Menu

Quote

security update

The updated packages fix some problems found in version 86 and security vulnerabilities. References: – https://bugs.mageia.org/show_bug.cgi?id=27630

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 8 vulnerabilities, contains one feature and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

security update

security update

David Benjamin discovered a flaw in the GENERAL_NAME_cmp() function which could cause a NULL dereference, resulting in denial of service. Additional details can be found in the upstream advisory:

An update that solves 6 vulnerabilities and has one errata is now available.

An update for mariadb-galera is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of High. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable (CVE-2020-26970).

In PDFResurrect before 0.20, lack of header validation checks causes a heap-buffer-overflow in pdf_get_version() (CVE-2020-20740). References: – https://bugs.mageia.org/show_bug.cgi?id=27704

Mutt before 2.0.2 did not ensure that $ssl_force_tls was processed if an IMAP server’s initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle (CVE-2020-28896).

Security fix for CVE-2020-8037

security update

security update

The package musl before version 1.2.1-2 is vulnerable to arbitrary code execution.

The package webkit2gtk before version 2.30.3-1 is vulnerable to arbitrary code execution.

The package gitea before version 1.12.6-1 is vulnerable to insufficient validation.

The package neomutt before version 20201120-1 is vulnerable to silent downgrade.

The package matrix-synapse before version 1.20.1-1 is vulnerable to denial of service.

security update

Two vulnerabilities in the certificate list syntax verification and in the handling of CSN normalization were discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can take advantage of these

Several vulnerabilities were discovered in salt. CVE-2020-16846

An update that fixes 5 vulnerabilities, contains one feature is now available.

An update that fixes 10 vulnerabilities is now available.

Chiaki Ishikawa discovered a stack overflow in SMTP server status handling which could potentially result in the execution of arbitrary code.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

security update

An update that fixes one vulnerability is now available.

An update is now available for Red Hat Ceph Storage 4.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

An update for rh-php73-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

An update that fixes 10 vulnerabilities is now available.

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This update upgrades Thunderbird to version 78.5.0. * Mozilla: Parsing mismatches could confuse and bypass security sanitizer for chrome privileged code (CVE-2020-26951) * Mozilla: Memory safety bugs fixed in Firefox 83 and Firefox ESR 78.5 (CVE-2020-26968) * Mozilla: Variable time processing of cross-origin images during drawImage calls (CVE-2020-16012) * Mozilla: Fullscreen could be enable [More…]

An update for faq is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat Ansible Tower 3.7.4-1 – RHEL7 Container 2. Description: * Fixed two jQuery vulnerabilities (CVE-2020-11022, CVE-2020-11023) * Improved Ansible Tower’s web service configuration to allow for

An update for rh-mariadb103-mariadb and rh-mariadb103-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

The package swtpm before version 0.5.1-1 is vulnerable to privilege escalation.

The package rclone before version 1.53.3-1 is vulnerable to private key recovery.

An update that fixes two vulnerabilities is now available.

Some issues have been found in qemu, a fast processor emulator. All issues are related to assertion failures, out-of-bounds access

Update to WebKitGTK 2.30.3: * Fix backdrop filters with rounded borders. * Fix scrolling iframes when async scrolling is enabled. * Allow applications to handle drag and drop on the web view again. * Update Outlook user agent quirk. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-9983, CVE-2020-13584

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

Guenal Davalan reported a flaw in x11vnc, a VNC server to allow remote access to an existing X session. x11vnc creates shared memory segments with 0777 mode. A local attacker can take advantage of this flaw for information disclosure, denial of service or interfering with the VNC

security update

Fix for multiple CVEs

fix CVE-2020-27780: authentication bypass when the user doesn’t exist

Update to upstream 17.9.0 for bug and security fixes

An update that fixes 10 vulnerabilities, contains one feature is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 12 vulnerabilities is now available.

security update

An update that solves 26 vulnerabilities and has 32 fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 26 vulnerabilities and has 32 fixes is now available.

security update

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that solves 12 vulnerabilities and has 103 fixes is now available.

An update that fixes one vulnerability is now available.