (CVE-2021-32810).
New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.
Firefox could be made to crash or run programs as your login if it opened a malicious website.
Several security issues were fixed in MySQL.
