Mutt before 2.0.2 did not ensure that $ssl_force_tls was processed if an IMAP server’s initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle (CVE-2020-28896).
Security fix for CVE-2020-8037
security update
security update
The package musl before version 1.2.1-2 is vulnerable to arbitrary code execution.
The package webkit2gtk before version 2.30.3-1 is vulnerable to arbitrary code execution.
The package gitea before version 1.12.6-1 is vulnerable to insufficient validation.
The package neomutt before version 20201120-1 is vulnerable to silent downgrade.
The package matrix-synapse before version 1.20.1-1 is vulnerable to denial of service.
security update
Two vulnerabilities in the certificate list syntax verification and in the handling of CSN normalization were discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can take advantage of these
Several vulnerabilities were discovered in salt. CVE-2020-16846
An update that fixes 5 vulnerabilities, contains one feature is now available.
An update that fixes 10 vulnerabilities is now available.
Chiaki Ishikawa discovered a stack overflow in SMTP server status handling which could potentially result in the execution of arbitrary code.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
security update
An update that fixes one vulnerability is now available.
An update is now available for Red Hat Ceph Storage 4.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes one vulnerability is now available.
An update for rh-php73-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes one vulnerability is now available.
An update that fixes 10 vulnerabilities is now available.
A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
This update upgrades Thunderbird to version 78.5.0. * Mozilla: Parsing mismatches could confuse and bypass security sanitizer for chrome privileged code (CVE-2020-26951) * Mozilla: Memory safety bugs fixed in Firefox 83 and Firefox ESR 78.5 (CVE-2020-26968) * Mozilla: Variable time processing of cross-origin images during drawImage calls (CVE-2020-16012) * Mozilla: Fullscreen could be enable [More…]
An update for faq is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
Red Hat Ansible Tower 3.7.4-1 – RHEL7 Container 2. Description: * Fixed two jQuery vulnerabilities (CVE-2020-11022, CVE-2020-11023) * Improved Ansible Tower’s web service configuration to allow for
An update for rh-mariadb103-mariadb and rh-mariadb103-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
The package swtpm before version 0.5.1-1 is vulnerable to privilege escalation.
The package rclone before version 1.53.3-1 is vulnerable to private key recovery.
An update that fixes two vulnerabilities is now available.
Some issues have been found in qemu, a fast processor emulator. All issues are related to assertion failures, out-of-bounds access
Update to WebKitGTK 2.30.3: * Fix backdrop filters with rounded borders. * Fix scrolling iframes when async scrolling is enabled. * Allow applications to handle drag and drop on the web view again. * Update Outlook user agent quirk. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-9983, CVE-2020-13584
An update that fixes one vulnerability is now available.
An update that fixes 5 vulnerabilities is now available.
Guenal Davalan reported a flaw in x11vnc, a VNC server to allow remote access to an existing X session. x11vnc creates shared memory segments with 0777 mode. A local attacker can take advantage of this flaw for information disclosure, denial of service or interfering with the VNC
security update
Fix for multiple CVEs
fix CVE-2020-27780: authentication bypass when the user doesn’t exist
Update to upstream 17.9.0 for bug and security fixes
An update that fixes 10 vulnerabilities, contains one feature is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes 12 vulnerabilities is now available.
security update
An update that solves 26 vulnerabilities and has 32 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves 26 vulnerabilities and has 32 fixes is now available.
security update
An update that fixes one vulnerability is now available.
An update that solves three vulnerabilities and has one errata is now available.
An update that solves 12 vulnerabilities and has 103 fixes is now available.
An update that fixes one vulnerability is now available.
An update that solves 21 vulnerabilities and has 21 fixes is now available.
An update that solves 17 vulnerabilities and has 15 fixes is now available.
An update that fixes 5 vulnerabilities is now available.
net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution (CVE-2020-15862) SL6 x86_64 net-snmp-5.5-60.el6_10.2.x86_64.rpm net-snmp-debuginfo-5.5-60.el6_10.2.i686.rpm net-snmp-debuginfo-5.5-60.el6_10.2.x86_64.rpm net-snmp-libs-5.5-60.el6_10.2.i686.rpm net-snmp-libs-5.5-60.el6_10.2.x86_64.rpm net-snmp-devel-5.5-60.el6_10.2.i686.rpm [More…]
This update upgrades Thunderbird to version 78.4.3. * Mozilla: Write side effects in MCallGetProperty opcode not accounted for (CVE-2020-26950) SL6 x86_64 thunderbird-78.4.3-1.el6_10.x86_64.rpm thunderbird-debuginfo-78.4.3-1.el6_10.x86_64.rpm i386 thunderbird-78.4.3-1.el6_10.i686.rpm – Scientific Linux Development Team
An update that fixes 5 vulnerabilities is now available.
An update that solves 15 vulnerabilities and has 75 fixes is now available.
An update for microcode_ctl is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for microcode_ctl is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact
An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.4 Advances Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
security update
security update
Update to 87.0.4280.66. Fixes bugs and security holes. Yay! CVE-2020-16012 CVE-2020-16018 CVE-2020-16019 CVE-2020-16020 CVE-2020-16021 CVE-2020-16022 CVE-2020-16015 CVE-2020-16014 CVE-2020-16023 CVE-2020-16024 CVE-2020-16025 CVE-2020-16026 CVE-2020-16027 CVE-2020-16028 CVE-2020-16029 CVE-2020-16030 CVE-2020-16031 CVE-2020-16032 CVE-2020-16033 CVE-2020-16034 CVE-2020-16035
– Update to upstream 2.1-31. 20201118 – Removal of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68[1]; – Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up to 0x34[2]. [1] The microcode has been removed after reports of system hangs: https://github.com/intel/Intel-Linux-Processor- Microcode-Data-Files/issues/44 [2] Addresses CVE-2020-8695 for this platform.
Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.
Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.
Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.
Multiple vulnerabilities were discovered in Zabbix, a network monitoring solution. An attacker may remotely execute code on the zabbix server, and redirect to external links through the zabbix web frontend.
Three issues have been found in golang-1.8, a Go programming language compiler version 1.8
