updated to 1.4 branch snapshot containing several security fixes
Security fix for CVE-2019-1010238
– Fix for CVE-2019-10216 added
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
Several security issues were fixed in GIFLIB.
Flask, a micro web framework for Python contains a CWE-20: Improper Input Validation vulnerability that can result in Large amount of memory usage possibly leading to denial of service. This attack appear
NLTK could be made to overwrite files.
Several security issues were fixed in CUPS.
security update
Nova could be made to expose sensitive information.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that contains security fixes can now be installed.
Docker could be made to crash or run programs as your login.
docker-credential-helpers could be made to crash or run programs as your login
Several security issues were fixed in OpenLDAP.
Several security issues were fixed in LibreOffice.
KConfig and KDE libraries could be made to crash or run programs if it opened a specially crafted file.
An update for rh-php71-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
This update fixes **CVE-2019-14744 (kconfig arbitrary shell code execution)** in the KDE 3 compatibility version of kdelibs used by legacy KDE 3 applications. The full list of fixes in this `kdelibs3` build: * fixes **CVE-2019-14744** – `kconfig`: malicious `.desktop` files (and others) would execute code. KConfig had a well-meaning feature that allowed configuration files to […]
Security fix for CVE-2019-1010189
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has 11 fixes is now available.
An update that fixes two vulnerabilities is now available.
An update that solves three vulnerabilities and has 41 fixes is now available.
This update fixes 2 security issues. A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure (CVE-2019-10192).
Updated postgresql packages fix security vulnerabilities: Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function
Updated mariadb packages fix security vulnerabilities: An easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise mariadb server. Successful attacks of this vulnerability can result in unauthorized
This update provides and update to mythtv 30, and updates the bundled ffmpeg to 3.2. It also fixes atleast the following issue: The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 4.0.2 does not check for an empty audio packet, leading to an assertion
It was discovered that elfutils incorrectly handled certain malformed files. If a user or automated system were tricked into processing a specially crafted file, elfutils could be made to crash or consume resources, resulting in a denial of service (CVE-2017-7607, CVE-2017-7608, CVE-2017-7609, CVE-2017-7610, CVE-2017-7611, CVE-2017-7612, CVE-2017-7613,
A vulnerability in hostapd and wpa_supplicant could lead to a Denial of Service condition.
Multiple vulnerabilities have been found in MariaDB and MySQL, the worst of which could result in privilege escalation.
Multiple vulnerabilities have been found in VLC, the worst of which could result in the arbitrary execution of code.
security update
Upstream details at : https://access.redhat.com/errata/RHSA-2019:2473
Upstream details at : https://access.redhat.com/errata/RHSA-2019:2471
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
security update
An update that fixes 10 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves 8 vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves 8 vulnerabilities and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
It was discovered that the code fixes to address CVE-2018-16858 and CVE-2019-9848 were not complete. For the oldstable distribution (stretch), these problems have been fixed
**MariaDB 10.3.17** Release notes: https://mariadb.com/kb/en/mariadb-10317-release-notes/ **MariaDB Connector/C 3.1.3** Release notes: https://mariadb.com/kb/en/mariadb- connector-c-313-release-notes/ **MariaDB Connector/ODBC 3.1.2** Release notes: https://mariadb.com/kb/en/mariadb-connector-odbc-312-release-notes/ —–
nginx could be made to crash if it received specially crafted network traffic.
fixes for CVE-2019-14232 to 14235
Multiple vulnerabilities have been found in imagemagick, an image processing toolkit. CVE-2019-12974
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, information disclosure or the execution of arbitrary code.
A buffer over-read in the t1-parser of freetype, a font engine, has been found and fixed by checking limits more sensible.
An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for the mysql:8.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]
A vulnerability in ZeroMQ might allow an attacker to execute arbitrary code.
A vulnerability in ProFTPD could result in the arbitrary execution of code.
A vulnerability in ZNC allows users to escalate privileges.
Multiple vulnerabilities have been found in polkit, the worst of which could result in privilege escalation.
Multiple vulnerabilities have been found in LibreOffice, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in libarchive, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in Oracles JDK and JRE software suites.
Multiple vulnerabilities have been found in SQLite, the worst of which could result in the arbitrary execution of code.
security update
security update
An update that fixes two vulnerabilities is now available.
An update that fixes 12 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
Several security issues have been fixed in otrs2, a well known trouble ticket system.
An update that fixes 7 vulnerabilities is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
wpa_supplicant and hostapd could be made to expose sensitive information over the network.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
An update that fixes two vulnerabilities is now available.
An update that contains security fixes can now be installed.
An update that fixes four vulnerabilities is now available.
security update
An update that solves four vulnerabilities and has one errata is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves four vulnerabilities and has three fixes is now available.
An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
