The 5.6.8 stable kernel update contains a number of important fixes across the tree.
The 5.6.8 stable kernel update contains a number of important fixes across the tree.
security update
An update that solves two vulnerabilities and has one errata is now available.
Several vulnerabilities have been discovered in otrs2 (Open source Ticket Request System)
An update that fixes one vulnerability is now available.
OpenJDK 14 April CPU update
Security fix for CVE-2020-5260 and CVE-2020-11008 CVE-2020-5260 – From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.4.txt): > With a crafted URL that contains a newline in it, the credential > helper machinery can be fooled to give credential information for > a wrong host. The
Update to 2.9.10 * Fix CVE-2019-19956, CVE-2019-20388 and CVE-2020-7595
security update
security update
security update
security update
security update
It was discovered that there was a integer signedness error in the miniupnpc UPnP client that could allow remote attackers to cause a denial of service attack.
An issue has been found in pound, A request smuggling vulnerability was discovered in pound, a everse proxy, load balancer and HTTPS front-end for Web servers, that may allow
Two issues have been found in w3m, WWW browsable pager with excellent tables/frames support.
An issue has been found in yodl, a pre-document language. Hanno Bock discovered that there was a buffer over-read vulnerability.
An update that fixes 6 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves 7 vulnerabilities and has 77 fixes is now available.
An update that solves 7 vulnerabilities and has 77 fixes is now available.
An update that solves 13 vulnerabilities and has 157 fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves 6 vulnerabilities and has 8 fixes is now available.
An update that solves 13 vulnerabilities and has 157 fixes is now available.
security update
re2c could be made to execute arbitrary code if it received a specially crafted file.
An update that solves 15 vulnerabilities and has 8 fixes is now available.
An update that solves 10 vulnerabilities and has 89 fixes is now available.
An update that solves 5 vulnerabilities and has 7 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
security update
An update that solves 11 vulnerabilities and has 96 fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves 12 vulnerabilities and has 139 fixes is now available.
Several security issues were fixed in OpenEXR.
Update to latest upstream OpenVPN 2.4.9 release. It contains a security fix for CVE-2020-11810. This security issue is quite hard to abuse, requiring a fairly precise timing attack combined with guessing a just assigned peer-id reference. If successful, only a single client just initiating a new connection will experience a denial of service situation. This […]
6.2.6
Three issues have been found in php5, a server-side, HTML-embedded scripting language.
Hanno Boeck discovered that it was possible to create a cross site scripting attack on the webarchives of the Mailman mailing list manager, by sending a special type of attachement.
Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Fix rendering after a cross site navigation with PSON enabled and hardware acceleration forced. * Fix a crash in nested wayland compositor when closing a tab with PSON enabled. * Update Chrome and Firefox versions in user agent quirks. […]
Security fix for CVE-2020-5260 From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.5.txt): > With a crafted URL that contains a newline or empty host, or lacks > a scheme, the credential helper machinery can be fooled into > providing credential information that is not appropriate for the > protocol in use and host being
Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Update Chrome and Firefox versions in user agent quirks. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-11793
Update to version 1.26. Resolves CVE-2017-18640.
security update
It was discovered that python-reportlab, a Python library to create PDF documents, is prone to a code injection vulnerability while parsing a color attribute. An attacker can take advantage of this flaw to execute arbitrary code if a specially crafted document is processed.
security update
This update fixes the following security vulnerabilities: CVE-2018-20536, CVE-2018-20537, CVE-2018-20539, CVE-2018-20540
**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid pointer address). (cmb, Nikita) **CURL:** * Fixed bug php#79199 (curl_copy_handle() memory leak). (cmb) **Date:** * Fixed bug php#79396 (DateTime hour incorrect during DST jump forward). (Nate Brunette) **Iconv:**
3.2.3 —- New version 3.2.2 Security fix for CVE-2020-7044, CVE-2020-9428, CVE-2020-9430, CVE-2020-9431
Fix mistakes in Wayland wrapper change —- Fixes Wayland issue when running from terminal —- Update sound touch library, fixes some known security issues.
Security fix for CVE-2015-9541
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
Several vulnerabilities have been discovered in the OpenJDK Java runtime, resulting in denial of service, insecure TLS handshakes, bypass of sandbox restrictions or HTTP response splitting attacks.
Multiple vulnerabilities have been found in Git which might all allow attackers to access sensitive information.
The package lib32-openssl before version 1.1.1.g-1 is vulnerable to denial of service.
Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could allow remote attackers to execute arbitrary code. [More…]
Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities were found in OpenSSL, the worst of which could allow remote attackers to cause a Denial of Service condition.
python-twisted: HTTP request smuggling when presented with two Content-Length headers (CVE-2020-10108) * python-twisted: HTTP request smuggling when presented with a Content-Length and a chunked Transfer-Encoding header (CVE-2020-10109) SL7 x86_64 python-twisted-web-12.1.0-7.el7_8.x86_64.rpm – Scientific Linux Development Team
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for openshift-enterprise-hyperkube-container is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for openshift is now available for Red Hat OpenShift Container Platform 4.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
security update
An update for git is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
The package webkit2gtk before version 2.28.1-1 is vulnerable to arbitrary code execution.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
Bernd Edlinger discovered that malformed data passed to the SSL_check_chain() function during or after a TLS 1.3 handshake could cause a NULL dereference, resulting in denial of service.
security update
security update
The package openvpn before version 2.4.9-1 is vulnerable to denial of service.
An update that fixes one vulnerability is now available.
It was discovered that there was a path-traversal issue in Apache Shiro, a security framework for the Java programming language. A specially-crafted request could cause an authentication bypass.
An update that fixes 26 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file’s parent is a symlink to a directory outside of the
Following CVEs were reported against the jackson-databind source package :
Following CVEs were reported against the awl source package: CVE-2020-11728
security update
Fixes CVE-2020-1730
Security fix for CVE-2020-5260 From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.4.txt): > With a crafted URL that contains a newline in it, the credential > helper machinery can be fooled to give credential information for > a wrong host. The attack has been made impossible by forbidding > a newline character in any value
Bugfix release from Google for 80.0.3987.162. —- Update to 80.0.3987.162. Fixes the following CVEs: * CVE-2020-6450 * CVE-2020-6451 * CVE-2020-6452
An update that solves two vulnerabilities and has one errata is now available.
New openvpn packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.
With a crafted URL that contains a newline in it, the credential helper machinery can be fooled to give credential information for a wrong host. The attack has been made impossible by forbidding a newline character in any value passed via the credential protocol (CVE-2020-5260).
Chromium-browser 81.0.4044.92 fixes security issues: Multiple flaws were found in the way Chromium 80.0.3987.149 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code,
– New Firefox and NSS upstream update – More info at https://www.mozilla.org/en- US/firefox/75.0/releasenotes/
– New Firefox and NSS upstream update – More info at https://www.mozilla.org/en- US/firefox/75.0/releasenotes/
An update that fixes one vulnerability is now available.
