An update that fixes two vulnerabilities is now available.
Several issues have been found in cimg, a powerful image processing library.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update that solves one vulnerability and has three fixes is now available.
An update that solves one vulnerability and has three fixes is now available.
An update that fixes three vulnerabilities is now available.
Two issues have been found in dompurify.js, an XSS sanitizer for HTML, MathML and SVG. Both issues are related to mXSS issues in SVG- or MATH-elements.
security update
Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2.4.37 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact
Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 5 zip release for RHEL 6, RHEL 7, RHEL 8 and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for openstack-cinder is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for openstack-selinux is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Several security issues were fixed in Perl.
An update that fixes three vulnerabilities is now available.
An update for jenkins-2-plugins, openshift-clients, podman, runc, and skopeo is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for Red Hat Satellite 6.8 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
security update
Open Liberty 20.0.0.11 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes 16 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes 5 vulnerabilities is now available.
Several vulnerabilities were found in package phpmyadmin. CVE-2019-19617
An update that solves one vulnerability and has two fixes is now available.
Update to freetype 2.10.4 which fixes security flaw CVE-2020-15999.
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has four fixes is now available.
An update that fixes 13 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 27 vulnerabilities is now available.
security update
security update
An update that fixes three vulnerabilities is now available.
An update that fixes 11 vulnerabilities is now available.
An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
security update
An update that solves 6 vulnerabilities and has 36 fixes is now available.
An update that solves 6 vulnerabilities and has 36 fixes is now available.
Several security issues were fixed in iTALC.
A flaw was found in the way the Linux kernel Bluetooth implementation handled L2CAP packets with A2MP CID. A remote attacker in adjacent range could use this flaw to crash the system causing denial of service or potentially execute arbitrary code on the system by sending a specially crafted L2CAP packet. The highest threat from […]
GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed certificates) when the client system is not configured to use a system-provided PKCS#11 store. This allows a meddler in the middle to present a different invalid certificate to intercept incoming and outgoing mail. (CVE-2020-24661)
An update for rh-postgresql96-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
security update
An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
**Version 5.0.3** (2020-10-09) – issue #15983 Require twig ^2.9 – issue Fix option to import files locally appearing as not available – issue #16048 Fix to allow NULL as a default bit value – issue #16062 Fix “htmlspecialchars() expects parameter 1 to be string, null given” on Export xml – issue #16078 Fix no charts […]
An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.
An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
security update
An update that solves four vulnerabilities and has 9 fixes is now available.
New version 3.2.7 Security fix for CVE-2020-25862, CVE-2020-25863, CVE-2020-25866
New version 3.2.7 Security fix for CVE-2020-25862, CVE-2020-25863, CVE-2020-25866
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that contains security fixes can now be installed.
An update that fixes two vulnerabilities is now available.
An issue has been found in PowerDNS Authoritative Server allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up […]
NULL Pointer Dereference that leads to arbitrary code execution’¯in the context of the current user. (CVE-2020-9746) References: – https://bugs.mageia.org/show_bug.cgi?id=27432
The TCP dissector could crash (CVE-2020-25862). The MIME Multipart dissector could crash (CVE-2020-25863). The BLIP dissector could crash (CVE-2020-25866).
A vulnerability was discovered where an attacker can cause an XSS attack through the transformation feature. If an attacker sends a crafted link to the victim with the malicious JavaScript, when the victim clicks on the link, the JavaScript will run and complete the instructions made by the attacker. (CVE-2020-26934)
CVE-2020-26116: HTTP request method CRLF injection in httplib
security update
Priyank Nigam discovered that HttpComponents Client, a Java HTTP agent implementation, could misinterpret malformed authority component in a request URI and pick the wrong target host for request execution.
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
Update to 3.17.7 — https://www.claws-mail.org/news.php
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
Several security issues were fixed in Vim.
The package chromium before version 86.0.4240.75-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and insufficient validation.
Red Hat Ansible Tower 3.6 runner release (CVE-2019-18874) 2. Description: * Updated python-psutil version to 5.6.6 inside ansible-runner container (CVE-2019-18874)
