The container suse/sle15 was updated. The following patches have been included in this update:
Several vulnerabilities have been found in Ansible, a configuration management, deployment and task execution system, which could result in information disclosure or argument injection. In addition a race condition in become_user was fixed.
security update
An update that fixes two vulnerabilities is now available.
Updated exiv2 packages fix security vulnerability: A heap-based buffer overflow vulnerability in jp2image.cpp of Exiv2 0.27.3 allows attackers to cause a denial of service (DOS) via crafted metadata (CVE-2021-31291).
Updated bluez packages fix security vulnerability: Adapter incorrectly restores Discoverable state after powered down (CVE-2021-3658).
Updated nodejs packages fix security vulnerability: Node.js is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior (CVE-2021-22930)
Updated php-pear packages fix security vulnerability: In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive (CVE-2021-32610).
Updated libsndfile packages fix security vulnerability: A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file (CVE-2021-3246).
security update
An update that fixes four vulnerabilities is now available.
This update provides a new upstream version.
An update that fixes one vulnerability is now available.
An update that solves four vulnerabilities and has one errata is now available.
An update that fixes 6 vulnerabilities is now available.
An update that solves four vulnerabilities and has two fixes is now available.
openCryptoki could be made to allow invalid curve attacks if it received a specially crafted key.
PEAR could be made to overwrite files as the administrator.
Several security issues were fixed in Perl DBI module.
An update that fixes four vulnerabilities is now available.
Security fix for CVE-2021-34558
Security fix for CVE-2021-34558
The package chromium before version 92.0.4515.131-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and content spoofing.
The package nodejs-lts-erbium before version 12.22.4-1 is vulnerable to arbitrary code execution.
The package nodejs-lts-fermium before version 14.17.4-1 is vulnerable to arbitrary code execution.
The package nodejs before version 16.6.0-1 is vulnerable to arbitrary code execution.
lasso: XML signature wrapping vulnerability when parsing SAML responses (CVE-2021-28091) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 – lasso-2.5.1-8.el7_9.i686.rpm – lasso-2.5.1-8.el7_9.x86_64.rpm – lasso-debuginfo-2.5.1-8.el7_9.i686.rpm – lasso-debuginfo-2.5.1-8.el7_9 [More…]
An update for glibc is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
security update
An update for lasso is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for the varnish:6 module is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.1 Extended Update Support, and Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact
Several security issues were fixed in QPDF.
The container sles-15-sp3-chost-byos-v20210729 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20210729-gen2 was updated. The following patches have been included in this update:
The 5.13.6 stable kernel update contains a number of important fixes across the tree.
The container suse-sles-15-sp3-chost-byos-v20210729-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
# New in release OpenJDK 11.0.12 (2021-07-20): Live versions of these release notes can be found at: * https://bitly.com/openjdk11012 * https://builds.shipilev.net/backports-monitor/release-notes-11.0.12.txt ## Security fixes – JDK-8256157: Improve bytecode assembly – JDK-8256491: Better HTTP transport – JDK-8258432, CVE-2021-2341: Improve file transfers –
# New in release OpenJDK 8u302 (2021-07-20) Live versions of these release notes can be found at: * https://bitly.com/openjdk8u302 * https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u302.txt ## Security fixes * JDK-8256157: Improve bytecode assembly * JDK-8256491: Better HTTP transport * JDK-8258432, CVE-2021-2341: Improve file transfers *
Upstream 6.2.5 release (RHBZ #1984631). Fix CVE-2021-32761: 32-bit systems BITFIELD command integer overflow.
# New in release OpenJDK 11.0.12 (2021-07-20): Live versions of these release notes can be found at: * https://bitly.com/openjdk11012 * https://builds.shipilev.net/backports-monitor/release-notes-11.0.12.txt ## Security fixes – JDK-8256157: Improve bytecode assembly – JDK-8256491: Better HTTP transport – JDK-8258432, CVE-2021-2341: Improve file transfers –
# New in release OpenJDK 8u302 (2021-07-20) Live versions of these release notes can be found at: * https://bitly.com/openjdk8u302 * https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u302.txt ## Security fixes * JDK-8256157: Improve bytecode assembly * JDK-8256491: Better HTTP transport * JDK-8258432, CVE-2021-2341: Improve file transfers *
security update
The container ses/7/ceph/ceph was updated. The following patches have been included in this update:
The package vivaldi before version 4.1.2369.11-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, content spoofing, incorrect calculation, information disclosure and insufficient validation.
The package powerdns before version 4.5.1-1 is vulnerable to denial of service.
The package 389-ds-base before version 2.0.7-1 is vulnerable to multiple issues including authentication bypass and denial of service.
The package geckodriver before version 0.29.1-1 is vulnerable to cross- site request forgery.
The package containerd before version 1.5.4-1 is vulnerable to directory traversal.
security update
A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes one vulnerability is now available.
Update to 2.53.8.1 Includes fixes for mailnews archiving, as well as account creation after news subscribing. Show just an icon (instead of a big image etc.) when moving in drag-and-drop operations to make sure the target is visible. (You can change it back by toggling boolean preference “nglayout.enable_drag_images” in about:config).
**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)
**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)
security update
An issue has been found in libsndfile, a library for reading/writing audio files. A crafted WAV file can trigger a heap buffer overflow and might allow exectution of arbitrary code.
PEAR could be made to overwrite files as the administrator.
Several security issues were fixed in QPDF.
libsndfile could be made to crash or run programs as your login if it opened a specially crafted file.
An update that solves one vulnerability, contains two features and has two fixes is now available.
libsndfile could be made to crash or run programs as your login if it opened a specially crafted file.
* Properly set the cookies settings after a network process crash. * Fix accessibility tree after a cross site navigation with PSON enabled. * Ensure WebKitScriptWorld::window-object-cleared signal is always emitted. * Fix several crashes and rendering issues. * Security fixes: CVE-2021-21775, CVE-2021-21779, CVE-2021-30663, CVE-2021-30665, CVE-2021-30689, CVE-2021-30720,
Several security issues were fixed in WebKitGTK.
An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for rh-nodejs12-nodejs and rh-nodejs12-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
* Update to go1.16.6 * Security fix for CVE-2021-34558
Red Hat OpenShift Container Platform release 4.8.2 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.8.
Red Hat OpenShift Container Platform release 4.8.2 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.8.
OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) For more details about the security issue(s), including the [More…]
OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) For more details about the security issue(s), including the [More…]
An update that fixes 8 vulnerabilities is now available.
An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
* Update to upstream 20210716 release * update NXP 8897/8997 firmware images * rtlwifi: de-dupe rtl8723b/rtl8192e SDIO/USB WiFi firmware * Mediatek: update WiFi/bluetooth chip (MT7921) * Mediatek: update MT7915 firmware to 20201105 * Mellanox: Add new mlxsw_spectrum firmware xx.2008.2946 * cxgb4: Update firmware to revision 1.26.0.0 * firmware/i915/guc: Add HuC v7.9.3 for TGL & DG1 […]
This update upgrades Thunderbird to version 78.12.0. * Mozilla: IMAP server responses sent by a MITM prior to STARTTLS could be processed (CVE-2021-29969) * Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970) * Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976) * chromium-browser: Out of bounds write in ANGLE […]
Aspell could be made to execute arbitrary code or cause a crash if it received a specially crafted input.
An update is now available for Red Hat OpenShift Container Platform 4.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Several security issues were fixed in MySQL.
This update ships updated CPU microcode for some types of Intel CPUs and provides mitigations for security vulnerabilities which could result in privilege escalation in combination with VT-d and various side channel attacks.
Several security issues were fixed in the kernel.
An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An integer overflow bug in Redis version 6.0 or newer could be exploited using the `STRALGO LCS` command to corrupt the heap and potentially result with remote code execution (CVE-2021-29477). An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt
This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require(‘y18n’)(); y18n.setLocale(‘__proto__’); y18n.updateLocale({polluted: true}); console.log(polluted); // true (CVE-2020-7774).
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository (CVE-2021-3572). The bundled python-urllib3 was also vulnerable to:
In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream (CVE-2021-21341).
It was discovered that the previous upload of the package rabbitmq-server versioned 3.6.6-1+deb9u1 introduced a regression in function fmt_strip_tags. Big thanks to Christoph Haas for the reporting an issue and for testing the update.
encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method (CVE-2021-27918).
security update
The container suse-sles-15-sp2-chost-byos-v20210722-gen2 was updated. The following patches have been included in this update:
An update that solves one vulnerability and has one errata is now available.
Multiple vulnerabilities have been found in libsdl2, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been found in libyang, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been found in Leptonica, the worst of which could result in a Denial of Service condition.
Security fix for CVE-2021-3602 bump podman to v3.2.3 include podman-machine- cni in podman-plugins subpackage bump crun to 0.20.1 —- Fix `secrets` definition in /usr/share/containers/containers.conf
The container sles-15-sp2-chost-byos-v20210722 was updated. The following patches have been included in this update:
The container suse-sles-15-sp2-chost-byos-v20210722-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
Several vulnerabilities were discovered in lemonldap-ng, a Web-SSO system. The flaws could result in information disclosure, authentication bypass, or could allow an attacker to increase its authentication level or impersonate another user, especially when lemonldap-ng is configured
