Menu

Quote

The container bci/openjdk-devel was updated. The following patches have been included in this update:

security update

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

security update

security update

An update that fixes four vulnerabilities is now available.

Update to 1.3.2 (CVE-2022-29187, CVE-2022-24765)

https://www.mediawiki.org/wiki/Release_notes/1.38 https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/message/UEMW64LVEH3BEXCJV43CVS6XPYURKWU3/

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

**Redis 6.2.10** Released Mon Jan 17 12:00:00 IST 2023 Upgrade urgency: MODERATE, a quick followup fix for a recently released 6.2.9. Bug Fixes * Revert the change to KEYS in the recent client output buffer limit fix (#11676) —- **Redis 6.2.9** Released Mon Jan 16 12:00:00 IDT 2023 Upgrade urgency: SECURITY, contains fixes to security […]

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

security update

security update

security update

libXpm 3.5.15, fixes CVE-2022-46285, CVE-2022-44617, CVE-2022-4883

**Redis 7.0.8** Released Mon Jan 16 12:00:00 IDT 2023 Security Fixes: * (**CVE-2022-35977**) Integer overflow in the Redis SETRANGE and SORT/SORT_RO commands can drive Redis to OOM panic * (**CVE-2023-22458**) Integer overflow in the Redis HRANDFIELD and ZRANDMEMBER commands can lead to denial-of- service Bug Fixes * Avoid possible hang when client issues long KEYS,

Several security issues were fixed in the Linux kernel.

An update is now available for Red Hat OpenShift GitOps 1.6.4 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat OpenShift GitOps 1.5.9 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat OpenShift GitOps 1.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

PAM would allow unintended access to the machine over network.

An update for go-toolset-1.18 and go-toolset-1.18-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Update to 42.6

security update

Red Hat OpenShift Container Platform release 4.10.50 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for pcs is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for sssd is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Setuptools could be made to crash if it received specially crafted input.

Multiple vulnerabilities were found in trafficserver, a caching proxy server. CVE-2021-37150

An update for sudo is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for sudo is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for sudo is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for sudo is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

– Update to 109.0

This updates .NET 6 to the January 2023 security release. The updated versions are SDK 6.0.113 and Runtime 6.0.13 This include a fix for CVE-2023-21538

Patches for CVE-2023-23456 and CVE-2023-23457

Rebase to sudo-1.9.12p2 – security fix for CVE-2023-22809

libXpm 3.5.15, fixes CVE-2022-46285, CVE-2022-44617, CVE-2022-4883

This updates .NET 6 to the January 2023 security release. The updated versions are SDK 6.0.113 and Runtime 6.0.13 This include a fix for CVE-2023-21538

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

security update

USN-5810-1 introduced a regression in Git.

Igor Ponomarev discovered that LAVA, a continuous integration system for deploying operating systems onto physical and virtual hardware for running tests, was susceptible to denial of service via recursive XML entity expansion.

It was discovered that the CompareTool of iText, a Java PDF library which uses the external ghostscript software to compare PDFs at a pixel level, allowed command injection when parsing a specially crafted filename.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

security update

security update

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42852

– Update to 109.0

New sudo packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue.

It was discovered that the CompareTool of iText, a Java PDF library which uses the external ghostscript software to compare PDFs at a pixel level, allowed command injection when parsing a specially crafted filename.

Sudo could be made to possibly edit arbitrary files if it received a specially crafted input.

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

New libXpm packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.

New httpd packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.

New git packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.

Security fix for CVE-2022-46391

Security fix for CVE-2022-46391

security update

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

An update that contains security fixes can now be installed.

The container sles-15-sp4-chost-byos-v20230111-arm64 was updated. The following patches have been included in this update:

A logic error was discovered in the implementation of the “SafeSocks” option of Tor, a connection-based low-latency anonymous communication system, which did result in allowing unsafe SOCKS4 traffic to pass.

An update for libxml2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for dpdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dpdk is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for dpdk is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dpdk is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for dpdk is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

menglong2234 discovered NULL pointer exceptions in net-snmp, a suite of Simple Network Management Protocol applications, which could could result in debian of service.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.

security update

security update

security update

v1.5.1 – fix logging to stdout when –stdout is used *thanks to Eta – update –treshold option accept decimal numbers as parameter – fix crashes when processing certain broken JPEG images – fix memory leaks – fix (logging) output in parallel processing mode