security update
Multiple vulnerabilities have been found in Apache Velocity, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in IcedTeaWeb, the worst of which could result in the arbitrary execution of code.
– fix TELNET stack contents disclosure again (CVE-2021-22925) – fix bad connection reuse due to flawed path name checks (CVE-2021-22924) – disable metalink support to fix the following vulnerabilities CVE-2021-22923 – metalink download sends credentials CVE-2021-22922 – wrong content via metalink not discarded
The package jre-openjdk before version 16.0.2.u7-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.
The package jre-openjdk-headless before version 16.0.2.u7-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.
The package lib32-libcurl-gnutls before version 7.78.0-1 is vulnerable to multiple issues including information disclosure and insufficient validation.
The package libcurl-gnutls before version 7.78.0-1 is vulnerable to multiple issues including information disclosure and insufficient validation.
The package lib32-libcurl-compat before version 7.78.0-1 is vulnerable to multiple issues including information disclosure and insufficient validation.
The package libcurl-compat before version 7.78.0-1 is vulnerable to multiple issues including information disclosure and insufficient validation.
security update
security update
Several security issues were fixed in Ruby.
An update that solves 13 vulnerabilities and has 5 fixes is now available.
An update that solves one vulnerability, contains one feature and has 5 fixes is now available.
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file (CVE-2021-22235). References:
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input (CVE-2013-7488). References:
An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact
Several security issues were fixed in systemd.
The Qualys Research Labs discovered that an attacker-controlled allocation using the alloca() function could result in memory corruption, allowing to crash systemd and hence the entire operating system.
The Qualys Research Labs discovered that an attacker-controlled allocation using the alloca() function could result in memory corruption, allowing to crash systemd and hence the entire operating system.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
An integer overflow flaw was found in glibc that may result in reading of arbitrary memory when wordexp is used with a specially crafted untrusted regular expression input (CVE-2021-35942). References:
This update provides Mbed TLS 2.16.11, with a number of bug fixes, including security fixes. The intermediate version 2.16.10 are included security fixes. See the referenced release notes and advisories for details.
security update
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. CVE-2021-30547
An update that fixes three vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
An update for nettle is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (buster), these problems have been fixed in
Multiple vulnerabilities have been found in Dovecot, the worst of which could result in a Denial of Service condition.
New upstream version (90.0) Disabled Wayland on KDE by default due to popup bugs.
Fix crash in ThemeService (thanks to OpenSUSE) —- Security fixes. CVE-2021-30506 CVE-2021-30507 CVE-2021-30508 CVE-2021-30509 CVE-2021-30510 CVE-2021-30511 CVE-2021-30512 CVE-2021-30513 CVE-2021-30514 CVE-2021-30515 CVE-2021-30516 CVE-2021-30517 CVE-2021-30518 CVE-2021-30519 CVE-2021-30520 CVE-2021-30521 CVE-2021-30522 CVE-2021-30523 CVE-2021-30524 CVE-2021-30525
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
Multiple vulnerabilities have been found in MediaWiki, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been found in Apache Commons FileUpload, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been found in Apache, the worst of which could result in a Denial of Service condition.
The package vivaldi before version 4.0.2312.41-1 is vulnerable to arbitrary code execution.
The package chromium before version 91.0.4472.164-1 is vulnerable to arbitrary code execution.
The package systemd before version 249-2 is vulnerable to denial of service.
The package varnish before version 6.6.1-1 is vulnerable to url request injection.
The package mbedtls before version 2.26.0-1 is vulnerable to information disclosure.
The package python-pillow before version 8.3.0-1 is vulnerable to arbitrary code execution.
security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
This advisory resolves CVE issues filed against XP2 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP2 code base. NOTE: This advisory is informational only. There are no code changes
Several vulnerabilities were discovered in php5, a server-side, HTML-embedded scripting language. An attacker could cause denial of service (DoS), memory corruption and potentially execution of arbitrary code, and server-side request forgery (SSRF) bypass.
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
Red Hat OpenShift Container Platform release 4.6.38 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.6.
Multiple vulnerabilities have been found in Pillow, the worst of which could result in a Denial of Service condition.
An update that solves 14 vulnerabilities, contains one feature and has 5 fixes is now available.
Multiple vulnerabilities have been found in Apache Thrift, the worst of which could result in a Denial of Service condition.
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service (CVE-2021-3200).
This update provides ffmpeg version 4.3.2, which fixes several security vulnerabilities and other bugs which were corrected upstream. References: – https://bugs.mageia.org/show_bug.cgi?id=28433
Release of OpenShift Serverless Client kn 1.16.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes one vulnerability is now available.
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
XStream: remote command execution attack by manipulating the processed input stream (CVE-2021-29505) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 noarch – xstream-1.3.1-14.el7_9.noarch.rpm – xstream-javadoc-1.3.1-14.el7_9.noarch.rpm – Scientific Linux Development Team
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Red Hat AMQ Broker 7.8.2 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability, contains three features and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves 14 vulnerabilities and has three fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves 9 vulnerabilities and has two fixes is now available.
Updated htmldoc packages fix security vulnerabilities: Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181 (CVE-2021-20308).
Updated connman packages fix security vulnerability. ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA) (CVE-2021-33833).
Updated php packages provides upstream 8.0.8 and fixes the following security vulnerabilities: – PDO_Firebird: * Fix Stack buffer overflow in firebird_info_cb (CVE-2021-21704).
Updated botan2 packages fix security vulnerability: In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex) (CVE-2021-24115).
security update
The package ruby-addressable before version 2.8.0-1 is vulnerable to denial of service.
The package gitlab before version 14.0.3-1 is vulnerable to multiple issues including cross-site request forgery, access restriction bypass, arbitrary code execution, arbitrary command execution, cross-site scripting, information disclosure, content spoofing and denial of service.
The package rabbitmq before version 3.8.19-1 is vulnerable to cross- site scripting.
The package php7 before version 7.4.21-1 is vulnerable to multiple issues including denial of service and insufficient validation.
The package php before version 8.0.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.
The package openexr before version 3.0.5-1 is vulnerable to arbitrary code execution.
Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service. In addition the implementation of the MergeSlashes option could result in unexpected behaviour.
The container ses/7/rook/ceph was updated. The following patches have been included in this update:
