Menu

Quote

Server processes unencrypted bytes from man-in-the-middle. (CVE-2021-23214) libpq processes unencrypted bytes from man-in-the-middle. (CVE-2021-23222) References:

All FreeRDP clients prior to version 2.4.1 using gateway connections (‘/gt:rpc’) fail to validate input data. A malicious gateway might allow client memory to be written out of bounds. This issue has been resolved in version 2.4.1. If you are unable to update then use `/gt:http` rather than /gt:rdp connections if possible or use a […]

Server-side Request Forgery (SSRF) References: – https://bugs.mageia.org/show_bug.cgi?id=29592 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HMUJA5GZTPQ5WRYUCCK2GEZM4W43N7HH/

Privilege escalation that allows an attacker to add or remove data in any database or make configuration changes. (CVE-2021-38295) References: – https://bugs.mageia.org/show_bug.cgi?id=29548

security update

An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the mailman:2.1 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured (CVE-2021-41617) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssh-7.4p1-22.el7_9.x86_64.rpm openssh-askpass-7.4p1-22.el7_9.x86_64.rpm openssh-clients-7.4p1-22.e [More…]

krb5: NULL pointer dereference in process_tgs_req() in kdc/do_tgs_req.c via a FAST inner body that lacks server field (CVE-2021-37750) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 krb5-debuginfo-1.15.1-51.el7_9.i686.rpm krb5-debuginfo-1.15.1-51.el7_9.x86_64.rpm krb5- [More…]

kernel: use-after-free in drivers/infiniband/core/ucma.c ctx use-after- free (CVE-2020-36385) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * scsi: ibmvfc: Avoid link down on FS9100 canister reboot * crash in qla2x00_status_entry() because of corrupt srb * qedf driver: race c […]

Several security issues were fixed in FreeRDP.

Release of OpenShift Serverless Client kn 1.19.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Release of OpenShift Serverless 1.19.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat Integration Camel Extensions for Quarkus 2.2 is now GA. The purpose of this text-only errata is to inform you about the security issues fixed since the tech preview 2 release. Red Hat Product Security has rated this update as having a security impact

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rpm is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat Enterprise Linux 7.6 Telco Extended Update Support, and Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions.

Two issues have been found in libmodbus, a library for the Modbus protocol. Both issues are related to out of bound reads, which could result in a

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

LibreOffice could incorrectly validate document signatures.

Header injection via default_mimetype / default_charset mbstring may use pointer from some previous request Unexpected behavior with arrays and JIT Special character is breaking the path in xml function (CVE-2021-21707) XMLReader::getParserProperty may throw with a valid property

IPPUSB dissector crash (CVE-2021-39920). Modbus dissector crash (CVE-2021-39921). C12.22 dissector crash (CVE-2021-39922). PNRP dissector large loop (wnpa-sec-2021-11). Bluetooth DHT dissector large loop (CVE-2021-39924).

Updated rust packages fix security vulnerability This update mitigates a security concern in the Unicode standard, affecting source code containing “bidirectional override” Unicode codepoints: in some cases the use of those codepoints could lead to the reviewed code being

The chromium-browser-stable package has been updated to 96.0.4664.45 version that fixes multiples security vulnerabilities. For changes from 94.0.4606.71 (released on September 30, 2021) to the 96.0.4664.45 version, see referenced advisories.

An update that contains security fixes can now be installed.

The security update of Salt, a remote execution manager, to fix CVE-2021-21996 introduced a regression in salt/fileclient.py which raised an unexpected exception and made file.managed states fail.

An authenticated remote attacker can execute arbitrary code in Firebird, a relational database based on InterBase 6.0, by executing a malformed SQL statement. The only known solution is to disable external UDF libraries from being loaded. In order to achieve this,

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

jQuery UI 1.13.0

Upstream announcement: [WordPress 5.8.2 Security and Maintenance Release](https://wordpress.org/news/2021/11/wordpress-5-8-2-security-and- maintenance-release/)

jQuery UI 1.13.0

An update that fixes 16 vulnerabilities is now available.

An update that fixes 16 vulnerabilities is now available.

Multiple security vulnerabilities have been discovered in Salt, a powerful remote execution manager, that allow for local privilege escalation on a minion, server side template injection attacks, insufficient checks for eauth credentials, shell and command injections or incorrect validation of SSL

The package chromium before version 96.0.4664.45-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, content spoofing, information disclosure, same-origin policy bypass, sandbox escape and denial of service.

The package opera before version 81.0.4196.54-1 is vulnerable to multiple issues including arbitrary code execution, insufficient validation and access restriction bypass.

The package kubectl-ingress-nginx before version 1.0.4-1 is vulnerable to information disclosure.

security update

An update that fixes 12 vulnerabilities is now available.

An update for devtoolset-11-annobin is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for devtoolset-11-binutils is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in Mailman.

rpki-client 7.5 untrusted input: – Fail repository synchronisation after 15min runtime. – Limit the number of repositories per TAL. – Don’t allow `DOCTYPE` definitions in RRDP XML files. – Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files.

Security fix for CVE-2021-3927 and CVE-2021-3928

An update that fixes 10 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3801

Upstream details at : https://access.redhat.com/errata/RHSA-2021:4619

Upstream details at : https://access.redhat.com/errata/RHSA-2021:4044

Upstream details at : https://access.redhat.com/errata/RHSA-2021:4033

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3889

security update

Security fix for CVE-2021-40529

An update that contains security fixes and contains one feature can now be installed.

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rust-toolset-1.54-rust is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in Vim.

Apache Santuario – XML Security for Java is vulnerable to an issue where the “secureValidation” property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

An update that solves 14 vulnerabilities, contains four features and has 5 fixes is now available.

An update that fixes one vulnerability is now available.

An update for gcc-toolset-10-binutils is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The 5.14.17 stable kernel update contains a number of important fixes across the tree.

The 5.14.17 stable kernel update contains a number of important fixes across the tree.

The 5.14.17 stable kernel update contains a number of important fixes across the tree.

security update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

security update

security update

security update

security update

security update

Security and compatibility fixes

Security and compatibility fixes

Apache Tomcat, the servlet and JSP engine, did not properly release an HTTP upgrade connection for WebSocket connections once the WebSocket connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

Jacob Champion discovered two vulnerabilities in the PostgreSQL database system, which could result in man-in-the-middle attacks. For Debian 9 stretch, these problems have been fixed in version

The binary got built with Fedora mandatory compiler flags.

ImageMagick is updated 6.9.12.28 , soname bump , many security fixes —- Add scraper2vdr_serienposter_statt_banner.diff

ImageMagick is updated 6.9.12.28 , soname bump , many security fixes —- Add scraper2vdr_serienposter_statt_banner.diff

ImageMagick is updated 6.9.12.28 , soname bump , many security fixes —- Add scraper2vdr_serienposter_statt_banner.diff

OpenEXR could be made to crash or execute arbitrary code if it received a specially crafted EXR file.

Openafs packages have been updated to 1.9.1 for various bugfixes, and added a fix for security vulnerability: There exist in the wild AFS3 clients that improperly construct access control lists which are then stored to directories via RXAFS_StoreACL

This kernel-linus update is based on upstream 5.10.78 and fixes atleast the following security issues: A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability (CVE-2021-3760).

This kernel update is based on upstream 5.10.78 and fixes atleast the following security issues: A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability (CVE-2021-3760).

An update that solves 13 vulnerabilities and has 43 fixes is now available.

An update for freerdp is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

An update for gcc-toolset-10-annobin is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for gcc-toolset-10-gcc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for gcc-toolset-11-gcc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for gcc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the rust-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which