Several security issues were fixed in the Linux kernel.
An update that fixes one vulnerability is now available.
An update that fixes 16 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
security update
security update
The package postgresql before version 11.5-1 is vulnerable to multiple issues including access restriction bypass and information disclosure.
The package postgresql-libs before version 11.5-1 is vulnerable to multiple issues including access restriction bypass and information disclosure.
The package chromium before version 76.0.3809.100-1 is vulnerable to arbitrary code execution.
An update that fixes one vulnerability is now available.
poppler could be made to crash if it received specially crafted PDF.
An update for cockpit-ovirt is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for rhvm-appliance is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Several vulnerabilities were discovered in python-django, a web development framework. They could lead to remote denial-of-service or SQL injection,
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
Security fix for CVE-2018-19800 CVE-2018-19801 CVE-2018-19802
Security fix for CVE-2018-19800 CVE-2018-19801 CVE-2018-19802
Benno Fuenfstueck discovered that Pango, a library for layout and rendering of text with an emphasis on internationalization, is prone to a heap-based buffer overflow flaw in the pango_log2vis_get_embedding_levels function. An attacker can take advantage of this flaw for denial of
The 5.2.7 stable kernel update contains a number of important fixes across the tree. —- The 5.2.6 kernel rebase contains new hardware support, features, and a number of important bug fixes across the tree. —- Update to v5.1.12
The 5.2.7 stable kernel update contains a number of important fixes across the tree. —- The 5.2.6 kernel rebase contains new hardware support, features, and a number of important bug fixes across the tree. —- Update to v5.1.12
The 5.2.7 stable kernel update contains a number of important fixes across the tree. —- The 5.2.6 kernel rebase contains new hardware support, features, and a number of important bug fixes across the tree. —- Update to v5.1.12
Patches for CVE-2019-14295, CVE-2019-14296
July CPU update. See: http://openjdk.java.net/groups/vulnerability/advisories/2019-07-16 and http://mail.openjdk.java.net/pipermail/jdk8u-dev/2019-July/009840.html
fixed CVEs 2019-10181, 2019-10182, 2019-10185 —- Updated to fres upstream release: https://mail.openjdk.java.net/pipermail/distro-pkg- dev/2019-March/041320.html New in release 1.8 (2019-03-12): * added support for javafx-desc and so allwong run of pure-javafx only applications * –nosecurity enhanced for possibility to skip invalid signatures * enhanced to allow
The 5.2.7 stable update contains a number of important fixes across the tree.
The 5.2.7 stable update contains a number of important fixes across the tree.
The 5.2.7 stable update contains a number of important fixes across the tree.
Security fix for CVE-2019-14378
Patches for CVE-2019-14295, CVE-2019-14296
security update
Multiple vulnerabilities have been found in LibVNCServer, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in Redis, the worst of which may allow execution of arbitrary code.
Multiple vulnerabilities have been found in JasPer, the worst of which could result in a Denial of Service condition.
Updated cyrus-imapd package fixes security vulnerability: It was discovered that cyrus-imapd had a buffer overflow in CalDAV request handling triggered by a long iCalendar property name (CVE-2019-11356).
Updated php packages fixes atleast the following security issues: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with
security update
security update
An update that fixes 7 vulnerabilities is now available.
An update that fixes 7 vulnerabilities is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Dominik Penner discovered that KConfig, the KDE configuration settings framework, supported a feature to define shell command execution in .desktop files. If a user is provided with a malformed .desktop file (e.g. if it’s embedded into a downloaded archive and it gets opened in
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
* CVE-2019-10208: `TYPE` in `pg_temp` executes arbitrary SQL during `SECURITY DEFINER` execution Versions Affected: 9.4 – 11
New upstream bugfix and security release.
An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 13.0 (Queens), and Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact
Several security issues were fixed in PostgreSQL.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
A minor version update (from 7.3 to 7.4) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact
New kdelibs packages are available for Slackware 14.2 and -current to fix a security issue.
**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows
Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting.
**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
Rack could allow cross-site scripting (XSS) attacks.
An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
PHP could be made to denial of service, expose sensitive information or execute arbitrary code if it received a specially crafted regular expression.
An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for libssh2 is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.
An update for augeas is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.
An update for systemd is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.
An update for perl is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
Mercurial could be made to overwrite files.
An update that solves two vulnerabilities and has one errata is now available.
An update for perl-Archive-Tar is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for dhcp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for libtiff is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for python-requests is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
security update
Tobias Maedel discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands.
July CPU update. See: http://openjdk.java.net/groups/vulnerability/advisories/2019-07-16 and https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-July/001423.html
This release includes four security fixes: – Prevent an attack where a federated server could send redactions for arbitrary events in v1 and v2 rooms. – Prevent a denial-of-service attack where cycles of redaction events would make Synapse spin infinitely. – Prevent an attack where users could be joined or parted from public rooms without […]
This kernel update is based on the upstream 5.1.20 and fixes atleast the following security issue: With Xen, virtual device backends and device models running in domain 0, or other backend driver domains, need to be able to map guest memory
A system hardening measure could be bypassed.
An update that fixes one vulnerability is now available.
Several minor issues have been fixed in vim, a highly configurable text editor.
Multiple vulnerabilities have been found in libpng, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]
