**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).
**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.
**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).
**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.
An update that fixes two vulnerabilities is now available.
An update that solves 5 vulnerabilities and has 5 fixes is now available.
An update that contains security fixes can now be installed.
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An unsafe shell call enabling shell injection via a user ID was corrected in gpg-key2ps, a tool to generate a PostScript file with OpenPGP key fingerprint slips.
The update of proftpd-dfsg issued as DLA-1753-1 caused a regression when using the sftp module. Login to the sftp server was impossible when the SFTPPAMEngine option was turned on (#926719).
Memcached could be made to crash if it received specially crafted network traffic.
Fix CVE-2019-11372
Fix CVE-2019-11372
**turba 4.2.24** * [mjr] SECURITY: Fix XSS vulnerability in display of contact tags. * [jan] Clarify objectClass filter examples for LDAP backends (Ralf Lang).
**horde 5.2.21** * [mjr] SECURITY: Fix XSS vulnerability in the Cloud Block.
security update
libvirt-domain.c in libvirt supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required. This could lead to could lead to potentially disclosing unintended
An update that fixes two vulnerabilities is now available.
An update for openstack-neutron is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Dovecot could be made to crash if it received specially crafted network traffic.
An update for openstack-neutron is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for openstack-ceilometer is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
An update for openstack-neutron, openstack-neutron-lbaas, and python-networking-bigswitch is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact
An update for openstack-cinder is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update is now available for Red Hat Ceph Storage 3.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
A minor version update (from 7.2 to 7.3) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact
An update that solves three vulnerabilities and has four fixes is now available.
WavPack could be made to crash if it received a speciallycrafted file.
security update
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has four fixes is now available.
An update that solves two vulnerabilities and has three fixes is now available.
An update that fixes two vulnerabilities is now available.
An update that solves 11 vulnerabilities and has one errata is now available.
An update for rh-python35-python is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Evince could be made to expose sensitive information if it receiveda specially crafted file.
GStreamer Base Plugins could be made to crash or run programs if it received specially crafted network traffic.
Several security issues were fixed in MySQL.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes 16 vulnerabilities is now available.
An update that fixes 7 vulnerabilities is now available.
An update that fixes four vulnerabilities is now available.
An update that solves 8 vulnerabilities and has one errata is now available.
An update that fixes 8 vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that solves 5 vulnerabilities and has three fixes is now available.
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves one vulnerability and has three fixes is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
A use-after-free vulnerability was discovered in the png_image_free() function in the libpng PNG library, which could lead to denial of service or potentially the execution of arbitrary code if a malformed image is processed.
security update
An update that solves 13 vulnerabilities and has one errata is now available.
An update that fixes two vulnerabilities is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Zack Flack found several issues in monit, a utility for monitoring and managing daemons or similar programs.
Hanno Bck discovered that GNOME Evolution is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted HTML email. This issue was mitigated by moving the security
An update that fixes two vulnerabilities is now available.
An update that solves three vulnerabilities and has four fixes is now available.
In the recently uploaded systemd security update (215-17+deb8u12 via DLA-1762-1), a regression was discovered in the fix for CVE-2017-18078.
An update that solves two vulnerabilities and has three fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has 5 fixes is now available.
An update that solves 13 vulnerabilities and has one errata is now available.
An update that solves one vulnerability and has four fixes is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
It was discovered that there was a path traversal vulnerability in the “mercurial” distributed revision version control system. Symbolic links and subrepositories could be used defeat Mercurial’s
An update that solves two vulnerabilities and has four fixes is now available.
An update that fixes one vulnerability is now available.
Bind could be made to consume resources if it received specially crafted network traffic.
tcpflow could be made to crash or expose sensitive information over the network if it opened a specially crafted file or received specially crafted network traffic.
Several security issues were fixed in PHP.
Updated Red Hat AMQ Clients 2.3.1 packages are now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves four vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has 24 fixes is now available.
An update that fixes three vulnerabilities is now available.
An update that solves one vulnerability and has 23 fixes is now available.
The package dovecot before version 2.3.5.2-1 is vulnerable to denial of service.
The package flashplugin before version 32.0.0.171-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.
The package jenkins before version 2.172-1 is vulnerable to multiple issues including access restriction bypass and cross-site scripting.
The package ghostscript before version 9.27-1 is vulnerable to sandbox escape.
AdvanceCOMP could be made to run arbitrary code if it opened a specially crafted file.
A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
