An update for rh-haproxy18-haproxy is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for CloudForms Management Engine 5.10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for atomic-openshift-web-console is now available for Red Hat Openshift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes 17 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update that fixes four vulnerabilities is now available.
A flaw was discovered in the CalDAV feature in httpd of the Cyrus IMAP server, leading to denial of service or potentially the execution of arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
security update
An update that solves one vulnerability and has one errata is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 5 vulnerabilities is now available.
An update that solves two vulnerabilities and has 13 fixes is now available.
An update that fixes four vulnerabilities is now available.
Update to version 3.0.10, which fixes a security issue (a buffer overrun vulnerability in the httpd daemon, CVE-2019-11356).
An update that fixes one vulnerability is now available.
Hanno Bck discovered that Evolution was vulnerable to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security bar with encryption and signature information above the message
security update
Update to version 3.0.10, which fixes a security issue (a buffer overrun vulnerability in the httpd daemon, CVE-2019-11356).
Update to version 2.8 from upstream, Security fix for [CVE-2019-11555]
security update
An update that fixes four vulnerabilities is now available.
An update that solves 24 vulnerabilities and has two fixes is now available.
A vulnerability in Exim could allow a remote attacker to execute arbitrary commands.
An update that fixes one vulnerability is now available.
An update for qpid-proton is now available for Red Hat OpenStack Platform 14 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for qpid-proton is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for qpid-proton is now available for Red Hat OpenStack Platform 14 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Vincent Tondellier reported that the qemu update issued as DSA 4454-1 did not correctly backport the support to define the md-clear bit to allow mitigation of the MDS vulnerabilities. Updated qemu packages are now available to correct this issue.
Several vulnerabilities have been found in the poppler PDF rendering library, which could result in denial of service or possibly other unspecified impact when processing malformed or maliciously crafted files.
The Qualys Research Labs reported a flaw in Exim, a mail transport agent. Improper validation of the recipient address in the deliver_message() function may result in the execution of arbitrary commands.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
It was discovered that there was a cross-site scripting (XSS) vulnerability in the Django web development framework. For Debian 8 “Jessie”, this issue has been fixed in python-django version
security update
An update for systemd is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
The package python-django before version 2.2.2-1 is vulnerable to cross-site scripting.
The package python2-django before version 1.11.21-1 is vulnerable to cross-site scripting.
An update that contains security fixes can now be installed.
An update that solves 5 vulnerabilities and has 6 fixes is now available.
An update that fixes four vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes 8 vulnerabilities is now available.
An update that solves 5 vulnerabilities and has 6 fixes is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes 16 vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
– https://www.drupal.org/project/views/releases/7.x-3.23 – https://www.drupal.org/project/views/releases/7.x-3.22 – https://www.drupal.org/project/views/releases/7.x-3.21 – [Less critical – Cross site scripting – SA-CONTRIB-2019-036](https://www.drupal.org/sa- contrib-2019-036) – [Moderately critical – Information disclosure – SA-
– https://www.drupal.org/project/module_filter/releases/7.x-2.2 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-042](https://www.drupal.org/sa-contrib-2019-042)
– https://www.drupal.org/project/path_breadcrumbs/releases/7.x-3.4 – [Less critical – Cross site scripting – SA- CONTRIB-2019-027](https://www.drupal.org/sa-contrib-2019-027)
– https://www.drupal.org/project/context/releases/7.x-3.10 – [Moderately critical – Cross site scripting – SA- CONTRIB-2019-028](https://www.drupal.org/sa-contrib-2019-028) – https://www.drupal.org/project/context/releases/7.x-3.9 – https://www.drupal.org/project/context/releases/7.x-3.8
– https://www.drupal.org/project/xmlsitemap/releases/7.x-2.6 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.5 – https://www.drupal.org/project/xmlsitemap/releases/7.x-2.4 – [Moderately critical – Information Disclosure – SA- CONTRIB-2018-053](https://www.drupal.org/sa-contrib-2018-053) –
– https://www.drupal.org/project/uuid/releases/7.x-1.2 – https://www.drupal.org/project/uuid/releases/7.x-1.1 – [Moderately critical – Arbitrary file upload – SA-CONTRIB-2018-045](https://www.drupal.org/sa- contrib-2018-045)
– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)
Update to 4.6.6 Various bugfixes on the 4.6 branch
– https://www.drupal.org/project/ds/releases/7.x-2.16 – https://www.drupal.org/project/ds/releases/7.x-2.15 – [Critical – Cross site scripting (XSS) – SA-CONTRIB-2018-019](https://www.drupal.org/sa- contrib-2018-019)
An update that fixes one vulnerability is now available.
An update that fixes 6 vulnerabilities is now available.
Insufficient sanitization of the query parameter in search_opensearch.php could lead to reflected cross-site scripting or iframe injection.
Update to 8.2.0.
security update
The package live-media before version 2019.05.12-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
The package curl before version 7.65.0-1 is vulnerable to arbitrary code execution.
The package lib32-curl before version 7.65.0-1 is vulnerable to arbitrary code execution.
The package lib32-libcurl-compat before version 7.65.0-1 is vulnerable to arbitrary code execution.
The package lib32-libcurl-gnutls before version 7.65.0-1 is vulnerable to arbitrary code execution.
The package libcurl-gnutls before version 7.65.0-1 is vulnerable to arbitrary code execution.
The package libcurl-compat before version 7.65.0-1 is vulnerable to arbitrary code execution.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes 13 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes 6 vulnerabilities is now available.
security update
Ben Barnea and colleagues from VDOO discovered several vulnerabilities in miniupnpd, a small daemon that provides UPnP Internet Gateway Device and Port Mapping Protocol services.
– https://www.drupal.org/project/entity/releases/7.x-1.9 – https://www.drupal.org/sa-contrib-2018-013
Microarchitectural Data Sampling speculative side channel [XSA-297, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091] additional patches so above applies cleanly work around grub2 issues in dom0
This is the 6 month notification for the retirement of Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions (E4S) and Telecommunications Update Service (TUS). This notification applies only to those customers subscribed to the Update Services for SAP Solutions (E4S) and
An update for go-toolset-1.11 and go-toolset-1.11-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for JBoss Core Services on RHEL 6 and RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Red Hat JBoss Core Services Pack Apache Server 2.4.29 Service Pack 2 zip release for RHEL 6 and RHEL 7 is available. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Nightwatch Cybersecurity Research team identified a XSS vulnerability in tomcat7. The SSI printenv command echoes user provided data without escaping. SSI is disabled by default. The printenv command is intended
– https://www.drupal.org/project/entity/releases/7.x-1.9 – https://www.drupal.org/sa-contrib-2018-013
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
