An update that solves 21 vulnerabilities and has 21 fixes is now available.
An update that solves 17 vulnerabilities and has 15 fixes is now available.
An update that fixes 5 vulnerabilities is now available.
net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution (CVE-2020-15862) SL6 x86_64 net-snmp-5.5-60.el6_10.2.x86_64.rpm net-snmp-debuginfo-5.5-60.el6_10.2.i686.rpm net-snmp-debuginfo-5.5-60.el6_10.2.x86_64.rpm net-snmp-libs-5.5-60.el6_10.2.i686.rpm net-snmp-libs-5.5-60.el6_10.2.x86_64.rpm net-snmp-devel-5.5-60.el6_10.2.i686.rpm [More…]
This update upgrades Thunderbird to version 78.4.3. * Mozilla: Write side effects in MCallGetProperty opcode not accounted for (CVE-2020-26950) SL6 x86_64 thunderbird-78.4.3-1.el6_10.x86_64.rpm thunderbird-debuginfo-78.4.3-1.el6_10.x86_64.rpm i386 thunderbird-78.4.3-1.el6_10.i686.rpm – Scientific Linux Development Team
An update that fixes 5 vulnerabilities is now available.
An update that solves 15 vulnerabilities and has 75 fixes is now available.
An update for microcode_ctl is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for microcode_ctl is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact
An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.4 Advances Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for microcode_ctl is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
security update
security update
Update to 87.0.4280.66. Fixes bugs and security holes. Yay! CVE-2020-16012 CVE-2020-16018 CVE-2020-16019 CVE-2020-16020 CVE-2020-16021 CVE-2020-16022 CVE-2020-16015 CVE-2020-16014 CVE-2020-16023 CVE-2020-16024 CVE-2020-16025 CVE-2020-16026 CVE-2020-16027 CVE-2020-16028 CVE-2020-16029 CVE-2020-16030 CVE-2020-16031 CVE-2020-16032 CVE-2020-16033 CVE-2020-16034 CVE-2020-16035
– Update to upstream 2.1-31. 20201118 – Removal of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68[1]; – Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up to 0x34[2]. [1] The microcode has been removed after reports of system hangs: https://github.com/intel/Intel-Linux-Processor- Microcode-Data-Files/issues/44 [2] Addresses CVE-2020-8695 for this platform.
Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.
Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.
Fix buffer overflow (RHBZ #1897485) A global buffer overflow was discovered in the check_chunk_name function via a crafted png file.
Multiple vulnerabilities were discovered in Zabbix, a network monitoring solution. An attacker may remotely execute code on the zabbix server, and redirect to external links through the zabbix web frontend.
Three issues have been found in golang-1.8, a Go programming language compiler version 1.8
Two issues have been found in golang-1.7, a Go programming language compiler version 1.7
A heap-based buffer overflow flaw was discovered in MuPDF, a lightweight PDF viewer, which may result in denial of service or the execution of arbitrary code if malformed documents are opened.
security update
An update that fixes three vulnerabilities is now available.
An update that fixes 16 vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that solves two vulnerabilities and has 12 fixes is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes 12 vulnerabilities is now available.
security update
An update that solves one vulnerability and has two fixes is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that solves one vulnerability, contains one feature and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
security update
An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
Release of OpenShift Serverless 1.11.0 2. Description: Red Hat OpenShift Serverless 1.11.0 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless
An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update that fixes one vulnerability is now available.
An update that fixes 29 vulnerabilities is now available.
An update that fixes 8 vulnerabilities is now available.
An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
Kerberos could be made to consume unlimited resources if it received specially crafted ASN.1.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for the virt:8.2 and virt-devel:8.2 modules is now available for Advanced Virtualization for RHEL 8.2.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Apache Ant uses various insecure temporary files possibly allowing local code execution.
A vulnerability in MIT Kerberos 5 could lead to a Denial of Service condition.
A vulnerability in libmaxminddb could lead to a Denial of Service condition.
In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation. (CVE-2020-0452)
The Kleopatra component before 20.07.80 for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary library. (CVE-2020-24972).
A flaw was found in Go standard library packages. Both the net/http/cgi and net/http/fcgi packages use a default Content-Type response header value of “text/html”, rather than “text/plain”. An attacker could exploit this in applications using these packages by uploading crafted files, allowing for a cross-site scripting attack (XSS) (CVE-2020-24553).
A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick was too tolerant against an invalid Transfer-Encoding header. This may lead to inconsistent interpretation between WEBrick and some HTTP proxy servers, which may allow the attacker to ”smuggle” a request (CVE-2020-25613).
Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. (CVE-2020-8694) Observable discrepancy in the RAPL interface for some Intel(R) Processors may
Update to latest upstream version.
security update
– Fix CVE-2020-28196 (DoS in ASN.1 parsing due to missing recursion depth checks) – fc32 + fc33 only: pull-up to rawhide
Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot.
CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452
USN-4607-1 introduced a regression in OpenJDK.
Li Fei found that libproxy, a library for automatic proxy configuration management, was vulnerable to a buffer overflow vulnerability when receiving a large PAC file from a server without a Content-Length header in the response.
A use-after-free was found in Thunderbird, which could potentially result in the execution of arbitrary code. For Debian 9 stretch, this problem has been fixed in version
Ken Gaillot discovered a vulnerability in the Pacemaker cluster resource manager: If ACLs were configured for users in the “haclient” group, the ACL restrictions could be bypassed via unrestricted IPC communication, resulting in cluster-wide arbitrary code execution with
security update
Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes
Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes
An update that solves 53 vulnerabilities, contains 14 features and has 5 fixes is now available.
libmaxminddb could be made to crash if it received specially crafted data.
USN-4171-1 introduced a regression in Apport.
An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
security update
security update
Several security issues were fixed in Intel Microcode.
raptor2 could be made to crash or run programs as your login if it opened a specially crafted file.
An update that fixes four vulnerabilities is now available.
An update that solves 18 vulnerabilities and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes 18 vulnerabilities is now available.
security update
The ppp de-capsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. The buffer should be big enough to hold the captured data, but it
It was discovered that ZeroMQ, a lightweight messaging kernel library does not properly handle connecting peers before a handshake is completed. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket
Firefox could be made to crash or run programs as your login if it opened a malicious website.
Fabian Vogt discovered a flaw in sddm before 0.19.0. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges (CVE-2020-28049). References:
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. (CVE-2019-19917) Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. (CVE-2019-19918)
ACL restrictions bypass. (CVE-2020-25654) References: – https://bugs.mageia.org/show_bug.cgi?id=27472 – https://www.openwall.com/lists/oss-security/2020/10/27/1
security update
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
