Update to 2.6.7
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
The package libnghttp2 before version 1.39.2-1 is vulnerable to denial of service.
The package go-pie before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.
The package go before version 2:1.12.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.
The package gettext before version 0.20.1-1 is vulnerable to arbitrary code execution.
An update for pango is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update that fixes two vulnerabilities is now available.
Ceph could be made to crash if it received specially crafted network traffic.
Ghostscript could be made to access arbitrary files if it opened a specially crafted file.
Two security vulnerabilities were found in the Apache HTTP server. CVE-2019-10092
USN-4110-1 introduced a regression in Dovecot.
An update for jenkins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for pango is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update is now available for Red Hat Ceph Storage 3.3 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that contains security fixes can now be installed.
An update that fixes 9 vulnerabilities is now available.
An update that solves two vulnerabilities and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes 6 vulnerabilities is now available.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
security update
An update that solves 7 vulnerabilities and has three fixes is now available.
Several vulnerabilities have been found in the Apache HTTPD server. CVE-2019-9517
ghostscript: -dSAFER escape via .buildfont1 (701394) (CVE-2019-10216) SL7 x86_64 ghostscript-9.25-2.el7_7.1.i686.rpm ghostscript-9.25-2.el7_7.1.x86_64.rpm ghostscript-cups-9.25-2.el7_7.1.x86_64.rpm ghostscript-debuginfo-9.25-2.el7_7.1.i686.rpm ghostscript-debuginfo-9.25-2.el7_7.1.x86_64.rpm libgs-9.25-2.el7_7.1.i686.rpm libgs-9.25-2.el7_7.1.x86_64.rpm ghostsc [More…]
zziplib: Bus error caused by loading of a misaligned address inzzip/zip.c (CVE-2018-6541) * zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c (CVE-2018-16548) SL7 x86_64 zziplib-0.13.62-11.el7.i686.rpm zziplib-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62-11.el7.x86_64.rpm zziplib-utils-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62- [More…]
opensc: Buffer overflows handling responses from Muscle Cards in card- muscle.c:muscle_list_files() (CVE-2018-16391) * opensc: Buffer overflows handling responses from TCOS Cards in card- tcos.c:tcos_select_file() (CVE-2018-16392) * opensc: Buffer overflows handling responses from Gemsafe V1 Smartcards in pkcs15-gemsafeV1.c:gemsafe_get_cert_len() (CVE-2018-16393) * opensc: Buffer overflow h [More…]
gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password (CVE-2019-3827) SL7 x86_64 gvfs-1.36.2-3.el7.i686.rpm gvfs-smb-1.36.2-3.el7.x86_64.rpm gvfs-afp-1.36.2-3.el7.x86_64.rpm gvfs-mtp-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.x86_64.rpm gvfs-client-1.36.2-3.el7.x86_64.rpm gvfs [More…]
Security fix for CVE-2019-13509
An update that fixes three vulnerabilities is now available.
An update for ruby is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
An update that contains security fixes can now be installed.
New kernel packages are available for Slackware 14.2 to fix a security issue.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Multiple vulnerabilities have been found in xymon, the network monitoring application. Remote attackers might leverage these vulnerabilities in the CGI parsing code (including buffer overflows and XSS) to cause denial of service, or any other unspecified impact.
Update to v1.15.2 + carry upstream #81330
Even Rouault found an issue in tiff, a library providing support for the Tag Image File Format. Wrong handling off integer overflow checks, that are based on undefined
Addresses CVE-2019-14462 and CVE-2019-14463
Addresses CVE-2019-14462 and CVE-2019-14463
Update to Node.js 10.6.13
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
An update that solves one vulnerability and has two fixes is now available.
An update that solves three vulnerabilities and has two fixes is now available.
It was discovered that there was a remote arbitrary code vulnerability in commons-beanutils, a set of utilities for manipulating JavaBeans code.
The package nginx before version 1.16.1-1 is vulnerable to denial of service.
The package nginx-mainline before version 1.17.3-1 is vulnerable to denial of service.
The package firefox before version 68.0.2-1 is vulnerable to information disclosure.
The package subversion before version 1.12.2-1 is vulnerable to denial of service.
The package libreoffice-still before version 6.2.6-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure.
