grub2 updates for boothole vulnerabilities in f31/f32.
security update
x86 pv: Crash when handling guest access to MSR_MISC_ENABLE [XSA-333, CVE-2020-25602] (#1881619) Missing unlock in XENMEM_acquire_resource error path [XSA-334, CVE-2020-25598] (#1881616) race when migrating timers between x86 HVM vCPU-s [XSA-336, CVE-2020-25604] (#1881618) PCI passthrough code reading back hardware registers [XSA-337, CVE-2020-25595] (#1881587) once valid event
An update that fixes 7 vulnerabilities is now available.
Two issues have been found in yaws, a high performance HTTP 1.1 webserver written in Erlang.
Two issues have been found in nfdump, a netflow capture daemon. Both issues are related to either a buffer overflow or an integer overflow, which could result in a denial of service or a local code
An issue has been found in curl, a command line tool for transferring data with URL syntax. In rare circumstances, when using the multi API of curl in combination
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
security update
An update that solves one vulnerability and has one errata is now available.
Several security issues were fixed in Gnuplot.
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work: SpecialUserRights could leak whether a user existed or not, multiple code paths lacked HTML sanitisation allowing for cross-site scripting and TOTP validation applied insufficient rate
Sanitize could be made to perform XSS attacks if it received specially crafted input.
Disable pkcs11 related test case running into GnuTLS locking bug
CVE-2020-12100: Parsing mails with a large number of MIME parts could have resulted in excessive CPU usage or a crash due to running out of stack memory. CVE-2020-12673: Dovecot’s NTLM implementation does not correctly check message buffer size, which leads to reading past allocation which can lead to crash. CVE-2020-10967: lmtp/submission:
An update that solves 6 vulnerabilities and has two fixes is now available.
An update that fixes 14 vulnerabilities is now available.
Several security issues were fixed in SPIP.
An update that fixes 19 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
An update that fixes 19 vulnerabilities is now available.
RDFLib could be made to made to execute arbitrary code if it were running in a directory with a specially crafted file.
– New upstream version (81.0)
Security fixes for CVE-2020-1472
Fix CVE-2020-25219
Fix for #1876738 and #1876689
An update that solves four vulnerabilities and has one errata is now available.
An update that fixes 19 vulnerabilities is now available.
An update that solves four vulnerabilities and has one errata is now available.
An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.
Several security issues were fixed in FreeImage.
An update that fixes one vulnerability is now available.
pam_tacplus could be made to expose sensitive information.
An update that fixes 14 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes 25 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
Two security issues were discovered in the modules of the InspIRCd IRC daemon, which could result in denial of service. CVE-2019-20917
An update that solves one vulnerability and has one errata is now available.
security update
security update
Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789).
Update to the new upstream 3.6.15 release. —- – Fix memory leak when serializing iovec_t (#1845083) – Fix automatic libraries sonames detection (#1845806)
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes 14 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
libproxy could be made to crash if it received a specially crafted PAC file.
apng2gif could be made to expose sensitive information if it opened a specifically crafted APNG file.
An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Samba would allow unintended access to files over the network.
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength. (CVE-2020-15503)
util-linux could be made to run programs when performing bash completion.
An update that contains security fixes can now be installed.
An update that solves three vulnerabilities and has 26 fixes is now available.
An update that solves one vulnerability and has 8 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
MCabber could be made to modify the roster and intercept messages if it received specially crafted XMPP packets.
security update
Apache XML-RPC could be made to execute arbitrary code if it received specially crafted data by a malicious XML-RPC server.
An update for librepo is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for the mysql:8.0 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Update to version 0.9.5 * https://www.libssh.org/2020/09/10/libssh-0-9-5/ * Fixes CVE-2020-16135
QEMU: usb: out-of-bounds r/w access issue [XSA-335, CVE-2020-14364] (#1871850)
Apache Log4j could be made to remotely execute arbitrary code if it received specially crafted log data.
An update that solves 8 vulnerabilities and has 17 fixes is now available.
An update that solves 8 vulnerabilities and has 17 fixes is now available.
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3617
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3631
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3643
An update that fixes one vulnerability is now available.
New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.
– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –
https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html
– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –
An update that fixes one vulnerability is now available.
Update to upstream bugfix and security release 2.9.13.
update to 2.2.16, CVE-2020-24583, CVE-2020-24584
New F31 selinux-policy build
