An update that fixes one vulnerability is now available.
New version 3.0.3, Security fix for CVE-2019-13619
Update to 2.6.7
security update
An update that solves four vulnerabilities and has three fixes is now available.
An update that fixes 8 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
Several security issues were fixed in Apache.
Hongxu Chen found several issues in djvulibre, a library and set of tools to handle images in the DjVu format.
New version 3.0.3, Security fix for CVE-2019-13619
Update to 2.6.7
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
The package libnghttp2 before version 1.39.2-1 is vulnerable to denial of service.
The package go-pie before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.
The package go before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.
The package gettext before version 0.20.1-1 is vulnerable to arbitrary code execution.
An update for pango is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update that fixes two vulnerabilities is now available.
Ceph could be made to crash if it received specially crafted network traffic.
Ghostscript could be made to access arbitrary files if it opened a specially crafted file.
Two security vulnerabilities were found in the Apache HTTP server. CVE-2019-10092
USN-4110-1 introduced a regression in Dovecot.
An update for jenkins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for pango is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update is now available for Red Hat Ceph Storage 3.3 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that contains security fixes can now be installed.
An update that fixes 9 vulnerabilities is now available.
An update that solves two vulnerabilities and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes 6 vulnerabilities is now available.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
security update
An update that solves 7 vulnerabilities and has three fixes is now available.
Several vulnerabilities have been found in the Apache HTTPD server. CVE-2019-9517
ghostscript: -dSAFER escape via .buildfont1 (701394) (CVE-2019-10216) SL7 x86_64 ghostscript-9.25-2.el7_7.1.i686.rpm ghostscript-9.25-2.el7_7.1.x86_64.rpm ghostscript-cups-9.25-2.el7_7.1.x86_64.rpm ghostscript-debuginfo-9.25-2.el7_7.1.i686.rpm ghostscript-debuginfo-9.25-2.el7_7.1.x86_64.rpm libgs-9.25-2.el7_7.1.i686.rpm libgs-9.25-2.el7_7.1.x86_64.rpm ghostsc [More…]
zziplib: Bus error caused by loading of a misaligned address inzzip/zip.c (CVE-2018-6541) * zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c (CVE-2018-16548) SL7 x86_64 zziplib-0.13.62-11.el7.i686.rpm zziplib-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62-11.el7.x86_64.rpm zziplib-utils-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62- [More…]
opensc: Buffer overflows handling responses from Muscle Cards in card- muscle.c:muscle_list_files() (CVE-2018-16391) * opensc: Buffer overflows handling responses from TCOS Cards in card- tcos.c:tcos_select_file() (CVE-2018-16392) * opensc: Buffer overflows handling responses from Gemsafe V1 Smartcards in pkcs15-gemsafeV1.c:gemsafe_get_cert_len() (CVE-2018-16393) * opensc: Buffer overflow h [More…]
gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password (CVE-2019-3827) SL7 x86_64 gvfs-1.36.2-3.el7.i686.rpm gvfs-smb-1.36.2-3.el7.x86_64.rpm gvfs-afp-1.36.2-3.el7.x86_64.rpm gvfs-mtp-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.x86_64.rpm gvfs-client-1.36.2-3.el7.x86_64.rpm gvfs [More…]
Security fix for CVE-2019-13509
An update that fixes three vulnerabilities is now available.
An update for ruby is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
An update that contains security fixes can now be installed.
New kernel packages are available for Slackware 14.2 to fix a security issue.
Multiple vulnerabilities have been found in xymon, the network monitoring application. Remote attackers might leverage these vulnerabilities in the CGI parsing code (including buffer overflows and XSS) to cause denial of service, or any other unspecified impact.
Update to v1.15.2 + carry upstream #81330
Even Rouault found an issue in tiff, a library providing support for the Tag Image File Format. Wrong handling off integer overflow checks, that are based on undefined
Addresses CVE-2019-14462 and CVE-2019-14463
Addresses CVE-2019-14462 and CVE-2019-14463
Update to Node.js 10.6.13
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
An update that solves one vulnerability and has two fixes is now available.
An update that solves three vulnerabilities and has two fixes is now available.
It was discovered that there was a remote arbitrary code vulnerability in commons-beanutils, a set of utilities for manipulating JavaBeans code.
The package nginx before version 1.16.1-1 is vulnerable to denial of service.
The package nginx-mainline before version 1.17.3-1 is vulnerable to denial of service.
The package firefox before version 68.0.2-1 is vulnerable to information disclosure.
The package subversion before version 1.12.2-1 is vulnerable to denial of service.
The package libreoffice-still before version 6.2.6-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure.
An update that fixes one vulnerability is now available.
Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP server, which could result in denial of service. For the stable distribution (buster), these problems have been fixed in
Several vulnerabilities were discovered in Squid, a fully featured web proxy cache. The flaws in the HTTP Digest Authentication processing, the HTTP Basic Authentication processing and in the cachemgr.cgi allowed remote attackers to perform denial of service and cross-site scripting
Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, the execution of arbitrary code or bypass of ACLs.
security update
2019-08-14 – Fix compile issues – Fix output buffer size for lzo1x_decompress_safe() 2019-08-07 – Fix VerifyExtensionMap #179 2019-08-06 – Fix compile errors 2019-08-05 – Fix nfdump.1 man page. #175 – Fix off by 1 array. #173 – Fix use after free in ModifyCompressFile – Add bound checks in AddExporterStat #174 – Add bound checks in […]
security update
Three vulnerabilities were discovered in the HTTP/2 code of Nginx, a high-performance web and reverse proxy server, which could result in denial of service.
An update that fixes one vulnerability is now available.
This update includes the latest release of the Apache HTTP Server, version `2.4.41`, fixing various security issues. Several major enhancements are also included in this update: * `mod_md` is now packaged from upstream *github* releases, adding support for ACMEv2. * `mod_cgid` stderr handling has been improved See http://www.apache.org/dist/httpd/CHANGES_2.4.41 for a full list of
This update includes the latest release of the Apache HTTP Server, version `2.4.41`, fixing various security issues. Several major enhancements are also included in this update: * `mod_md` is now packaged from upstream *github* releases, adding support for ACMEv2. * `mod_cgid` stderr handling has been improved See http://www.apache.org/dist/httpd/CHANGES_2.4.41 for a full list of
– update to the latest upstream release (fixes CVE-2019-9511 and CVE-2019-9513)
– Security fix for CVE-2019-13636 – Security fix for CVE-2019-13638
The latest security update of openjdk-7 caused a regression when applications relied on elliptic curve algorithms to establish SSL connections. Several duplicate classes were removed from rt.jar by the upstream developers of OpenJDK because they were also present in
Two issues have been found in cups, the Common UNIX Printing System(tm). Basically both CVEs (CVE-2019-8675 and CVE-2019-8696) are about
An update that fixes two vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves four vulnerabilities and has 7 fixes is now available.
An update that contains security fixes can now be installed.
An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for atomic-openshift-web-console is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Fixes CVE-2019-9511, CVE-2019-9513, CVE-2019-9516
security update
Multiple security issues were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed file/stream is processed.
An update that solves one vulnerability and has one errata is now available.
Several security issues were fixed in OpenJPEG.
An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu 16.04. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Zstandard could be made to execute arbitrary code if it received specially crafted input.
An update that fixes 30 vulnerabilities is now available.
An update is now available for Red Hat Ceph Storage 3.3 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
A security update for Red Hat 3scale API Management Platform is now available from the Red Hat Container Catalog. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
– Fix for CVE-2019-10216 added
