An update that fixes one vulnerability is now available.
Several security issues were fixed in QEMU.
Upstream details at : https://access.redhat.com/errata/RHSA-2020:0515
An update that fixes 6 vulnerabilities is now available.
An update that fixes 25 vulnerabilities is now available.
The package thunderbird before version 68.5.0-1 is vulnerable to multiple issues including arbitrary code execution, cross-site scripting, denial of service and information disclosure.
The package systemd before version 244.2-1 is vulnerable to privilege escalation.
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Tom Lane discovered that “ALTER … DEPENDS ON EXTENSION” sub commands in the PostgreSQL database did not perform authorisation checks. For Debian 8 “Jessie”, this problem has been fixed in version
security update
Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (stretch), these problems have been fixed
Do not evaluate arithmetic expressions from environment variables at startup
security update
Do not evaluate arithmetic expressions from environment variables at startup
An update that fixes 7 vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
Several vulnerabilities were discovered in evince, a simple multi-page document viewer. CVE-2017-1000159
Fix CVE-2019-20388 and CVE-2020-7595
security update
security update
– Update to 73.0
Rebase to radare2-4.2.1 and cutter-re 1.10.1. It fixes CVE-2019-19590 and CVE-2019-19547. It also fix a problem in cutter-re that did not display the window icon on Wayland.
Rebase to radare2-4.2.1 and cutter-re 1.10.1. It fixes CVE-2019-19590 and CVE-2019-19547. It also fix a problem in cutter-re that did not display the window icon on Wayland.
**Horde_Data 2.1.5** * [jan] Fix Remote Code Execution vulnerability (CVE-2020-8518, Reported by: Andrea Cardaci/SSD).
security update
security update
Resolve buffer overflow in TexOpen() function, CVE-2019-19601
Rebase to radare2-4.2.1 and cutter-re 1.10.1. It fixes CVE-2019-19590 and CVE-2019-19547. It also fix a problem in cutter-re that did not display the window icon on Wayland.
An update is now available for Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update of the Red Hat OpenShift Container Platform 3.11 and 4.1 container images is now available for Red Hat AMQ Online. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Updated flash-player-plugin package fixes a security vulnerability: Type confusion that leads to arbitrary code execution in the context of the current user. (CVE-2020-3757)
The updated packages fix a security vulnerability: In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of service
Updated python-waitress packages fix security vulnerabilities: If a front-end server does not parse header fields with an LF the same way as it does those with a CRLF it can lead to the front-end and the back-end server parsing the same HTTP message in two different ways.
Updated vim and neovim package fixes security vulnerability: It was discovered that Vim before 8.1.1365 and Neovim before 0.3.6 did not restrict the `:source!` command when executed in a sandbox. This allows remote attackers to take advantage of the modeline feature to
An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An denial of service via an algorithmic complexity attack on email address parsing have been identified in libemail-address-list-perl.
An update that fixes 38 vulnerabilities is now available.
An update for ose-baremetal-installer-container and ose-cli-artifacts-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact
An update for ose-installer-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.
Yubico PIV Tool could be made to crash or run programs as an administrator if it received specially crafted input.
spice-client: Insufficient encoding checks for LZ can cause different integer/buffer overflows (CVE-2018-10893) SL6 x86_64 spice-glib-0.26-8.el6_10.2.i686.rpm spice-glib-0.26-8.el6_10.2.x86_64.rpm spice-gtk-0.26-8.el6_10.2.i686.rpm spice-gtk-0.26-8.el6_10.2.x86_64.rpm spice-gtk-debuginfo-0.26-8.el6_10.2.i686.rpm spice-gtk-debuginfo-0.26-8.el6_10.2.x86_64.rpm spic [More…]
An update for spice-gtk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for nss-softokn is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
The updated packages fix a security vulnerability: In Sudo before 1.8.31, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however,
Security researchers from Snyk discovered that the fix for CVE-2019-9658 was incomplete. Checkstyle, a development tool to help programmers write Java code that adheres to a coding standard, was still vulnerable to XML External Entity (XXE) injection.
an out-of-bounds write vulnerability due to an integer overflow was reported in libexif, a library to parse exif files. This flaw might be leveraged by remote attackers to cause denial of service, or potentially execute arbitrary code via crafted image files.
Several security issues were fixed in libxml2.
Several security issues were fixed in Qt.
Add patch for CVE-2020-6750 and related issues.
An update that fixes 38 vulnerabilities is now available.
Update to Node.js 12.15.0
Update to Node.js 12.15.0
Update to Node.js 12.15.0
libasr-1.0.4, opensmtpd-6.6.2p1 update
libasr-1.0.4, opensmtpd-6.6.2p1 update
Resolve buffer overflow in TexOpen() function, CVE-2019-19601
Resolves: #1796107, #1796109 – Security fix for CVE-2019-19921
Update to upstream 2.0.1 release for CVE-2019-10747
Update to upstream 1.3.2 release for CVE-2019-10746
MinGW cross compiled SDL 2.0.10, fixing a number of CVE issues.
Update to 2.40.0. —- MinGW cross compiled gdk-pixbuf 2.36.12 release, fixing various CVE’s.
security update
security update
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has three fixes is now available.
An update that fixes four vulnerabilities is now available.
An update that solves four vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has one errata is now available.
This package allowed ../ directory traversal to access private resources because resource matching did not ensure that pathnames were in a canonical format.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
Several security issues were fixed in Pillow.
An update that solves two vulnerabilities and has one errata is now available.
Several security issues were fixed in systemd.
An update that fixes one vulnerability is now available.
OpenSMTPD could be made to run programs as root if it received specially crafted input over the network.
ipa: Denial of service in IPA server due to wrong use of ber_scanf() (CVE-2019-14867) * ipa: Batch API logging user passwords to /var/log/httpd/error_log (CVE-2019-10195) SL7 x86_64 ipa-client-4.6.5-11.el7_7.4.x86_64.rpm ipa-debuginfo-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-4.6.5-11.el7_7.4.x86_64.rpm ipa-server-trust-ad-4.6.5-11.el7_7.4.x86_64.rpm noarch ipa-client-co [More…]
hw: TSX Transaction Asynchronous Abort (TAA) (CVE-2019-11135) * QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) SL7 x86_64 qemu-img-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-common-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-debuginfo-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-tools-1.5.3-167.el7_7.4.x86_64.rpm – Scien [More…]
security update
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
Several security issues were fixed in SpamAssassin.
An update that fixes 5 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
security update
An update that solves 10 vulnerabilities and has 11 fixes is now available.
Sudo could allow unintended access to the administrator account.
git: arbitrary code execution via .gitmodules (CVE-2018-17456) SL6 x86_64 git-1.7.1-10.el6_10.x86_64.rpm git-daemon-1.7.1-10.el6_10.x86_64.rpm git-debuginfo-1.7.1-10.el6_10.x86_64.rpm i386 git-1.7.1-10.el6_10.i686.rpm git-daemon-1.7.1-10.el6_10.i686.rpm git-debuginfo-1.7.1-10.el6_10.i686.rpm noarch emacs-git-1.7.1-10.el6_10.noarch.rpm emacs-git-el-1.7.1- [More…]
Several security issues were fixed in the kernel.
An update for git is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
