An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for ignition ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2350-1 Rating: moderate References: #1199524 Cross-References: CVE-2022-1706 CVSS scores: CVE-2022-1706 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2022-1706 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise Micro 5.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for ignition fixes the following issues: - CVE-2022-1706: Fixed accessible configs from unprivileged containers in VMs running on VMware products (bsc#1199524). - Update to version 2.14.0 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Micro 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2022-2350=1 Package List: - SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64): ignition-2.14.0-150300.4.7.1 ignition-debuginfo-2.14.0-150300.4.7.1 ignition-dracut-grub2-2.14.0-150300.4.7.1 References: https://www.suse.com/security/cve/CVE-2022-1706.html https://bugzilla.suse.com/1199524 . SUSE Security Update on kube-apiserver tackles CVE-2022-1707 with moderate risk level. Deploy using advised procedures.. SUSE Ignition Update, CVE-2022-1706, SUSE Security Advisory, Linux Micro, Moderate Threat. . LinuxSecurity.com Team
An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2021:2742-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2742 Issue date: 2021-07-15 CVE Names: CVE-2021-29970 CVE-2021-29976 CVE-2021-30547 ==================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v. 8.2) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 78.12.0 ESR. Security Fix(es): * Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970) * Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976) * chromium-browser: Out of bounds write in ANGLE (CVE-2021-30547) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1970109 - CVE-2021-30547 chromium-browser: Out of bounds write in ANGLE 1982013 - CVE-2021-29970 Mozilla: Use-after-free in accessibility features of a document 1982014 - CVE-2021-29976 Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 6. Package List: Red Hat Enterprise Linux AppStream EUS (v. 8.2): Source: firefox-78.12.0-1.el8_2.src.rpm aarch64: firefox-78.12.0-1.el8_2.aarch64.rpm firefox-debuginfo-78.12.0-1.el8_2.aarch64.rpm firefox-debugsource-78.12.0-1.el8_2.aarch64.rpm ppc64le: firefox-78.12.0-1.el8_2.ppc64le.rpm firefox-debuginfo-78.12.0-1.el8_2.ppc64le.rpm firefox-debugsource-78.12.0-1.el8_2.ppc64le.rpm s390x: firefox-78.12.0-1.el8_2.s390x.rpm firefox-debuginfo-78.12.0-1.el8_2.s390x.rpm firefox-debugsource-78.12.0-1.el8_2.s390x.rpm x86_64: firefox-78.12.0-1.el8_2.x86_64.rpm firefox-debuginfo-78.12.0-1.el8_2.x86_64.rpm firefox-debugsource-78.12.0-1.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-29970 https://access.redhat.com/security/cve/CVE-2021-29976 https://access.redhat.com/security/cve/CVE-2021-30547 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYPAd5tzjgjWX9erEAQhj6Q//ee298TejOw/DoFGswe+VV6O31qUeZhuE 0FXjeWj2WrmuMOkqVtnAv9ONt31l5BrslSED0OPcQV2Raf3rx5DgqvalF0L6fgdy vHaZFOwOaE0874KROT0eUeMQ0ivCXBKMQpmU3+Pqc3Tnm62Dq+rtr0akkD1pLbLq OSkqwBaPo+Gs/qTpUoCDapImnKV3BsvuEbNPlEAGjaA7BBnNh28aeIoTrzCYDoNm ZVAd7F5Nz1b810gYib/qgfbvpCdAfJoqXLo7CzQ2JQe6yYSzI/sSqoyRv5bJnpKy dHwnatJjmX5ETJ8pKLoZH8B7ibDaeWDJzYG8oZUy44brJA2b1ifp8PLauWH+9KiK NW3mMq8f0/aUaKaXvVbLS9KCJj6eD+3LKr/76pCvY5NDQerzdF7hQqNz08+gl1i9 9nYI/1x3Po7PP+L6HT+K3Hv16fT0nLXyruOdoNbOR+oy1ZLMiSX7gZkONoO8KHVV +Bc4eIbcCA8dXlcc7f7yZxVBHd9dTPy97tHQ/dLjIbpfMTWHWO956Iv2aqfv5nv0 axSIh4ixLSy8YFpufwrQI5c6MT34d553KW/ZHKl3aufrJ26yDI7HSjN0gfihsLpj 4U0KQSDWHc3yyVytXBF0lsdMV+pRLP1e/4UwjO7tKKvZnbitn1kt7A19iLLRDXQc KNX0GtOOlEg=tlXC -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Upstream details at : https://access.redhat.com/errata/RHSA-2019:3128. CentOS Errata and Security Advisory 2019:3128 Important Upstream details at : https://access.redhat.com/errata/RHSA-2019:3128 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 6be45c4b3d7d4b924da7eca629d855ea2991bb618dd4803103fb9735ff30f939 java-1.8.0-openjdk-1.8.0.232.b09-0.el7_7.i686.rpm 76419a124dd11edec7f2f0db600e5d81f615c778a5c8eb700b386d4847ece7da java-1.8.0-openjdk-1.8.0.232.b09-0.el7_7.x86_64.rpm ff0fb4340f453869481572bd845ee89de664eef53a7029ecd8e0f10d14134090 java-1.8.0-openjdk-accessibility-1.8.0.232.b09-0.el7_7.i686.rpm 705cf5f782644757b80ac7347d8c9e43ff2c46d910a16c8fac7d57d6974bdce6 java-1.8.0-openjdk-accessibility-1.8.0.232.b09-0.el7_7.x86_64.rpm aeeb200370864da6cdb05287e435543eb67787fa5127a242e6493685027b68fe java-1.8.0-openjdk-accessibility-debug-1.8.0.232.b09-0.el7_7.i686.rpm 26fba6662859c85cafd271740c9a605021cb58f2c94efe058cedaffe45d45449 java-1.8.0-openjdk-accessibility-debug-1.8.0.232.b09-0.el7_7.x86_64.rpm 4494a1a317d85f97a56c8555feb9540a437d8cf97718d9961ad5c60d5990836d java-1.8.0-openjdk-debug-1.8.0.232.b09-0.el7_7.i686.rpm 4cd6a101a5ab3b51a5c33dcbae3dd81ec70f7d0b8c914b2d8b7675fb92f67039 java-1.8.0-openjdk-debug-1.8.0.232.b09-0.el7_7.x86_64.rpm a40a4fbd6bc8692bc9c8ef34658cedfe6839f58d0e772650e6ca16b1a826867e java-1.8.0-openjdk-demo-1.8.0.232.b09-0.el7_7.i686.rpm c7c1066e768ae606653ca24d2ac63afa4232d47c6c9a01b015d8fd79180ec37a java-1.8.0-openjdk-demo-1.8.0.232.b09-0.el7_7.x86_64.rpm e2d4742f1a2a6172ddf0d3714652623c70fddb032a4eac36d0d7141b4b235763 java-1.8.0-openjdk-demo-debug-1.8.0.232.b09-0.el7_7.i686.rpm 79335285aab1558d06f0a55e7185544f5dd58596153b241703dbb33883f3db4b java-1.8.0-openjdk-demo-debug-1.8.0.232.b09-0.el7_7.x86_64.rpm 4d2564446cd1827e349fded9b15eb14ffa89848d393dd4b91830c8ce8b4786ac java-1.8.0-openjdk-devel-1.8.0.232.b09-0.el7_7.i686.rpm b06d68b79e2a5a7694a4d3f4248f4ac2af577eb02b1a238fccfba556eec3a241 java-1.8.0-openjdk-devel-1.8.0.232.b09-0.el7_7.x86_64.rpm 5f0612fd6359d4b13ae451941bb23e09664a844783f1bd0c2b572666a654db84 java-1.8.0-openjdk-devel-debug-1.8.0.232.b09-0.el7_7.i686.rpm 40e387ee0605179c0dba9758ddcad4bbe62344615a80d272ba82d05ad6e328a2 java-1.8.0-openjdk-devel-debug-1.8.0.232.b09-0.el7_7.x86_64.rpm 06572f1b6bab69ffd0f3b44749ef8c0670c1ce7f01134c110aa613f45df0e54f java-1.8.0-openjdk-headless-1.8.0.232.b09-0.el7_7.i686.rpm cd3c5458ec1d58aa1c6414da80668412d89290a640e7145bc9ef6813c44e8152 java-1.8.0-openjdk-headless-1.8.0.232.b09-0.el7_7.x86_64.rpm 29728203f56aaed340823d5727b61229b1f170cb17c8de87060ec6069c94e0ad java-1.8.0-openjdk-headless-debug-1.8.0.232.b09-0.el7_7.i686.rpm 63ebf18fa0313d35c241a996ad6b2cf47eea2ab1d3e53921eef491db9336d1e4 java-1.8.0-openjdk-headless-debug-1.8.0.232.b09-0.el7_7.x86_64.rpm 823fb448b0c4c00a23ade792d5ffd51ca5b3c3d4fd24d41ede758aa3c221a790 java-1.8.0-openjdk-javadoc-1.8.0.232.b09-0.el7_7.noarch.rpm af0423e8184aa09e34ec3fdd79d0badbbf8255de985b5ed0e46734e30c4f35b9 java-1.8.0-openjdk-javadoc-debug-1.8.0.232.b09-0.el7_7.noarch.rpm 7a74b88f52de35f722ae6a1017af55c1b63f8fa225b3ee33e6cf1349a6ee1196 java-1.8.0-openjdk-javadoc-zip-1.8.0.232.b09-0.el7_7.noarch.rpm 51e949b22605f0fb8ef01aaff6f616d4204a077a1b623d8b90783704e470883a java-1.8.0-openjdk-javadoc-zip-debug-1.8.0.232.b09-0.el7_7.noarch.rpm 113f6b7be1a0b5f6f270546e3e0207de722f6838b511fab80bc2e464900c231d java-1.8.0-openjdk-src-1.8.0.232.b09-0.el7_7.i686.rpm 74aec31ec933e4640371f0d208efe50f17de68ad6095511499f0aeb38c125944 java-1.8.0-openjdk-src-1.8.0.232.b09-0.el7_7.x86_64.rpm 6b2a930c3a5bea0623b4448c2582b59ac6fbf0f8322bf4125319c67728e724f6 java-1.8.0-openjdk-src-debug-1.8.0.232.b09-0.el7_7.i686.rpm d609ca8fa065f985aa9b6941d33cd221313d6edd30e3ee9db8041492c6da24e3 java-1.8.0-openjdk-src-debug-1.8.0.232.b09-0.el7_7.x86_64.rpm Source: 9c730db7ca73e3986ec6c209398cd6f36b750034569dc2a889131730ce15acbc java-1.8.0-openjdk-1.8.0.232.b09-0.el7_7.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc:hughesjr, #
USN-3747-1 introduced a regression in OpenJDK 10.. =========================================================================Ubuntu Security Notice USN-3747-2 September 12, 2018 openjdk-lts regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: USN-3747-1 introduced a regression in OpenJDK 10. Software Description: - openjdk-lts: Open Source Java implementation Details: USN-3747-1 fixed vulnerabilities in OpenJDK 10 for Ubuntu 18.04 LTS. Unfortunately, that update introduced a regression around accessability support that prevented some Java applications from starting. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that OpenJDK did not properly validate types in some situations. An attacker could use this to construct a Java class that could possibly bypass sandbox restrictions. (CVE-2018-2825, CVE-2018-2826) It was discovered that the PatternSyntaxException class in OpenJDK did not properly validate arguments passed to it. An attacker could use this to potentially construct a class that caused a denial of service (excessive memory consumption). (CVE-2018-2952) Daniel Bleichenbacher discovered a vulnerability in the Galois/Counter Mode (GCM) mode of operation for symmetric block ciphers in OpenJDK. An attacker could use this to expose sensitive information. (CVE-2018-2972) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: openjdk-11-jdk 10.0.2+13-1ubuntu0.18.04.2 openjdk-11-jdk-headless 10.0.2+13-1ubuntu0.18.04.2 openjdk-11-jre 10.0.2+13-1ubuntu0.18.04.2 openjdk-11-jre-headless 10.0.2+13-1ubuntu0.18.04.2 openjdk-11-jre-zero 10.0.2+13-1ubuntu0.18.04.2 This update uses a new upstream release, which includes additional bug fixes. After a standard systemupdate you need to restart any Java applications or applets to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3747-2 https://ubuntu.com/security/notices/USN-3747-1 https://bugs.launchpad.net/ubuntu/+source/openjdk-lts/+bug/1788250 Package Information: https://launchpad.net/ubuntu/+source/openjdk-lts/10.0.2+13-1ubuntu0.18.04.2 . The OpenJDK 10 regression affects Ubuntu 18.04 LTS, necessitating updates to address accessibility issues stemming from previous modifications.. OpenJDK Update, Java Security Fix, Ubuntu Security Advisory. . Severity: Critical. LinuxSecurity.com Team
The update for didiwiki issued as DSA-3485-1 introduced a regression that caused a large number of valid pages to not be accessible anymore. This occurred mostly for pages whose names started with non-ascii characters. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3485-2
Get the latest Linux and open source security news straight to your inbox.