A security vulnerability has been found in Kaminari, a pagination engine plugin for Rails 3+ and other modern frameworks, that would allow an attacker to inject arbitrary code into pages with pagination links.
Several security issues were fixed in WebKitGTK.
SQL parse could be made to denial of service if it received a specially crafted regular expression.
IBM s390x systems could be made to crash or run programs as an administrator.
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sles12sp5 was updated. The following patches have been included in this update:
security update
Update to 2.32.4: * Do not append .asc extension to downloaded text/plain files. * Fix several crashes and rendering issues. * Fix CVE-2021-30858
– CVE-2021-22947 – STARTTLS protocol injection via MITM – CVE-2021-22946 – protocol downgrade required TLS bypassed – CVE-2021-22945 – use-after-free and double-free in MQTT sending
Backport patch for CVE-2021-23437.
Backport patch for CVE-2021-23437.
Backport patch for CVE-2021-23437.
Backport patch for CVE-2021-23437.
security update
Rebase with Security fix for CVE-2021-3781
Rebuild for dovecot 2.3.16 —- Rebuild for dovecot 2.3.16
– fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)
An update for rh-ruby27-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that solves one vulnerability and has one errata is now available.
Two vulnerabilities were discovered in the Nextcloud desktop client, which could result in information disclosure. For the oldstable distribution (buster), these problems have been fixed
The legacy 1.0 version of OpenSSL, a cryptography library for secure communication, fails to validate alternate trust chains in some conditions. In particular this breaks connecting to servers that use Let’s Encrypt certificates, starting 2021-10-01.
Multiple vulnerabilities were discovered in nettle, a low level cryptographic library, which could result in denial of service (remote crash in RSA decryption via specially crafted ciphertext, crash on ECDSA signature verification) or incorrect verification of ECDSA signatures.
GnuTLS, a portable cryptography library, fails to validate alternate trust chains in some conditions. In particular this breaks connecting to servers that use Let’s Encrypt certificates, starting 2021-10-01.
Update to 2.2.17
Upstream annoucement: [WordPress 5.8.1 Security and Maintenance Release](https://wordpress.org/news/2021/09/wordpress-5-8-1-security-and- maintenance-release/)
Another race in XENMAPSPACE_grant_table handling [XSA-384, CVE-2021-28701] bugfix for XSA-380
The container caasp/v4.5/kube-scheduler was updated. The following patches have been included in this update:
The container caasp/v4.5/kube-proxy was updated. The following patches have been included in this update:
The container caasp/v4.5/kube-controller-manager was updated. The following patches have been included in this update:
Several security issues were fixed in Python.
Several security issues were fixed in Qt.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Libgcrypt could be made to expose sensitive information.
An update that solves one vulnerability and has three fixes is now available.
Squashfs-Tools could be made to overwrite files.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
Several security issues were fixed in curl.
Squashfs-Tools could be made to overwrite files.
The container ses/7/rook/ceph was updated. The following patches have been included in this update:
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update that fixes four vulnerabilities is now available.
The 5.13.15 stable kernel update contains a number of important fixes across the tree.
update to 1.1.1l
This advisory resolves CVE issues filed against XP2 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP2 code base. NOTE: This advisory is informational only. There are no code changes
This update upgrades Thunderbird to version 78.14.0. * Mozilla: Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 (CVE-2021-38493) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 – thunderbird-78.14.0-1.el7_9.x86_64.rpm – thunderbird-debuginfo-78.1 [More…]
This update upgrades Firefox to version 78.14.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 (CVE-2021-38493) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 – firefox-78.14.0-1.el7_9.i686.rpm – firefox-78.14.0-1.el7_9.x86_64.r [More…]
An update that contains security fixes can now be installed.
Several security issues were fixed in the kernel.
Update to Chromium 93. There have been … a few security fixes since the last Fedora chromium update. This update fixes the following CVEs: CVE-2021-30565 CVE-2021-30566 CVE-2021-30567 CVE-2021-30568 CVE-2021-30569 CVE-2021-30571 CVE-2021-30572 CVE-2021-30573 CVE-2021-30574 CVE-2021-30575 CVE-2021-30576 CVE-2021-30577 CVE-2021-30578 CVE-2021-30579 CVE-2021-30580 CVE-2021-30581
security update
It was found that the patch for CVE-2021-3592 introduced a regression which prevented ssh connections to the host system. Since there is no imminent solution for the problem, the patch for CVE-2021-3592 has been reverted. Updated qemu packages are now available to correct this issue.
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the oldstable distribution (buster), this problem has been fixed
security update
security update
security update
Firefox could be made to crash or run programs as your login if it opened a malicious website.
* New upstream version (92.0)
Update to latest upstream release 2.0.12
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Ghostscript could be made to crash, access files, or run programs if it opened a specially crafted file.
It was discovered that Ghostscript, the GPL PostScript/PDF interpreter, does not properly validate access for the “%pipe%”, “%handle%” and “%printer%” io devices, which could result in the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER
security update
Kevin Israel discovered that Postorius, the administrative web frontend for Mailman 3, didn’t validate whether a logged-in user owns the email address when unsubscribing.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Update to CVE release 3003.3-1 https://saltproject.io/security_announcements/salt-security- advisory-2021-sep-02/ CVE-2021-21996 CVE-2021-22004 CVE-2021-31607
Build of libtpms 0.8.5
8u302 update
Update to CVE release 3003.3-1 https://saltproject.io/security_announcements/salt-security- advisory-2021-sep-02/ CVE-2021-21996 CVE-2021-22004 CVE-2021-31607
security update
kernel: use-after-free in route4_change() in net/sched/cls_route.c (CVE-2021-3715) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * [SL 7.8][s390x][DASD]Crash in __list_del_entry, alias_pav_group list corrupt when running dasd_alias_remove_device() * EMBARGOED CVE-2021-3715 kern [More…]
Update to v1.41.1 Fix CVE-2021-39163, CVE-2021-39164 —- Update to v1.41.0
Cumulative bug-fix release from upstream.
– fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)
Cumulative bug-fix release from upstream.
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for kernel is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Update NTFS-3G to 2021.8.22 to fix multiple CVEs
Update NTFS-3G to 2021.8.22 to fix multiple CVEs
Update NTFS-3G to 2021.8.22 to fix multiple CVEs
Update NTFS-3G to 2021.8.22 to fix multiple CVEs
Update NTFS-3G to 2021.8.22 to fix multiple CVEs
An issue has been found in btrbk, a backup tool for btrfs subvolumes. Due to mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys an arbitrary code execution would
IOMMU page mapping issues on x86 [XSA-378, CVE-2021-28694, CVE-2021-28695, CVE-2021-28696] (#1997531) (#1997568) (#1997537) grant table v2 status pages may remain accessible after de-allocation [XSA-379, CVE-2021-28697] (#1997520) long running loops in grant table handling [XSA-380, CVE-2021-28698] (#1997526) inadequate grant-v2 status frames array bounds check [XSA-382, CVE-2021-28699]
An update that fixes two vulnerabilities is now available.
IOMMU page mapping issues on x86 [XSA-378, CVE-2021-28694, CVE-2021-28695, CVE-2021-28696] (#1997531) (#1997568) (#1997537) grant table v2 status pages may remain accessible after de-allocation [XSA-379, CVE-2021-28697] (#1997520) long running loops in grant table handling [XSA-380, CVE-2021-28698] (#1997526) inadequate grant-v2 status frames array bounds check [XSA-382, CVE-2021-28699]
An update that fixes one vulnerability is now available.
security update
