An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform various Cross-Side Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks, create files on the server, disclose private information, create open
security update
security update
An update that solves one vulnerability and has three fixes is now available.
An update that fixes three vulnerabilities is now available.
A Denial of Service (DoS) vulnerability was discovered in the network time protocol server/client, ntp. ntp allowed an “off-path” attacker to block unauthenticated
An update for sqlite is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Update to Samba 4.12.2
Update to Samba 4.12.2
security update
A regression has been found in the patch for CVE-2016-10711 of pound, a reverse proxy, load balancer and HTTPS front-end for Web servers. Without the fix pound can be tricked to use 100% CPU.
Several vulnerabilities were discovered in the Tomcat servlet and JSP engine, which could result in HTTP request smuggling and code execution in the AJP connector (disabled by default in Debian).
An update for cri-o is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for haproxy is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes two vulnerabilities is now available.
An update that fixes four vulnerabilities is now available.
A vulnerability was discovered in mailman. GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against
New seamonkey packages are available for Slackware 14.2 and -current to fix security issues.
An update that fixes 5 vulnerabilities is now available.
A security flaw was found on rubygem-json prior to 2.3.0 which was now assigned as CVE-2020-10663. This new rpm contains backport fixes for this issue.
Update to latest upstream OpenVPN 2.4.9 release. It contains a security fix for CVE-2020-11810. This security issue is quite hard to abuse, requiring a fairly precise timing attack combined with guessing a just assigned peer-id reference. If successful, only a single client just initiating a new connection will experience a denial of service situation. This […]
security update
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has two fixes is now available.
A vulnerability was discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. LDAP search filters with nested boolean expressions can result in denial of service (slapd daemon
The 5.6.8 stable kernel update contains a number of important fixes across the tree.
The 5.6.8 stable kernel update contains a number of important fixes across the tree.
The 5.6.8 stable kernel update contains a number of important fixes across the tree.
security update
An update that solves two vulnerabilities and has one errata is now available.
Several vulnerabilities have been discovered in otrs2 (Open source Ticket Request System)
An update that fixes one vulnerability is now available.
OpenJDK 14 April CPU update
Security fix for CVE-2020-5260 and CVE-2020-11008 CVE-2020-5260 – From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.4.txt): > With a crafted URL that contains a newline in it, the credential > helper machinery can be fooled to give credential information for > a wrong host. The
Update to 2.9.10 * Fix CVE-2019-19956, CVE-2019-20388 and CVE-2020-7595
security update
security update
security update
security update
security update
It was discovered that there was a integer signedness error in the miniupnpc UPnP client that could allow remote attackers to cause a denial of service attack.
An issue has been found in pound, A request smuggling vulnerability was discovered in pound, a everse proxy, load balancer and HTTPS front-end for Web servers, that may allow
Two issues have been found in w3m, WWW browsable pager with excellent tables/frames support.
An issue has been found in yodl, a pre-document language. Hanno Bock discovered that there was a buffer over-read vulnerability.
An update that fixes 6 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves 7 vulnerabilities and has 77 fixes is now available.
An update that solves 7 vulnerabilities and has 77 fixes is now available.
An update that solves 13 vulnerabilities and has 157 fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves 6 vulnerabilities and has 8 fixes is now available.
An update that solves 13 vulnerabilities and has 157 fixes is now available.
security update
re2c could be made to execute arbitrary code if it received a specially crafted file.
An update that solves 15 vulnerabilities and has 8 fixes is now available.
An update that solves 10 vulnerabilities and has 89 fixes is now available.
An update that solves 5 vulnerabilities and has 7 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
security update
An update that solves 11 vulnerabilities and has 96 fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves 12 vulnerabilities and has 139 fixes is now available.
Several security issues were fixed in OpenEXR.
Update to latest upstream OpenVPN 2.4.9 release. It contains a security fix for CVE-2020-11810. This security issue is quite hard to abuse, requiring a fairly precise timing attack combined with guessing a just assigned peer-id reference. If successful, only a single client just initiating a new connection will experience a denial of service situation. This […]
6.2.6
Three issues have been found in php5, a server-side, HTML-embedded scripting language.
Hanno Boeck discovered that it was possible to create a cross site scripting attack on the webarchives of the Mailman mailing list manager, by sending a special type of attachement.
Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Fix rendering after a cross site navigation with PSON enabled and hardware acceleration forced. * Fix a crash in nested wayland compositor when closing a tab with PSON enabled. * Update Chrome and Firefox versions in user agent quirks. […]
Security fix for CVE-2020-5260 From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.5.txt): > With a crafted URL that contains a newline or empty host, or lacks > a scheme, the credential helper machinery can be fooled into > providing credential information that is not appropriate for the > protocol in use and host being
Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Update Chrome and Firefox versions in user agent quirks. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-11793
Update to version 1.26. Resolves CVE-2017-18640.
security update
It was discovered that python-reportlab, a Python library to create PDF documents, is prone to a code injection vulnerability while parsing a color attribute. An attacker can take advantage of this flaw to execute arbitrary code if a specially crafted document is processed.
security update
This update fixes the following security vulnerabilities: CVE-2018-20536, CVE-2018-20537, CVE-2018-20539, CVE-2018-20540
**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid pointer address). (cmb, Nikita) **CURL:** * Fixed bug php#79199 (curl_copy_handle() memory leak). (cmb) **Date:** * Fixed bug php#79396 (DateTime hour incorrect during DST jump forward). (Nate Brunette) **Iconv:**
3.2.3 —- New version 3.2.2 Security fix for CVE-2020-7044, CVE-2020-9428, CVE-2020-9430, CVE-2020-9431
Fix mistakes in Wayland wrapper change —- Fixes Wayland issue when running from terminal —- Update sound touch library, fixes some known security issues.
Security fix for CVE-2015-9541
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
Several vulnerabilities have been discovered in the OpenJDK Java runtime, resulting in denial of service, insecure TLS handshakes, bypass of sandbox restrictions or HTTP response splitting attacks.
Multiple vulnerabilities have been found in Git which might all allow attackers to access sensitive information.
The package lib32-openssl before version 1.1.1.g-1 is vulnerable to denial of service.
Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]
Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities were found in OpenSSL, the worst of which could allow remote attackers to cause a Denial of Service condition.
python-twisted: HTTP request smuggling when presented with two Content-Length headers (CVE-2020-10108) * python-twisted: HTTP request smuggling when presented with a Content-Length and a chunked Transfer-Encoding header (CVE-2020-10109) SL7 x86_64 python-twisted-web-12.1.0-7.el7_8.x86_64.rpm – Scientific Linux Development Team
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
