It was discovered that Docker could be made to expose sensitive information when processing URLs in container image manifests. A remote attacker could use this to trick the user and obtain the user’s registry credentials (CVE-2020-15157).
An update that solves 18 vulnerabilities and has one errata is now available.
An update that solves one vulnerability and has 35 fixes is now available.
SFD_GetFontMetaData() insufficient CVE-2020-5395 backport. (CVE-2020-25690) References: – https://bugs.mageia.org/show_bug.cgi?id=27563 – https://access.redhat.com/errata/RHSA-2020:4844
The latest release of mariadb fixes some undisclosed easily exploitable vulnerabilities. (CVE-2020-14765, CVE-2020-14776, CVE-2020-14789 and CVE-2020-14812). Additionally some bugs are fixed:
It was discovered that junit contained a local information disclosure vulnerability. On Unix like systems, the system’s temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system. This vulnerability does not […]
Vaisha Bernard discovered that blueman did not properly sanitize input on the D-Bus interface to blueman-mechanism. A local attacker could possibly use this issue to escalate privileges and run arbitrary code or cause a denial of service (CVE-2020-15238).
The suricata package has been updated to version 4.1.9, which fixes security issues and other bugs. See the upstream announcements for details. References: – https://bugs.mageia.org/show_bug.cgi?id=27475
An XSS Vulnerability exists in Webmin 1.941 and earlier affecting the Cluster Shell Commands Endpoint. A user may enter any XSS Payload into the Command field and execute it. Then, after revisiting the Cluster Shell Commands Menu, the XSS Payload will be rendered and executed. (CVE-2020-8820)
security update
In libexif/exif-entry.c, through libexif 0.6.21-2+deb9u4, compiler optimization could remove a buffer overflow check, making a buffer overflow possible with some EXIF tags.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that solves three vulnerabilities and has 7 fixes is now available.
It was discovered that raptor2, an RDF parser library, is prone to heap-based buffer overflow flaws, which could result in denial of service, or potentially the execution of arbitrary code, if a specially crafted file is processed.
security update
Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to run insecure deserialization, embed spam, perform various Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) attacks, escalate privileges, run arbitrary
netqmail could be made to crash if it received specially crafted input.
Update to CVE release 3001.3-1 for Python3 Includes fixes for CVE-2020-16846, CVE-2020-17490, CVE-2020-25592
Fix executable hardening (PIC/PIE)
Update to v2.1.4. Contains security fix for CVE-2020-15238.
Update to Chromium 86. A few big things here: 1. Upstream has made hardware accelerated video support (VAAPI) for Linux possible without patches. One key difference is that the patchset used previously in Fedora enabled it by default and upstream’s approach disables it by default. To enable Hardware accelerated video in chromium, open this link […]
An update that fixes 5 vulnerabilities is now available.
An update that solves three vulnerabilities and has 6 fixes is now available.
An update that fixes 7 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
security update
An update that solves three vulnerabilities and has 6 fixes is now available.
An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that fixes two vulnerabilities is now available.
An update that fixes 16 vulnerabilities is now available.
python-cryptography could be made to expose sensitive information over the network.
Several security issues were fixed in AccountsService.
GDM could be made to create privileged users.
Vaisha Bernard discovered that Blueman, a graphical bluetooth manager performed insufficient validation on a D-Bus interface, which could result in denial of service or privilege escalation.
There were several vulnerabilites reported against wordpress, as follows: CVE-2020-28032
An update that solves one vulnerability and has two fixes is now available.
Several security issues were fixed in Samba.
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
In junit4 the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system’s temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system. Both the SPICE client (spice-gtk) and server are affected by
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that solves 8 vulnerabilities and has 5 fixes is now available.
security update
An update that fixes one vulnerability is now available.
An update that fixes 7 vulnerabilities is now available.
An update that solves 8 vulnerabilities and has 5 fixes is now available.
This update corrects a regression in some Xen virtual machine environments. For reference the original advisory text follows. Several vulnerabilities have been discovered in the Linux kernel that
An update that fixes 6 vulnerabilities is now available.
An update that solves one vulnerability and has three fixes is now available.
A vulnerability in the handling of normalization with modrdn was discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can use this flaw to cause a denial of service (slapd daemon crash) via a
An update that fixes two vulnerabilities is now available.
Several issues have been found in cimg, a powerful image processing library.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update that solves one vulnerability and has three fixes is now available.
An update that solves one vulnerability and has three fixes is now available.
An update that fixes three vulnerabilities is now available.
Two issues have been found in dompurify.js, an XSS sanitizer for HTML, MathML and SVG. Both issues are related to mXSS issues in SVG- or MATH-elements.
security update
Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2.4.37 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact
Red Hat JBoss Core Services Pack Apache Server 2.4.37 Service Pack 5 zip release for RHEL 6, RHEL 7, RHEL 8 and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for openstack-cinder is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for openstack-selinux is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Several security issues were fixed in Perl.
An update that fixes three vulnerabilities is now available.
An update for jenkins-2-plugins, openshift-clients, podman, runc, and skopeo is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for Red Hat Satellite 6.8 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
security update
Open Liberty 20.0.0.11 Runtime is now available from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes 16 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes 5 vulnerabilities is now available.
Several vulnerabilities were found in package phpmyadmin. CVE-2019-19617
An update that solves one vulnerability and has two fixes is now available.
Update to freetype 2.10.4 which fixes security flaw CVE-2020-15999.
