An update that solves one vulnerability and has 22 fixes is now available.
Multiple security issues have been found in Thunderbird which could potentially result in the execution of arbitrary code or denial of service. Debian follows the Thunderbird upstream releases. Support for the 60.x series
An update is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
A security vulnerability was found in libapache2-mod-auth-openidc, the OpenID Connect authentication module for the Apache HTTP server. Insufficient validation of URLs leads to an Open Redirect
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Several security issues were fixed in python-ecdsa.
Several security issues were fixed in MySQL.
An update for libcomps is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
New kernel packages are available for Slackware 14.2 to fix security issues.
A vulnerability was discovered in mosquitto, a MQTT version 3.1/3.1.1 compatible message broker, allowing a malicious MQTT client to cause a denial of service (stack overflow and daemon crash), by sending a specially crafted SUBSCRIBE packet containing a topic with a extremely
VCPUOP_initialise DoS [XSA-296, CVE-2019-18420] missing descriptor table limit checking in x86 PV emulation [XSA-298, CVE-2019-18425] Issues with restartable PV type change operations [XSA-299, CVE-2019-18421] (#1767726) add-to-physmap can be abused to DoS Arm hosts [XSA-301, CVE-2019-18423] passed through PCI devices may corrupt host memory after deassignment [XSA-302, CVE-2019-18424]
8u232 update
Security fix for CVE-2019-15142, CVE-2019-15143, CVE-2019-15144 and CVE-2019-15145.
Update to 1.1.20
Security fix for CVE-2019-16275
Rich Mirch discovered that the pg_ctlcluster script didn’t drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
An update that fixes 11 vulnerabilities is now available.
security update
security update
Security fix for CVE-2019-14664, CVE-2019-12269 and compatibility with Thunderbird 68
Update to Samba 4.10.10 – Security fixes for CVE-2019-10218, CVE-2019-14833, CVE-2019-14847
Update to latest stable (78.0.3904.97). This build contains a number of bug fixes and security updates. Changes can be viewed here: https://chromium.googles ource.com/chromium/src/+log/78.0.3904.86..78.0.3904.92?n=10000
An update that solves one vulnerability and has two fixes is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves 49 vulnerabilities and has two fixes is now available.
Tim Brown discovered a shared memory permissions vulnerability in the Mesa 3D graphics library. Some Mesa X11 drivers use shared-memory XImages to implement back buffers for improved performance, but Mesa
An update that fixes one vulnerability is now available.
An update that fixes 11 vulnerabilities is now available.
Updated libapreq2 packages fix security vulnerability: Max Kellermann reported a NULL pointer dereference flaw in libapreq2, allowing a remote attacker to cause a denial of service against an application using the library (application crash) if an invalid nested
in cpio 2.11, when using the –no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive (CVE-2015-1197). Thomas Habets discovered that GNU cpio incorrectly handled certain
Updated fribidi packages fix security vulnerability: A stack buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi 1.0.0 through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary
Updated webkit2 packages fix security vulnerabilities: Processing maliciously crafted web content may lead to universal cross site scripting (CVE-2019-8625, CVE-2019-8674, CVE-2019-8719, CVE-2019-8813)
A security vulnerability has been reported in libzmq/zeromq. a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary
Updated python-numpy packages fix security vulnerability: An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call
An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update that solves 8 vulnerabilities and has 29 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
security update
security update
security update
security update
In libssh2, SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A
An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Several security issues were fixed in libjpeg-turbo.
An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
DPDK could be made to consume resources if it received specially crafted input.
Update to version 1.9.4. Resolves CVE-2019-10086.
bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes —- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix issue with buffer size and TLS PRF handling. * Add support for D-Bus non-root ObjectManager. iwd 1.0: * Add support for stable D-Bus interfaces. * Add […]
bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes —- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix issue with buffer size and TLS PRF handling. * Add support for D-Bus non-root ObjectManager. iwd 1.0: * Add support for stable D-Bus interfaces. * Add […]
bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes —- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix issue with buffer size and TLS PRF handling. * Add support for D-Bus non-root ObjectManager. iwd 1.0: * Add support for stable D-Bus interfaces. * Add […]
Update to version 1.9.4. Resolves CVE-2019-10086.
The 5.3.11 stable kernel update contains a number of important security updates across the tree, including mitigations for the most recent hardware issues disclosed on Nov 12. —- The 5.3.9 update contains a number of important fixes across the tree —- Update to upstream 2.1-22. 20190618
The 5.3.11 stable kernel update contains a number of important security updates across the tree, including mitigations for the most recent hardware issues disclosed on Nov 12. —- The 5.3.9 update contains a number of important fixes across the tree —- Update to upstream 2.1-22. 20190618
security update
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves one vulnerability and has two fixes is now available.
built version 0.10.5 fix CVE-2019-18837 —- built version 0.10.4 —- built version 0.10.3
**MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed: CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997
This update brings security updates for OpenJDK 13 and updates it to most current version 13.0.1.9.
built version 0.10.5 fix CVE-2019-18837
**MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed: CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997
rebase to 1.16.1
This update brings security updates for OpenJDK 13 and updates it to most current version 13.0.1.9.
security update
An update that solves two vulnerabilities and has one errata is now available.
Several vulnerabilities were discovered in Ampache, a web-based audio file management system.
Bash could be made to crash or execute arbitrary code if it received a specially crafted input.
In haml, when using user input to perform tasks on the server, characters like ” ‘ must be escaped properly. In this case, the ‘ character was missed. An attacker can manipulate the input to introduce additional
fixed multiple security bugs
Security fix CVE-2019-16275 (AP mode PMF disconnection protection bypass)
Fix CVE-2019-3463, CVE-2019-3464 and CVE-2019-1000018.
An update that contains security fixes can now be installed.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, cross-site scripting or denial of service.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
fixed multiple security bugs
Fix CVE-2019-3463, CVE-2019-3464 and CVE-2019-1000018.
– fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)
Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has three fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes 9 vulnerabilities is now available.
An update that fixes 9 vulnerabilities is now available.
An update that fixes 9 vulnerabilities is now available.
