Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Python.. ========================================================================== Ubuntu Security Notice USN-7710-2 August 29, 2025 python2.7 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Python. Software Description: - python2.7: An interactive high-level object-oriented language Details: USN-7710-1 fixed vulnerabilities in Python. This update provides the corresponding fix for CVE-2025-8194 for Python 2.7. Original advisory details: It was discovered that Python inefficiently parsed maliciously crafted HTML input. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-6069) It was discovered that Python incorrectly parsed maliciously crafted Tar archives. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-8194) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libpython2.7 2.7.18-13ubuntu1.5+esm7 Available with Ubuntu Pro python2.7 2.7.18-13ubuntu1.5+esm7 Available with Ubuntu Pro Ubuntu 20.04 LTS libpython2.7 2.7.18-1~20.04.7+esm8 Available with Ubuntu Pro python2.7 2.7.18-1~20.04.7+esm8 Available with Ubuntu Pro Ubuntu 18.04 LTS libpython2.7 2.7.17-1~18.04ubuntu1.13+esm12 Available with Ubuntu Pro python2.7 2.7.17-1~18.04ubuntu1.13+esm12 Available with Ubuntu Pro Ubuntu 16.04 LTS libpython2.7 2.7.12-1ubuntu0~16.04.18+esm17 Available with Ubuntu Pro python2.7 2.7.12-1ubuntu0~16.04.18+esm17 Available with Ubuntu Pro Ubuntu 14.04 LTS libpython2.7 2.7.6-8ubuntu0.6+esm26 Available with Ubuntu Pro python2.7 2.7.6-8ubuntu0.6+esm26 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7710-2 https://ubuntu.com/security/notices/USN-7710-1 CVE-2025-8194 . Recent vulnerabilities in Python 2.7 for Ubuntu have been identified; critical patches advised.. Ubuntu security, Python advisory, Denial of service, Python update, Ubuntu vulnerability. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # bsdtar-3.7.7-2.1 on GA media Announcement ID: openSUSE-SU-2025:14844-1 Rating: moderate Cross-References: * CVE-2024-57970 CVSS scores: * CVE-2024-57970 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57970 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the bsdtar-3.7.7-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * bsdtar 3.7.7-2.1 * libarchive-devel 3.7.7-2.1 * libarchive13 3.7.7-2.1 * libarchive13-32bit 3.7.7-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-57970.html . A moderate security update has been issued for bsdtar on openSUSE. It is crucial to update to avoid potential threats due to identified vulnerabilities. bsdtar security, openSUSE update, advisory information, moderate rating, cross-reference issue. . LinuxSecurity.com Team
The radare2 is a reverse-engineering framework that is multi-architecture, multi-platform, and highly scriptable. Radare2 provides a hexadecimal editor, wrapped I/O, file system support, debugger support, diffing between two functions or binaries, and code analysis at opcode, basic block, and function levels.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ac8d48e58a 2024-12-12 01:33:19.386673+00:00 -------------------------------------------------------------------------------- Name : radare2 Product : Fedora 41 Version : 5.9.8 Release : 4.fc41 URL : https://radare.org/ Summary : The reverse engineering framework Description : The radare2 is a reverse-engineering framework that is multi-architecture, multi-platform, and highly scriptable. Radare2 provides a hexadecimal editor, wrapped I/O, file system support, debugger support, diffing between two functions or binaries, and code analysis at opcode, basic block, and function levels. -------------------------------------------------------------------------------- Update Information: Bump radare2 to 5.9.8, iaito to 5.9.9, fixes CVE-2024-11858 -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 30 2024 Michal Ambroz - 5.9.8-4 - fix epel build * Mon Nov 25 2024 Michal Ambroz - 5.9.8-2 - documentation of embedded quickjs-ng library * Fri Nov 22 2024 Michal Ambroz - 5.9.8-1 - bump to 5.9.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2313891 - iaito: fails to install from epel9 https://bugzilla.redhat.com/show_bug.cgi?id=2313891 [ 2 ] Bug #2327286 - iaito-5.9.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2327286 [ 3 ] Bug #2327308 - radare2-5.9.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2327308 [ 4 ] Bug #2329104 - CVE-2024-11858 radare2:Command Injection via Pebble Application Files in Radare2 [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2329104 [ 5 ] Bug #2329105 - CVE-2024-11858 radare2: Command Injection via Pebble Application Files in Radare2 [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2329105 [ 6 ] Bug #2329107 - CVE-2024-11858 radare2: Command Injection via Pebble Application Files in Radare2 [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2329107 [ 7 ] Bug #2329108 - CVE-2024-11858 radare2: Command Injection via Pebble Application Files in Radare2 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2329108 [ 8 ] Bug #2329622 - F41FailsToInstall: iaito https://bugzilla.redhat.com/show_bug.cgi?id=2329622 [ 9 ] Bug #2329623 - F40FailsToInstall: iaito https://bugzilla.redhat.com/show_bug.cgi?id=2329623 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ac8d48e58a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
. -- _______________________________________________ package-announce mailing list --
Update to 115.12.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-28/ https://www.thunderbird.net/en-US/thunderbird/115.12.0esr/releasenotes/. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-748bedc96c 2024-06-16 14:47:07.939415 -------------------------------------------------------------------------------- Name : thunderbird Product : Fedora 40 Version : 115.12.0 Release : 2.fc40 URL : https://wiki.mozilla.org/Thunderbird:Home Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. -------------------------------------------------------------------------------- Update Information: Update to 115.12.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-28/ https://www.thunderbird.net/en-US/thunderbird/115.12.0esr/releasenotes/ -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 12 2024 Eike Rathke - 115.12.0-2 - Update to 115.12.0 * Mon Jun 3 2024 Eike Rathke - 115.11.2-1 - Update to 115.11.2 * Wed May 29 2024 Eike Rathke - 115.11.1-1 - Update to 115.11.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2283720 - thunderbird-wayland wasn't built in thunderbird-115.11.0-1.fc40, and thunderbird-wayland remained installed after upgrading to it https://bugzilla.redhat.com/show_bug.cgi?id=2283720 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-748bedc96c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update for java-11-openjdk is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: java-11-openjdk security update Advisory ID: RHSA-2023:0201-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0201 Issue date: 2023-01-18 CVE Names: CVE-2023-21835 CVE-2023-21843 ==================================================================== 1. Summary: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 3. Description: The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. Security Fix(es): * OpenJDK: handshake DoS attack against DTLS connections (JSSE, 8287411) (CVE-2023-21835) * OpenJDK: soundbank URL remote loading (Sound, 8293742) (CVE-2023-21843) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 All running instances of OpenJDK Java must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2160421 - CVE-2023-21835 OpenJDK: handshake DoS attack against DTLS connections (JSSE, 8287411) 2160475 - CVE-2023-21843 OpenJDK: soundbank URL remote loading (Sound, 8293742) 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.9.0): Source: java-11-openjdk-11.0.18.0.10-1.el9_0.src.rpm aarch64: java-11-openjdk-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-debugsource-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-demo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-devel-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-devel-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-devel-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-devel-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-headless-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-headless-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-headless-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-headless-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-javadoc-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-javadoc-zip-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-jmods-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-src-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-static-libs-11.0.18.0.10-1.el9_0.aarch64.rpm ppc64le: java-11-openjdk-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-debugsource-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-demo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-devel-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-devel-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-devel-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-devel-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-headless-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-headless-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-headless-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-headless-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-javadoc-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-javadoc-zip-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-jmods-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-src-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-static-libs-11.0.18.0.10-1.el9_0.ppc64le.rpm s390x: java-11-openjdk-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-debugsource-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-demo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-devel-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-devel-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-devel-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-headless-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-headless-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-headless-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-javadoc-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-javadoc-zip-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-jmods-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-src-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-static-libs-11.0.18.0.10-1.el9_0.s390x.rpm x86_64: java-11-openjdk-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-debugsource-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-demo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-devel-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-devel-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-devel-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-devel-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-headless-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-headless-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-headless-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-headless-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-javadoc-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-jmods-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-src-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-static-libs-11.0.18.0.10-1.el9_0.x86_64.rpm Red Hat CodeReady Linux Builder EUS(v.9.0): aarch64: java-11-openjdk-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-debugsource-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-demo-fastdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-demo-slowdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-devel-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-devel-fastdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-devel-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-devel-slowdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-devel-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-fastdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-headless-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-headless-fastdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-headless-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-headless-slowdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-headless-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-jmods-fastdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-jmods-slowdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-slowdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-src-fastdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-src-slowdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-static-libs-fastdebug-11.0.18.0.10-1.el9_0.aarch64.rpm java-11-openjdk-static-libs-slowdebug-11.0.18.0.10-1.el9_0.aarch64.rpm ppc64le: java-11-openjdk-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-debugsource-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-demo-fastdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-demo-slowdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-devel-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-devel-fastdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-devel-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-devel-slowdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-devel-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-fastdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-headless-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-headless-fastdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-headless-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-headless-slowdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-headless-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-jmods-fastdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-jmods-slowdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-slowdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-src-fastdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-src-slowdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-static-libs-fastdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm java-11-openjdk-static-libs-slowdebug-11.0.18.0.10-1.el9_0.ppc64le.rpm s390x: java-11-openjdk-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-debugsource-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-demo-slowdebug-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-devel-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-devel-slowdebug-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-devel-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-headless-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-headless-slowdebug-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-headless-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-jmods-slowdebug-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-slowdebug-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-src-slowdebug-11.0.18.0.10-1.el9_0.s390x.rpm java-11-openjdk-static-libs-slowdebug-11.0.18.0.10-1.el9_0.s390x.rpm x86_64: java-11-openjdk-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-debugsource-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-demo-fastdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-demo-slowdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-devel-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-devel-fastdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-devel-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-devel-slowdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-devel-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-fastdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-headless-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-headless-fastdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-headless-fastdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-headless-slowdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-headless-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-jmods-fastdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-jmods-slowdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-slowdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-slowdebug-debuginfo-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-src-fastdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-src-slowdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-static-libs-fastdebug-11.0.18.0.10-1.el9_0.x86_64.rpm java-11-openjdk-static-libs-slowdebug-11.0.18.0.10-1.el9_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-21835 https://access.redhat.com/security/cve/CVE-2023-21843 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hatsecurity contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -- RHSA-announce mailing list
- - [SA-CONTRIB-2022-034]() - - - . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-d209710a36 2022-11-24 01:30:52.558626 --------------------------------------------------------------------------------Name : drupal7-link Product : Fedora 36 Version : 1.11 Release : 1.fc36 URL : https:// Summary : Defines simple link field types Description : The link module can be count to the top 50 modules in Drupal installations and provides a standard custom content field for links. With this module links can be added easily to any content types and profiles and include advanced validating and different ways of storing internal or external links and URLs. It also supports additional link text title, site wide tokens for titles and title attributes, target attributes, CSS class attribution, static repeating values, input conversion, and many more. This package provides the following Drupal module: * link --------------------------------------------------------------------------------Update Information: - https:// - [SA-CONTRIB-2022-034](https://) -https:// -https:// -https:// --------------------------------------------------------------------------------ChangeLog: * Tue Nov 15 2022 Shawn Iwinski - 1.11-1 - Update to 1.11 (RHBZ #1950456) * Thu Jul 21 2022 Fedora Release Engineering - 1.7-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1950456 - drupal7-link-1.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=1950456 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-d209710a36' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The container bci/golang was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:1076-1 Container Tags : bci/golang:1.17 , bci/golang:1.17-17.19 Container Release : 17.19 Severity : important Type : security References : 1197443 1197743 1198446 1199240 CVE-2022-1304 CVE-2022-29155 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1670-1 Released: Mon May 16 10:06:30 2022 Summary: Security update for openldap2 Type: security Severity: important References: 1199240,CVE-2022-29155 This update for openldap2 fixes the following issues: - CVE-2022-29155: Fixed SQL injection in back-sql (bsc#1199240). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1688-1 Released: Mon May 16 14:02:49 2022 Summary: Security update for e2fsprogs Type: security Severity: important References: 1198446,CVE-2022-1304 This update for e2fsprogs fixes the following issues: - CVE-2022-1304: Fixed out-of-bounds read/write leading to segmentation fault and possibly arbitrary code execution. (bsc#1198446) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1691-1 Released: Mon May 16 15:13:39 2022 Summary: Recommended update for augeas Type: recommended Severity: moderate References: 1197443 This update for augeas fixes the following issue: - Sysctl keys can contain some more non-alphanumeric characters. (bsc#1197443) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1709-1 Released: Tue May 17 17:35:47 2022 Summary: Recommended update forlibcbor Type: recommended Severity: important References: 1197743 This update for libcbor fixes the following issues: - Fix build errors occuring on SUSE Linux Enterprise 15 Service Pack 4 The following package changes have been done: - libaugeas0-1.10.1-150000.3.12.1 updated - libcbor0-0.5.0-150100.4.6.1 updated - libcom_err2-1.43.8-150000.4.33.1 updated - libldap-2_4-2-2.4.46-150200.14.8.1 updated - libldap-data-2.4.46-150200.14.8.1 updated - container:sles15-image-15.0.0-17.14.16 updated . SUSE has released a crucial patch for the bci/golang container, tackling significant security flaws and vulnerabilities.. container update,bci,golang,security advisory,SUSE update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.