# July 2020 OpenJDK security update for OpenJDK 8. Full release notes: https://bitly.com/oj8u262 ## New features * [JDK-8223147](https://bugs.openjdk.java.net/browse/JDK-8223147): JFR Backport ## Security fixes – JDK-8028431, CVE-2020-14579: NullPointerException in DerValue.equals(DerValue) – JDK-8028591, CVE-2020-14578:
ClamAV 0.102.4 is a bug patch release to address the following issues: CVE-2020-3350 Fixed a vulnerability a malicious user could exploit to replace a scan target’s directory with a symlink to another path to trick clamscan, clamdscan, or clamonacc into removing or moving a different file (such as a critical system
An update that solves two vulnerabilities and has three fixes is now available.
Several vulnerabilities were fixed in MilkyTracker, a music tracker for composing music in the MOD and XM module file formats. CVE-2019-14464
Several security issues were fixed in ClamAV.
SQLite could be made to crash or run programs if it processed a specially crafted query.
libslirp could be made to crash if it received specially crafted network traffic.
librsvg could be made to crash if it opened a specially crafted file.
An update that fixes 8 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has 55 fixes is now available.
An update that solves four vulnerabilities and has 7 fixes is now available.
The following CVE(s) were reported against src:qemu: CVE-2017-9503
security update
0.9.24 release
An update that fixes two vulnerabilities is now available.
An update that fixes 10 vulnerabilities is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has four fixes is now available.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves 19 vulnerabilities and has 162 fixes is now available.
An update that fixes one vulnerability is now available.
security update
Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2020-13934
Several security issues were fixed in FFmpeg.
Several security issues were fixed in Python.
Pillow could be made to crash if it opened a specially crafted file.
Evolution Data Server could be made to expose sensitive information over the network.
Several vulnerabilities have been found in librsvg, an SVG rendering library. This update corrects some denial of service issues via exponential element processing, stack exhaustion or application crash when processing specially crafted files, as well as some memory safety
An update for kpatch-patch is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for cloud-init is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes 10 vulnerabilities is now available.
An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for the mod_auth_openidc:2.3 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
security update
security update
security update
security update
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An HTTP request smuggling issue was discovered in the ngx_lua plugin for nginx, a high-performance web and reverse proxy server, as demonstrated by the ngx.location.capture API.
Multiple vulnerabilities were found in Ruby on Rails, a MVC ruby-based framework geared for web application development, which could lead to remote code execution and untrusted user input usage, depending on the application.
An update that contains security fixes can now be installed.
An update that fixes 13 vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves four vulnerabilities and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
security update
security update
security update
security update
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 10 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that solves four vulnerabilities and has two fixes is now available.
An update for .NET Core is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for .NET Core is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
Update to 3.9.0b4
0.9.24 release
Update to 3.9.0b4
An update that fixes three vulnerabilities is now available.
Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) SL6 x86_64 thunderbird-68.10.0-1.el6_10.x86_64 [More…]
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Damian Poddebniak and Fabian Ising discovered a response injection vulnerability in Evolution data server, which could enable MITM attacks.
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that solves 5 vulnerabilities and has one errata is now available.
An update that fixes 5 vulnerabilities is now available.
Several security issues were fixed in libvpx.
kernel: powerpc: incomplete Spectre-RSB mitigation leads to information exposure (CVE-2019-18660) SL6 x86_64 kernel-2.6.32-754.31.1.el6.x86_64.rpm kernel-debug-2.6.32-754.31.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-754.31.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-754.31.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-754.31.1.el6.i686.rpm kernel-debug-devel-2.6.3 [More…]
An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
Multiple security issues were discovered in Python, an interactive high-level object-oriented language. CVE-2018-20406
Several security issues were fixed in WebKitGTK.
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
An update is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for machine-config-daemon and openshift is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
dbus: denial of service via file descriptor leak (CVE-2020-12049) SL7 x86_64 dbus-1.10.24-14.el7_8.x86_64.rpm dbus-debuginfo-1.10.24-14.el7_8.i686.rpm dbus-debuginfo-1.10.24-14.el7_8.x86_64.rpm dbus-libs-1.10.24-14.el7_8.i686.rpm dbus-libs-1.10.24-14.el7_8.x86_64.rpm dbus-x11-1.10.24-14.el7_8.x86_64.rpm dbus-devel-1.10.24-14.el7_8.i686.rpm dbus-devel-1.10.24- [More…]
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
The previous update for chromium released as DSA 4714-2 contained a flaw in the service worker implementation. This problem causes the browser to crash when a connection error occurs. Updated chromium packages are now available that correct this issue.
Update to 2.28.3: * Fix kinetic scrolling with async scrolling. * Fix web process hangs on large GitHub pages. * Bubblewrap sandbox should not attempt to bind empty paths. * Fix threading issues in the media player. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-9802, CVE-2020-9803, CVE-2020-9805, CVE-2020-9806, CVE-2020-9807, CVE-2020-9843, CVE-2020-9850,
The 5.7.8 stable kernel update contains a number of important fixes across the tree.
