An update that fixes one vulnerability is now available.
An update that fixes 7 vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update for openshift-istio-kiali-rhel7-operator-container is now available for Openshift Service Mesh 1.0 and 1.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for jaeger, kiali, and servicemesh-grafana is now available for OpenShift Service Mesh 1.0. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes 7 vulnerabilities is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that fixes 13 vulnerabilities is now available.
In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts
Upstream details at : https://access.redhat.com/errata/RHSA-2020:2344
Upstream details at : https://access.redhat.com/errata/RHSA-2020:2337
Upstream details at : https://access.redhat.com/errata/RHSA-2020:2334
Flask could be made to consume a large amount of memory if it received a specially crafted input.
An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Gollem, as used in Horde Groupware Webmail Edition and other products, had been affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting
The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
An update that solves one vulnerability and has one errata is now available.
New upstream release with bug and security fixes. Also, consolidates duplicate pakages marked and nodejs-marked. I tested upgrades from both, but may have missed some wonky situation.
New version 3.2.4, enabled build with androiddump.
Two memory management issues were found in the asfdemux element of the GStreamer “ugly” plugin collection, which can be triggered via a maliciously crafted file.
Two memory handling issues were found in gst-plugins-good0.10, a collection of GStreamer plugins from the “good” set:
It was discovered that there was both an invalid memory and heap overflow vulnerability in dosfstools, a collection of utilities for making and checking MS-DOS FAT filesystems.
Several vulnerabilities were discovered in package salt, a configuration management and infrastructure automation software.
New version 3.2.4, enabled build with androiddump.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has two fixes is now available.
git: Crafted URL containing new lines, empty host or lacks a scheme can cause credential leak (CVE-2020-11008) SL7 x86_64 git-1.8.3.1-23.el7_8.x86_64.rpm git-daemon-1.8.3.1-23.el7_8.x86_64.rpm git-debuginfo-1.8.3.1-23.el7_8.x86_64.rpm git-gnome-keyring-1.8.3.1-23.el7_8.x86_64.rpm git-svn-1.8.3.1-23.el7_8.x86_64.rpm noarch emacs-git-1.8.3.1-23.el7_8.noarch.rpm [More…]
## Python 3.8.3 This is the third maintenance release of Python 3.8. See [the c hangelog](https://docs.python.org/release/3.8.3/whatsnew/changelog.html#changelo g) for details. Contains the security fix for CVE-2020-8492.
An update that fixes three vulnerabilities is now available.
USN-4369-1 introduced a regression in the Linux kernel.
USN-4367-1 introduced a regression in the Linux kernel.
Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine.
An update for freerdp is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for freerdp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Various minor vulnerabilities have been addredd in libexif, a library to parse EXIF metadata files.
This is a security update for JBoss EAP Continuous Delivery 19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update that fixes 5 vulnerabilities is now available.
security update
security update
An update that fixes three vulnerabilities is now available.
Several security issues were fixed in Unbound.
Updated transmission packages fix security vulnerability: Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent
Updated sleuthkit packages fix security vulnerabilities: An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table (CVE-2019-14532).
Updated log4net packages fix security vulnerability This patch fixes a security vulnerabiliy reported by Karthik Balasundaram. The security vulnerability was found in the way how log4net parses xml configuration files where it allowed to process XML External Entity Processing. An attacker could use
Advisory text to describe the update. Wrap lines at ~75 chars. Updated dojo package fixes security vulnerabilities: In affected versions of dojo, the deepCopy method is vulnerable to
An update that fixes one vulnerability is now available.
An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Several security issues were fixed in Thunderbird.
An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
This microcode updates provides new microcode versions for the following Intel Ice Lake and Sandy Bride family processors: Processor Stepping Model Update Name – ICL-U/Y D1 6-7e-5/80 00000046->00000078 Core Gen10 Mobile
An update that contains security fixes can now be installed.
### python-markdown2 2.3.9 ### – [pull #335] Added header support for wiki tables – [pull #336] Reset _toc when convert is run – [pull #353] XSS fix – [pull #350] XSS fix
An update that fixes one vulnerability is now available.
The 5.6.14 stable kernel update contains a number of important fixes across the tree
### python-markdown2 2.3.9 ### – [pull #335] Added header support for wiki tables – [pull #336] Reset _toc when convert is run – [pull #353] XSS fix – [pull #350] XSS fix
An update that fixes two vulnerabilities is now available.
Georgi Guninski and the Qualys Research Labs discovered multiple vulnerabilities in qmail (shipped in Debian as netqmail with additional patches) which could result in the execution of arbitrary code, bypass of mail address verification and a local information leak whether a file
Security fix for CVE-2018-1285
Update to 8.10 release (CVE-2020-12823)
security update
Security fix for CVE-2020-12662 and CVE-2020-12663
– CVE-2020-10957: lmtp/submission: A client can crash the server by sending a NOOP command with an invalid string parameter. This occurs particularly for a parameter that doesn’t start with a double quote. This applies to all SMTP services, including submission-login, which makes it possible to crash the submission service without authentication. – CVE-2020-10958: lmtp/submission:
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
The package chromium before version 83.0.4103.61-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, content spoofing and insufficient validation.
The package openconnect before version 1:8.10-1 is vulnerable to arbitrary code execution.
The package powerdns-recursor before version 4.2.2-1 is vulnerable to multiple issues including denial of service and insufficient validation.
The package dovecot before version 2.3.10.1-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
security update
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
**PHP version 7.3.18** (14 May 2020) **Core:** * Fixed bug php#78875 (Long filenames cause OOM and temp files are not cleaned). (**CVE-2019-11048**) (cmb) * Fixed bug php#78876 (Long variables in multipart/form-data cause OOM and temp files are not cleaned). (**CVE-2019-11048**) (cmb) * Fixed bug php#79434 (PHP 7.3 and PHP-7.4 crash with NULL-pointer dereference on !CS […]
security update
Several vulnerabilities were discovered in the Dovecot email server, which could cause crashes in the submission, submission-login or lmtp services, resulting in denial of service.
Several security issues were fixed in the Linux kernel.
New upstream release with fixes for CVEs and other enhancements.
New upstream release with fixes for CVEs and other enhancements.
New upstream release with fixes for CVEs and other enhancements.
This update includes a security fix for CVE-2020-10737. Additionally, From 0.34.6: – update license on src/buffer.h – changes “/var/run” to “/run” in systemd service file (Orion Poplawski, #1834511) From 0.34.5: – apply patch from Matthias Gerstner of the SUSE security team to fix a possible race condition in the mkhomedir helper (noted above, this fixes […]
security update
The following CVE(s) were found in src:clamav package. CVE-2020-3327
The 5.6.13 stable kernel update contains a number of important fixes across the tree —- The 5.6.12 stable update contains a number of important fixes across the tree.
Latest upstream.
Backported patch for CVE-2018-10756.
The 5.6.13 stable kernel update contains a number of important fixes across the tree
3.8.3
security update
This package fixes a security issue that allowed for _method query parameters to be used with GET requests. The fix is backported from Mojolicious v8.42.
