An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that contains security fixes can now be installed.
An update that solves 12 vulnerabilities and has 59 fixes is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
Frediano Ziglio discovered multiple buffer overflow vulnerabilities in the QUIC image decoding process of spice, a SPICE protocol client and server library, which could result in denial of service, or possibly, execution of arbitrary code.
security update
An update that fixes 5 vulnerabilities is now available.
An update that fixes 5 vulnerabilities is now available.
A potential Cross-Site Scripting (XSS) vulnerability was found in rails, a ruby based MVC framework. Views that allow the user to control the default (not found) value of the `t` and `translate` helpers could be susceptible to XSS attacks. When an HTML-unsafe string is passed as the
Oleg Kalnichevski discovered that httpcomponents-client, a Java library for building HTTP-aware applications, can misinterpret a malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
In Eclipse Web Tools Platform, a component of the Eclipse IDE, XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Backport fix for CVE-2020-26159
Backport fix for CVE-2020-26159
autobuilt v2.1.0,Security fix for CVE-2020-14370
An update that solves 9 vulnerabilities and has 105 fixes is now available.
An update that solves 9 vulnerabilities and has 105 fixes is now available.
An update for go-toolset-1.13 and go-toolset-1.13-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
CVE-2019-11840 An issue was discovered in supplementary Go cryptography libraries, aka golang-googlecode-go-crypto. If more than 256 GiB of keystream is
Red Hat AMQ Interconnect 1.9.0 release packages are available for A-MQ Interconnect on RHEL 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
security update
An update that solves four vulnerabilities and has two fixes is now available.
An update that fixes 9 vulnerabilities, contains 10 features is now available.
An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Several security vulnerabilities have been discovered in puma, highly concurrent HTTP server for Ruby/Rack applications. CVE-2020-11076
An update that fixes one vulnerability is now available.
Spice could be made to crash or run programs if it received specially crafted network traffic.
An update that fixes one vulnerability is now available.
An update for spice and spice-gtk is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that solves one vulnerability and has two fixes is now available.
Security fix for CVE-2020-5238 – ghc-cmark-gfm updated to 0.2.2 which rebases the bundled cmark-gfm to 0.29.0.gfm.1 https://github.com/github/cmark- gfm/security/advisories/GHSA-7gc6-9qr5-hc85
Security fix for CVE-2020-5238 – ghc-cmark-gfm updated to 0.2.2 which rebases the bundled cmark-gfm to 0.29.0.gfm.1 https://github.com/github/cmark- gfm/security/advisories/GHSA-7gc6-9qr5-hc85
Security fix for CVE-2020-5238 – ghc-cmark-gfm updated to 0.2.2 which rebases the bundled cmark-gfm to 0.29.0.gfm.1 https://github.com/github/cmark- gfm/security/advisories/GHSA-7gc6-9qr5-hc85
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Brotli could be made to crash if it received a specially crafted input.
Fix PAC buffer overflow
Update to 85.0.4183.121. Why? Because security, that’s why. It fixes these CVEs: CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 It also has a fix for an issue where networking… uh… didn’t.
Mumble 1.3.2. === Client * Fixed: Overlay not starting (#4282) Server * Fixed: keychain-error on macOS for custom certificates (#4345) Known issues * Overlay blocked by BattleEye. A request to whitelist it has been made. * Overlay blocked by CS:GO Trusted Mode
security update
An update that fixes four vulnerabilities is now available.
An update that solves 10 vulnerabilities and has one errata is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 5 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Security fixes for CVE-2020-1472
An update that fixes 5 vulnerabilities is now available.
An update that contains security fixes can now be installed.
Update to 85.0.4183.121. Why? Because security, that’s why. It fixes these CVEs: CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 It also has a fix for an issue where networking… uh… didn’t. —- Update Chromium to 85.0.4183.102. Fix issue where unpackaged components prevented hardware accelerated rendering from
Mumble 1.3.2. === Client * Fixed: Overlay not starting (#4282) Server * Fixed: keychain-error on macOS for custom certificates (#4345) Known issues * Overlay blocked by BattleEye. A request to whitelist it has been made. * Overlay blocked by CS:GO Trusted Mode
It was found that SNMP Trap Translator does not drop privileges as configured and does not properly escape shell commands in certain functions. A remote attacker, by sending a malicious crafted SNMP trap, could possibly execute arbitrary shell code with the privileges of the
Several security vulnerabilities have been discovered in Squid, a high- performance proxy caching server for web clients. CVE-2020-15049
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, guest-to-host privilege escalation or information leaks.
An update that solves one vulnerability and has 25 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has one errata is now available.
A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with jruby) was too tolerant against
A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with ruby2.3) was too tolerant against
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes 12 vulnerabilities is now available.
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. Therefore, there was a need to explicitly specify the number
This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
Updated OpenShift Container Storage packages fixing various security issues and other bugs are now available for Red Hat OpenShift Container Storage with 3.11.z Async update. Red Hat Product Security has rated this update as having a security impact
An update that solves four vulnerabilities and has two fixes is now available.
Several security improvements were added to Samba.
Several security issues were fixed in Tomcat.
security update
The package podman before version 2.1.0-1 is vulnerable to information disclosure.
The package firefox before version 81.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, cross-site scripting and denial of service.
The package chromium before version 85.0.4183.121-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, information disclosure and insufficient validation.
The package libvirt before version 6.5.0-2 is vulnerable to privilege escalation.
An update that solves 11 vulnerabilities and has one errata is now available.
An update that solves 10 vulnerabilities and has one errata is now available.
Several security issues were fixed in iTALC.
libuv could be made to crash or execute arbitrary code if it received a specially crafted path.
ImageMagick could be made to crash if it opened a specially crafted file.
Several vulnerabilities were discovered in the Perl5 Database Interface (DBI). An attacker could trigger a denial-of-service (DoS) and possibly execute arbitrary code.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has 6 fixes is now available.
An update that fixes 7 vulnerabilities is now available.
