Fixes for CVE-2019-6472, CVE-2019-6473 and CVE-2019-6474
This release fixes a heap buffer over-read in BlitNtoN() function when processing an invalid BMP image. It also updates a URL in the RPM metadata.
Security fix for CVE-2019-15043
An update that fixes one vulnerability is now available.
It was discovered that various procedures in Ghostscript, the GPL PostScript/PDF interpreter, do not properly restrict privileged calls, which could result in bypass of file system restrictions of the dSAFER sandbox.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
It was discovered that there was a stack-based buffer over-read in memcached, the in-memory object caching system. For Debian 8 “Jessie”, this issue has been fixed in memcached version
Multiple vulnerabilities have been found in Exim, the worst of which allows remote attackers to execute arbitrary code.
security update
An update that fixes one vulnerability is now available.
Exim could be made to run programs as an administrator if it received specially crafted network traffic.
Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in Apache, the worst of which could result in a Denial of Service condition.
A buffer overflow in Pango might allow an attacker to execute arbitrary code.
Multiple vulnerabilities have been found in VLC, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in Perl, the worst of which could result in the arbitrary execution of code.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
It was discovered that there was a heap-based buffer overread vulnerability in expat, an XML parsing library. A specially-crafted XML input could fool the parser into changing
* Security fix for CVE-2019-14267 * Security fix for CVE-2019-14934
Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling.
Update LXC to version 3.0.4. The release announcement can be found [here](https://discuss.linuxcontainers.org/t/lxc-3-0-4-has-been-released/5080).
security update
security update
An update that fixes 6 vulnerabilities is now available.
An update that solves one vulnerability and has 19 fixes is now available.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, bypass of the same-origin policy, sandbox escape, information disclosure or denial of service.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 7 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes 12 vulnerabilities is now available.
An update that solves three vulnerabilities and has one errata is now available.
npm/fstream could be made to overwrite files.
An update that solves 12 vulnerabilities and has 19 fixes is now available.
security update
The package jenkins before version 2.192-1 is vulnerable to multiple issues including cross-site request forgery and cross-site scripting.
The package grafana before version 6.3.4-1 is vulnerable to denial of service.
An update that solves three vulnerabilities and has two fixes is now available.
Several newly-referenced issues have been fixed in the FreeType 2 font engine.
An update that fixes 8 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update for openstack-nova is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Alf-Andre Walla discovered a remotely triggerable assert in the Varnish web accelerator; sending a malformed HTTP request could result in denial of service.
The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]
The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]
The 5.2.11 stable kernel update contains a number of important fixes across the tree. —- The 5.2.10 stable kernel update contains a number of important fixes across the tree. —- The 5.2.9 stable kernel update contains a number of important fixes across the tree. —- The 5.2.8 stable kernel update contains a number of important […]
security update
security update
An update that solves one vulnerability and has three fixes is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for kdelibs and kde-setting is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for openstack-nova is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for redis is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for openstack-nova is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for redis is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Irssi could be made to crash or execute arbitrary code if it received a specially crafted CAP request.
security update
An update that solves two vulnerabilities and has 7 fixes is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves three vulnerabilities and has two fixes is now available.
Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, the execution of arbitrary code or bypass of ACLs.
It was discovered that there was an arbitrary code execution vulnerability in the pump BOOTP and DHCP client. When copying the body of the server response, the ethernet packet
PolicyKit could allow unintended access.
An update that solves three vulnerabilities and has 13 fixes is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update that solves four vulnerabilities and has 7 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
A vulnerability has been discovered in Python, an interactive high-level object-oriented language, that is relevant for cookie handling. By using a malicious server an attacker might steal cookies that are meant for other
Multiple vulnerabilities have been found in Dovecot, the worst of which could result in the arbitrary execution of code.
A vulnerability in the GNOME desktop library may allow attackers to escape the sandbox.
A vulnerability in Nautilus may allow attackers to escape the sandbox.
Multiple vulnerabilities have been found in libofx, the worst of which could result in the arbitrary execution of code.
The mpg123 package has been updated to version 1.25.12, fixing several issues which could cause it to crash or hang while parsing mp3 files. References: – https://bugs.mageia.org/show_bug.cgi?id=25350
Updated webmin package fixes security vulnerability: Webmin before 1.930 allows remote exploits if the option to change expired passwords is enabled (CVE-2019-15107).
Updated ghostscript packages fix security vulnerability: It was found that the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript
Updated pango package fixes security vulnerability: It was discovered that pango was subject to a heap based buffer overflow vulnerability which could be used to get code execution (CVE-2019-1010238).
Updated ansible package fixes security vulnerability: A flaw was discovered in the way Ansible templating was implemented before version 2.7.12, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable
Updated vlc packages fixes security vulnerabilities: Multiple security issues were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed file/stream is processed (CVE-2019-13602, CVE-2019-13962,
AUpdated memcached packages fix security vulnerability: In memcached before 1.5.14, a NULL pointer dereference was found in the “lru mode” and “lru temp_ttl” commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in
Updated wavpack packages fixes security vulnerabilities: Rohan Padhye discovered that WavPack incorrectly handled certain WAV files. An attacker could possibly use this issue to cause a denial of service (CVE-2019-1010315, CVE-2019-1010317, CVE-2019-1010318, CVE-2019-1010319).
Updated wavpack packages fixes security vulnerabilities: It was discovered that WavPack incorrectly handled certain DFF files. An attacker could possibly use this issue to cause a denial of service (CVE-2019-11498).
A number of potential side channel attacks were discovered in the SAE implementations used by both hostapd (AP) and wpa_supplicant (infrastructure BSS station/mesh station). SAE (Simultaneous Authentication of Equals) is also known as WPA3-Personal. The discovered side channel attacks may be able to leak information about the used
* CVE-2019-11500: IMAP protocol parser does not properly handle NUL byte when scanning data in quoted strings, leading to out of bounds heap memory writes
Rebuilt with newer nghttp2 —- This update includes the latest upstream release of `mod_http2`, version **1.15.3**. Upstream changes include: * fixes Timeout vs. KeepAliveTimeout behaviour, see PR 63534. * Fixes stream cleanup when connection throttling is in place. * Counts stream resets by client on streams initiated by client as cause for connection throttling. * […]
