An update that solves four vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has four fixes is now available.
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.
Several security issues were fixed in file.
An update for openstack-octavia is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for ansible is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes 18 vulnerabilities is now available.
Security fix CVE-2019-9210
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
An update that fixes three vulnerabilities is now available.
An update that fixes four vulnerabilities is now available.
An update that solves 8 vulnerabilities and has 73 fixes is now available.
Several security issues identified in ikiwiki fixed by updating to version 3.20190228. See references for details References: – https://bugs.mageia.org/show_bug.cgi?id=24453
An update that fixes two vulnerabilities is now available.
An update is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for openstack-octavia is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for openstack-ceilometer is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
An update for haproxy is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for haproxy is now available for Red Hat OpenShift Container Platform 3.10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Multiple vulnerabilities have been found in Oracles JDK and JRE software suites.
Multiple vulnerabilities have been found in BIND, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code.
A vulnerability was discovered in XRootD which could lead to the remote execution of code.
Multiple Information Disclosure vulnerabilities in OpenSSL allow attackers to obtain sensitive information.
A vulnerability in the GNU C Library could result in a Denial of Service condition.
security update
security update
Multiple buffer overflow security issues have been found in libsdl2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard.
Multiple buffer overflow security issues have been found in libsdl1.2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard.
cockpit: Crash when parsing invalid base64 headers (CVE-2019-3804) SL7 x86_64 cockpit-173.2-1.el7.x86_64.rpm cockpit-bridge-173.2-1.el7.x86_64.rpm cockpit-debuginfo-173.2-1.el7.i686.rpm cockpit-debuginfo-173.2-1.el7.x86_64.rpm cockpit-ws-173.2-1.el7.i686.rpm cockpit-ws-173.2-1.el7.x86_64.rpm cockpit-doc-173.2-1.el7.x86_64.rpm cockpit-173.2-1.el7.src.rpm noa [More…]
openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) (CVE-2018-5407) Bug Fix(es): * Perform the RSA signature self-tests with SHA-256 SL7 x86_64 openssl-1.0.2k-16.el7_6.1.x86_64.rpm openssl-debuginfo-1.0.2k-16.el7_6.1.i686.rpm openssl-debuginfo-1.0.2k-16.el7_6.1.x86_64.rpm openssl-libs-1.0.2k-16.el7_6.1.i686.rpm openssl-libs-1.0.2k-16.el [More…]
An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Updates for rh-dotnetcore10-dotnetcore, rh-dotnetcore11-dotnetcore, rh-dotnet21-dotnet, and rh-dotnet22-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
It was found that the fix for CVE-2018-19758 was incomplete. That has been addressed in this update. The description for CVE-2018-19758 follows:
An update for cockpit is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Ross Geerlings discovered that the XMLTooling library didn’t correctly handle exceptions on malformed XML declarations, which could result in denial of service against the application using XMLTooling.
LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.
An update that solves 8 vulnerabilities and has two fixes is now available.
Several security vulnerabilities were discovered in Zabbix, a server/client network monitoring solution. CVE-2016-10742
The package pacman before version 5.1.3-1 is vulnerable to arbitrary code execution.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0462
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
poppler could be made to crash if it opened a specially craftedfile.
A vulnerability in GNU Wget which could allow an attacker to obtain sensitive information.
Multiple vulnerabilities have been found in systemd, the worst of which may allow execution of arbitrary code.
Multiple vulnerabilities have been discovered in rdesktop, the worst of which could result in the remote execution of arbitrary code.
security update
A vulnerability in Tar could led to a Denial of Service condition.
Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.
Multiple vulnerabilities have been found in cURL, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec, that could be leveraged to cause a denial of service or possibly remote code execution.
Clement Lecigne discovered a use-after-free issue in chromium’s file reader implementation. A maliciously crafted file could be used to remotely execute arbitrary code because of this problem.
Input validation errors in Zsh could result in arbitrary code execution.
Multiple vulnerabilities have been found in Keepalived, the worst of which could allow an attacker to cause Denial of Service condition.
Several security vulnerabilities have been discovered in symfony, a PHP web application framework. Numerous symfony components are affected: Security, bundle readers, session handling, SecurityBundle,
security update
An update that fixes one vulnerability is now available.
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF extension had multiple cases of invalid memory access and rename() was implemented insecurely.
Security fix for CVE-2018-15587
An update that solves one vulnerability and has 5 fixes is now available.
An update that fixes two vulnerabilities is now available.
New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.
An update that solves 5 vulnerabilities and has 6 fixes is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0230
An update that solves three vulnerabilities and has one errata is now available.
An update that fixes 9 vulnerabilities is now available.
An update that fixes 15 vulnerabilities is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –
## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –
A flaw was found in Nagios Core version 4.4.1 and earlier. The qh_help function is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket (CVE-2018-13441).
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. […]
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a […]
When symmetric encryption is used, data can be injected through the passphrase property of the gnupg.GPG.encrypt() and gnupg.GPG.decrypt() methods. The supplied passphrase is not validated for newlines, and the library passes –passphrase-fd=0 to the gpg executable, which expects the passphrase on the first line of stdin, and the ciphertext to be decrypted
NVIDIA graphics drivers could be made to expose sensitive information.
An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update that solves two vulnerabilities and has one errata is now available.
An update that solves four vulnerabilities and has four fixes is now available.
An update that solves one vulnerability and has one errata is now available.
security update
Several security issues were fixed in PHP.
– https://www.drupal.org/project/link/releases/7.x-1.6 – https://www.drupal.org/sa-contrib-2019-020 – https://www.drupal.org/sa- core-2019-003 – https://www.drupal.org/project/link/releases/7.x-1.5 – https://www.drupal.org/project/link/releases/7.x-1.5-beta3
## 1.7.1 – #475: “Loose” lists will now contain paragraphs in all items, not just some. – #433: Links will no longer be double nested – #525: The info- string when beginning a code block may now contain non-word characters (e.g. `c++`) – #561: The `mbstring` extension (which we already depend on) has been added […]
Fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165.
– bugfix {foreach} using new style property access like {$item@property} on Smarty 2 style named foreach loop could produce errors https://github.com/smarty-php/smarty/issues/484 31.08.2018 – bugfix some custom left and right delimiters like ‘{^’ ‘^}’ did not work
