Menu

Quote

An update that solves one vulnerability and has three fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has four fixes is now available.

An update that fixes two vulnerabilities is now available.

Updated pdns packages fix security vulnerability: An issue has been found in PowerDNS Authoritative Server when the HTTP remote backend is used in RESTful mode (without post=1 set), allowing a remote user to cause the HTTP backend to connect to an attacker-specified

The updated live, mplayer, vlc packages fix security vulnerabilities: liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation

This kernel update is based on the upstream 4.14.106 and fixes atleast the following security issue: In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers

Updated openjpeg2 packages fix security vulnerability: Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service

The updated file packages fix security vulnerabilities: do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360. (CVE-2019-8905)

The updated poppler packages fix security vulnerabilities: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in

The package dovecot before version 2.3.5.1-1 is vulnerable to privilege escalation.

The package imagemagick before version 7.0.8.35-1 is vulnerable to arbitrary code execution.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

security update

An update that fixes two vulnerabilities is now available.

An update that solves 8 vulnerabilities and has one errata is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

xmltooling could be made to crash if it opened a specially crafted file.

Red Hat Ansible Tower 3.3.5 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes:

Red Hat Ansible Tower 3.4.3 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes:

Several vulnerabilities have recently been discovered in libssh2, a client-side C library implementing the SSH2 protocol

An update that fixes one vulnerability is now available.

openwsman: Disclosure of arbitrary files outside of the registered URIs (CVE-2019-3816) SL7 x86_64 libwsman1-2.6.3-6.git4391e5c.el7_6.i686.rpm libwsman1-2.6.3-6.git4391e5c.el7_6.x86_64.rpm openwsman-client-2.6.3-6.git4391e5c.el7_6.i686.rpm openwsman-client-2.6.3-6.git4391e5c.el7_6.x86_64.rpm openwsman-debuginfo-2.6.3-6.git4391e5c.el7_6.i686.rpm openwsman-debuginfo-2. [More…]

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

An update that fixes four vulnerabilities is now available.

Multiple scp client vulnerabilities have been discovered in OpenSSH, the premier connectivity tool for secure remote shell login and secure file transfer.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Two issues have been fixed in bash, the GNU Bourne-Again Shell: CVE-2016-9401

CVE-2018-19364: 9pfs: use-after-free (bz #1651359) CVE-2018-19489: 9pfs: use- after-free renaming files (bz #1653157) CVE-2018-16867: usb-mtp: path traversal issue (bz #1656746) CVE-2018-16872: usb-mtp: path traversal issue (bz #1659150) CVE-2018-20191: pvrdma: uar_read leads to NULL deref (bz #1660315) CVE-2019-6778: slirp: heap buffer overflow (bz #1669072) CVE-2019-3812: Out-of-

Security fix for [CVE-2018-1000877 CVE-2018-1000878 CVE-2018-1000879 CVE-2018-1000880] —- Applied various flaws from upsteam

Update to 3.0. License has changed to ASL 2.0 + exception. See https://github.com/michaelrsweet/mxml/releases/tag/v3.0 for more info.

Trail of Bits used the automated vulnerability discovery tools developed for the DARPA Cyber Grand Challenge to audit zlib. As rsync, a fast, versatile, remote (and local) file-copying tool, uses an embedded copy of

security update

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

It was discovered that Wireshark, a network traffic analyzer, contained several vulnerabilities in the dissectors for 6LoWPAN, P_MUL, RTSE, ISAKMP, TCAP, ASN.1 BER and RPCAP, which could result in denial of service.

An arbitrary file read vulnerability was discovered in passenger, a web application server. A local user allowed to deploy an application to passenger, can take advantage of this flaw by creating a symlink from the REVISION file to an arbitrary file on the system and have its

The package firefox before version 66.0.1-1 is vulnerable to arbitrary code execution.

security update

Several issues have been discovered in Apache module auth_mellon, which provides SAML 2.0 authentication. CVE-2019-3877

Backport a security fix from PuTTY 0.71 affecting SFTP connections: Fix an integer overflow in the RSA key exchange preceeding host key verification

**Version 1.38.2** (2019-03-12) * added TemplateWrapper::getTemplateName() —- **Version 1.38.1** (2019-03-12) * fixed class aliases —- **Version 1.38.0** (2019-03-12) * fixed sandbox security issue (under some circumstances, calling the __toString() method on an object was possible even if not allowed by the security policy) * fixed batch filter clobbers array

**Version 2.7.2** (2019-03-12) * added TemplateWrapper::getTemplateName() —- **Version 2.7.1** (2019-03-12) * fixed class aliases —- **Version 2.7.0** (2019-03-12) * fixed sandbox security issue (under some circumstances, calling the __toString() method on an object was possible even if not allowed by the security policy) * fixed batch filter clobbers array keys when fill

This update addresses various overflow conditions that could result in possible memory read/write out of bounds errors or zero byte allocations when connected to a malicious server.

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

A heap-based buffer overflow was discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of this flaw for local root privilege escalation.

Libzip could be made to crash if it received specially crafted input.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0622

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0623

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes three vulnerabilities is now available.

Update tcpflow to 1.5.2 tag at github, fixing a security issue.

security update

security update

security update

Proxy Auto-Configuration file can define localhost access to be proxied (CVE-2018-18506). Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6 (CVE-2019-9788).

In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c. (CVE-2019-7397) References: – https://bugs.mageia.org/show_bug.cgi?id=24396

The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837). The fetch module was susceptible to path traversal (CVE-2019-3828).

Several security issues were fixed in Ghostscript.

An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

NTFS-3G could be made to crash or potentially run programs as anadministrator if executed with specially crafted arguments.

An update that fixes three vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes two vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that solves 9 vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

The package wordpress before version 5.1-1 is vulnerable to directory traversal.

The package libelf before version 0.176-1 is vulnerable to denial of service.

Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to gain unauthorized access.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0597

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

security update

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

cloud-init: extra ssh keys added to authorized_keys on the Azure platform (CVE-2019-0816) SL7 x86_64 cloud-init-18.2-1.el7_6.2.x86_64.rpm – Scientific Linux Development Team

An update that fixes 9 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0482

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0485

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0483

Upstream details at : https://access.redhat.com/errata/RHSA-2019:0512

It has been discovered that OTRS (Open source Ticket Request System) is susceptible to code injection vulnerability. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully

An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

The CLI tools in python-rdflib-tools can load python modules found in the current directory. This happens because “python -m” appends the current directory in the python path.