Menu

Quote

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in libjpeg-turbo.

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

DPDK could be made to consume resources if it received specially crafted input.

Update to version 1.9.4. Resolves CVE-2019-10086.

bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes —- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix issue with buffer size and TLS PRF handling. * Add support for D-Bus non-root ObjectManager. iwd 1.0: * Add support for stable D-Bus interfaces. * Add […]

bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes —- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix issue with buffer size and TLS PRF handling. * Add support for D-Bus non-root ObjectManager. iwd 1.0: * Add support for stable D-Bus interfaces. * Add […]

bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes —- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix issue with buffer size and TLS PRF handling. * Add support for D-Bus non-root ObjectManager. iwd 1.0: * Add support for stable D-Bus interfaces. * Add […]

Update to version 1.9.4. Resolves CVE-2019-10086.

The 5.3.11 stable kernel update contains a number of important security updates across the tree, including mitigations for the most recent hardware issues disclosed on Nov 12. —- The 5.3.9 update contains a number of important fixes across the tree —- Update to upstream 2.1-22. 20190618

The 5.3.11 stable kernel update contains a number of important security updates across the tree, including mitigations for the most recent hardware issues disclosed on Nov 12. —- The 5.3.9 update contains a number of important fixes across the tree —- Update to upstream 2.1-22. 20190618

security update

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves one vulnerability and has two fixes is now available.

built version 0.10.5 fix CVE-2019-18837 —- built version 0.10.4 —- built version 0.10.3

**MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed: CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997

This update brings security updates for OpenJDK 13 and updates it to most current version 13.0.1.9.

built version 0.10.5 fix CVE-2019-18837

**MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed: CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997

rebase to 1.16.1

This update brings security updates for OpenJDK 13 and updates it to most current version 13.0.1.9.

security update

An update that solves two vulnerabilities and has one errata is now available.

Several vulnerabilities were discovered in Ampache, a web-based audio file management system.

Bash could be made to crash or execute arbitrary code if it received a specially crafted input.

In haml, when using user input to perform tasks on the server, characters like ” ‘ must be escaped properly. In this case, the ‘ character was missed. An attacker can manipulate the input to introduce additional

fixed multiple security bugs

Security fix CVE-2019-16275 (AP mode PMF disconnection protection bypass)

Fix CVE-2019-3463, CVE-2019-3464 and CVE-2019-1000018.

An update that contains security fixes can now be installed.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, cross-site scripting or denial of service.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

fixed multiple security bugs

Fix CVE-2019-3463, CVE-2019-3464 and CVE-2019-1000018.

– fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that solves three vulnerabilities and has four fixes is now available.

An update that fixes one vulnerability is now available.

GDAL through 3.0.1 had a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold was exceeded.

New kernel packages are available for Slackware 14.2 to fix security issues.

An update that fixes one vulnerability is now available.

Applications using FriBidi could be made to crash or run programs as your login if it displayed specially crafted text.

security update

Alex Murray discovered a stack-based buffer overflow vulnerability in fribidi, an implementation of the Unicode Bidirectional Algorithm algorithm, which could result in denial of service or potentially the execution of arbitrary code, when processing a large number of unicode

security update

It was discovered that Expat did not properly handle internal entities closing the doctype, potentially resulting in denial of service or information disclosure if a malformed XML file is processed (CVE-2019-15903).

Chromium-browser 78.0.3904.87 fixes security issues: Multiple flaws were found in the way Chromium 77.0.3865.120 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose

Updated freetds packages fix security vulnerability: Felix Wilhelm discovered that FreeTDS incorrectly handled certain types after a protocol downgrade. A remote attacker could use this issue to cause FreeTDS to crash, resulting in a denial of service, or possibly

Updated python and python3 packages fix security vulnerabilities: It was discovered that Python incorrectly parsed certain email addresses. A remote attacker could possibly use this issue to trick Python applications into accepting email addresses that should be denied (CVE-2019-16056).

Updated unbound packages fix security vulnerability: Versions before 1.9.4 allow accesses to uninitialized memory, which would permit remote attackers to trigger a crash (CVE-2019-16866).

The updated packages fix security issues: Use-after-free when creating index updates in IndexedDB. (CVE-2019-11757)

The updated packages fix several bugs and some security issues: Use-after-free when creating index updates in IndexedDB. (CVE-2019-11757)

Updated proftpd package fixes security vulnerabilities: It was discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands (CVE-2019-12815).

The package linux-hardened before version 5.3.7.b-1 is vulnerable to arbitrary code execution.

An update for cri-o is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for mediawiki123 is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in WebKitGTK+.

An update that fixes 9 vulnerabilities is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

An update for openstack-octavia is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

security update

The package qt5-webengine before version 5.13.2-2 is vulnerable to arbitrary code execution.

An update that fixes 21 vulnerabilities is now available.

An update that fixes 21 vulnerabilities is now available.

Rebasing to 2.26.x For release info please see https://www.webkitgtk.org/2019/09/09/webkitgtk2.26.0-released.html and https://www.webkitgtk.org/2019/09/23/webkitgtk2.26.1-released.html CVE fixes: CVE-2019-8625, CVE-2019-8720, CVE-2019-8769, CVE-2019-8771

An update that fixes two vulnerabilities is now available.

– fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

**PHP version 7.3.11** (24 Oct 2019) **Core:** * Fixed bug php#78535 (auto_detect_line_endings value not parsed as bool). (bugreportuser) * Fixed bug php#78620 (Out of memory error). (cmb, Nikita) **Exif :** * Fixed bug php#78442 (‘Illegal component’ on exif_read_data since PHP7) (Kalle) **FPM:** * Fixed bug php#78599 (env_path_info underflow in fpm_main.c can lead to RCE).

Updated libxslt package fixes security vulnerabilities: * In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains

Updated libsoup package fixes security vulnerability: It was discovered that libsoup incorrectly handled parsing certain NTLM messages. If a user or automated system were tricked into connecting to a malicious server, a remote attacker could possibly use this issue to

Updated aspell packages fix security vulnerability: libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated character (CVE-2019-17544).

Updated golang packages fix security vulnerability: Daniel Mandragona discovered that invalid DSA public keys can cause a panic in dsa.Verify(), resulting in denial of service (CVE-2019-17596).

Updated ansible package fixes security vulnerabilities: ansible-playbook -k and ansible cli tools prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them

An update that fixes 21 vulnerabilities is now available.

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

**PHP version 7.2.24** (24 Oct 2019) **Core:** * Fixed bug php#78535 (auto_detect_line_endings value not parsed as bool). (bugreportuser) * Fixed bug php#78620 (Out of memory error). (cmb, Nikita) **Exif:** * Fixed bug php#78442 (‘Illegal component’ on exif_read_data since PHP7) (Kalle) **FPM:** * Fixed bug php#78599 (env_path_info underflow in fpm_main.c can lead to RCE).

security update

security update

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3287

Upstream details at : https://access.redhat.com/errata/RHSA-2019:3281