Menu

Quote

An issue has been found in cups, the Common UNIX Printing System(tm). Due to a use-after-free bug an attacker could cause a denial-of-service. In case of having access to the log files, an attacker could also

Update to 2.40.3: * Make memory pressure monitor honor memory.memsw.usage_in_bytes if exists. * Include key modifiers in wheel events. * Apply cookie blocking policy to WebSocket handshakes. * Fix several crashes and rendering issues. * Security fixes: CVE-2023-32439

– Rebased to the latest upstream sources (see CHANGELOG.md) – Updated pcs-web-ui – Removed dependency fedora-logos – favicon is now correctly provided by pcs- web-ui – Resolves: rhbz#2109852 rhbz#2170648

Patch update to Kubernetes 1.25 for Fedora 37. Primarily a security fix for CVE-2023-2431: Bypass of seccomp profile enforcement.

– Rebased to the latest upstream sources (see CHANGELOG.md) – Updated pcs-web-ui – Removed dependency fedora-logos – favicon is now correctly provided by pcs- web-ui – Resolves: rhbz#2109852 rhbz#2170648

Several vulnerabilities were fixed in the Python3 interpreter. CVE-2015-20107

security update

Al Viro found a buffer overflow in Window Maker 0.80.0 and earlier which may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer.

Updated mICQ packages are available for Red Hat Linux versions 7.2 and 7.3 that fix a remote crash.

Updated zlib packages are now available which fix a buffer overflow vulnerability.

Versions of man before 1.51 have a bug where a malformed man file can cause a program named “unsafe” to be run.

open-vm-tools: authentication bypass vulnerability in the vgauth module (CVE-2023-20867) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * [ESXi] [SL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file ‘quiesce_manifest.xml’ * [ESX [More…]

An update that fixes one vulnerability is now available.

security update

A flaw was found in the ‘/v2/_catalog’ endpoint in ‘distribution/distribution’, which accepts a parameter to control the maximum number of records returned (query string: ‘n’). This vulnerability allows a malicious user to

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for go-toolset-1.19 and go-toolset-1.19-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

security update

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

Missing input validation in various functions may have resulted in denial of service in various functions provided by libx11, the X11 client-side library.

An update for python3 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Upstream security update with additional bugfixes. Resolves CVE-2023-2431.

Update to 114.0.5735.133. Fixes the following security issues: CVE-2023-3214, CVE-2023-3215, CVE-2023-3215, CVE-2023-3217,

security update

Two vunerabilities were discovered in c-ares, an asynchronous name resolver library: CVE-2023-31130

An update for the python38:3.8 and python38-devel:3.8 modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

Red Hat OpenShift Container Platform release 4.12.22 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.12.

Update to version 1.2.1. This version includes a fix for CVE-2023-32570 (race condition that can lead to an application crash).

This is the June 2023 monthly update for .NET 6. It includes fixes for several CVEs. Release Notes: – Runtime: https://github.com/dotnet/core/blob/main/release-notes/6.0/6.0.18/6.0.18.md – SDK: https://github.com/dotnet/core/blob/main/release- notes/6.0/6.0.18/6.0.118.md

This is the June 2023 monthly update for .NET 7. It includes fixes for several CVEs. Release Notes: – Runtime: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.7/7.0.7.md – SDK: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.7/7.0.107.md

Backport fix for CVE-2023-34969.

This is the June 2023 monthly update for .NET 7. It includes fixes for several CVEs. Release Notes: – Runtime: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.7/7.0.7.md – SDK: https://github.com/dotnet/core/blob/main/release-notes/7.0/7.0.7/7.0.107.md

security update

USN 6161-1 introduced a regression in .NET that could incorrectly cause X.509 certificate imports to fail when they should succeed.

Red Hat OpenShift Container Platform release 4.13.4 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13.

Red Hat OpenShift Container Platform release 4.13.4 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13.

The container bci/php was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

The container bci/php-apache was updated. The following patches have been included in this update:

security update

security update

security update

security update

security update

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

A heap-based buffer overflow vulnerability was found in the HTTP chunk parsing code of minidlna, a lightweight DLNA/UPnP-AV server, which may result in denial of service or the execution of arbitrary code.

An update for kpatch-patch is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in pngcheck.

Several security issues were fixed in Ruby.

Gregory James Duck reported that missing input validation in various functions provided by libx11, the X11 client-side library, may result in denial of service.

USN-6143-2 caused some minor regressions in Firefox.

An update for c-ares is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

Jettison could be made to crash if it opened a specially crafted file.

libxpm is a library handling X PixMap image format (so called xpm files). xpm files are an extension of the monochrome X BitMap format specified in the X protocol, and is commonly used in traditional X applications.

Niels Dossche and Tim D’¼sterhus discovered that PHP’s implementation of the SOAP HTTP Digest authentication did not check for failures, which may result in a stack information leak. Furthermore, the code used an insufficient number of random bytes.

Update to 114.0.5735.133. Fixes the following security issues: CVE-2023-3214, CVE-2023-3215, CVE-2023-3215, CVE-2023-3217,

security update

Several security issues were fixed in Jettison.

libcap could be made to crash or possibly execute arbitrary code if it received a specially crafted input.

An update for c-ares is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for texlive is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, Red Hat Enterprise Linux 8.2 Update

An update for c-ares is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

Release of Bug Advisories for the OpenShift Jenkins image and Jenkins agent base image. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

libX11 1.8.6 (CVE-2023-3138)

Bump to 5.8.6

Bump to 5.8.6

Security fix for CVE-2023-33461

Bump to 5.8.6

Bump to 5.8.6

security update

security update

The container bci/golang was updated. The following patches have been included in this update:

update to 114.0.5735.106. Fixes the following security issue: CVE-2023-3709

Update to v1.85.2 —- Update to v1.85.1 —- Update to v1.85.0 Fixes CVE-2023-32682, CVE-2023-32683 —- Update to v1.84.1

Several security vulnerabilities have been discovered in golang-go.crypto, the supplementary Go cryptography libraries. CVE-2019-11840