The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2021-3810 https://linux.oracle.com/errata/ELSA-2021-3810.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: libxml2-2.9.1-6.0.3.el7_9.6.aarch64.rpm libxml2-devel-2.9.1-6.0.3.el7_9.6.aarch64.rpm libxml2-python-2.9.1-6.0.3.el7_9.6.aarch64.rpm libxml2-static-2.9.1-6.0.3.el7_9.6.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/libxml2-2.9.1-6.0.3.el7_9.6.src.rpm Related CVEs: CVE-2016-4658 Description of changes: [2.9.1-6.0.3] - Rebuild to include attribution logo [Orabug: 33024216] - Update doc/redhat.gif in tarball - Add libxml2-oracle-enterprise.patch and update logos in tarball [2.9.1-6.6] - Fix CVE-2016-4658 (#1966916) _______________________________________________ El-errata mailing list
An update that solves four vulnerabilities and has one errata is now available.. openSUSE Security Update: Security update for libqt4 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1452-1 Rating: moderate References: #1118595 #1118596 #1118599 #1121214 #1176315 Cross-References: CVE-2018-15518 CVE-2018-19869 CVE-2018-19873 CVE-2020-17507 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that solves four vulnerabilities and has one errata is now available. Description: This update for libqt4 fixes the following issues: * Fix buffer over-read in read_xbm_body (boo#1176315, CVE-2020-17507) * Fix "double free or corruption" in QXmlStreamReader (boo#1118595, CVE-2018-15518) * Fix QBmpHandler segfault on malformed BMP file boo#1118596, CVE-2018-19873) * Fix crash when parsing malformed url reference (boo#1118599, CVE-2018-19869) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1452=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): libqt4-4.8.7-lp151.9.3.1 libqt4-debuginfo-4.8.7-lp151.9.3.1 libqt4-debugsource-4.8.7-lp151.9.3.1 libqt4-devel-4.8.7-lp151.9.3.1 libqt4-devel-debuginfo-4.8.7-lp151.9.3.1 libqt4-linguist-4.8.7-lp151.9.3.1 libqt4-linguist-debuginfo-4.8.7-lp151.9.3.1 libqt4-private-headers-devel-4.8.7-lp151.9.3.1 libqt4-qt3support-4.8.7-lp151.9.3.1 libqt4-qt3support-debuginfo-4.8.7-lp151.9.3.1 libqt4-sql-4.8.7-lp151.9.3.1 libqt4-sql-debuginfo-4.8.7-lp151.9.3.1 libqt4-sql-sqlite-4.8.7-lp151.9.3.1 libqt4-sql-sqlite-debuginfo-4.8.7-lp151.9.3.1 libqt4-x11-4.8.7-lp151.9.3.1 libqt4-x11-debuginfo-4.8.7-lp151.9.3.1 - openSUSE Leap 15.1 (x86_64): libqt4-32bit-4.8.7-lp151.9.3.1 libqt4-32bit-debuginfo-4.8.7-lp151.9.3.1 libqt4-devel-32bit-4.8.7-lp151.9.3.1 libqt4-devel-32bit-debuginfo-4.8.7-lp151.9.3.1 libqt4-devel-doc-4.8.7-lp151.9.3.1 libqt4-devel-doc-debuginfo-4.8.7-lp151.9.3.1 libqt4-devel-doc-debugsource-4.8.7-lp151.9.3.1 libqt4-qt3support-32bit-4.8.7-lp151.9.3.1 libqt4-qt3support-32bit-debuginfo-4.8.7-lp151.9.3.1 libqt4-sql-32bit-4.8.7-lp151.9.3.1 libqt4-sql-32bit-debuginfo-4.8.7-lp151.9.3.1 libqt4-sql-plugins-debugsource-4.8.7-lp151.9.3.1 libqt4-sql-postgresql-4.8.7-lp151.9.3.1 libqt4-sql-postgresql-debuginfo-4.8.7-lp151.9.3.1 libqt4-sql-sqlite-32bit-4.8.7-lp151.9.3.1 libqt4-sql-sqlite-32bit-debuginfo-4.8.7-lp151.9.3.1 libqt4-sql-unixODBC-4.8.7-lp151.9.3.1 libqt4-sql-unixODBC-debuginfo-4.8.7-lp151.9.3.1 libqt4-x11-32bit-4.8.7-lp151.9.3.1 libqt4-x11-32bit-debuginfo-4.8.7-lp151.9.3.1 qt4-x11-tools-4.8.7-lp151.9.3.1 qt4-x11-tools-debuginfo-4.8.7-lp151.9.3.1 - openSUSE Leap 15.1 (noarch): libqt4-devel-doc-data-4.8.7-lp151.9.3.1 References: https://www.suse.com/security/cve/CVE-2018-15518.html https://www.suse.com/security/cve/CVE-2018-19869.html https://www.suse.com/security/cve/CVE-2018-19873.html https://www.suse.com/security/cve/CVE-2020-17507.html https://bugzilla.suse.com/1118595 https://bugzilla.suse.com/1118596 https://bugzilla.suse.com/1118599 https://bugzilla.suse.com/1121214 https://bugzilla.suse.com/1176315 -- . A new update for openSUSE rectifies three vulnerabilities in libqt5, improving both security and reliability for its users.. openSUSE Update, libqt4 Security, Application Patch. . LinuxSecurity.com Team
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-245 2005-03-23 ---------------------------------------------------------------------Product : Fedora Core 3 Name : kdelibs Version : 3.3.1 Release : 2.9.FC3 Summary : K Desktop Environment - Libraries Description : Libraries for the K Desktop Environment: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). ---------------------------------------------------------------------* Wed Mar 23 2005 Than Ngo 6:3.3.1-2.9.FC3 - Applied patch to fix konqueror international domain name spoofing, CAN-2005-0237, #147405 - get rid of broken AltiVec instructions on ppc * Wed Mar 2 2005 Than Ngo 6:3.3.1-2.8.FC3 - Applied patch to fix DCOP DoS, CAN-2005-0396, #150092 thanks KDE security team * Wed Feb 16 2005 Than Ngo 6:3.3.1-2.7.FC3 - Applied patch to fix dcopidlng insecure temporary file usage, CAN-2005-0365, #148823 ---------------------------------------------------------------------This update can be downloaded from: c28ef6077f606f12a42cc9353b44dbfb SRPMS/kdelibs-3.3.1-2.9.FC3.src.rpm 27aa0f9c550e57fecd378e5e7c5aff97 x86_64/kdelibs-3.3.1-2.9.FC3.x86_64.rpm f2801218b5ff4be23df191f5de57fa42 x86_64/kdelibs-devel-3.3.1-2.9.FC3.x86_64.rpm add5d7c4324e4790ee84441237225e88 x86_64/debug/kdelibs-debuginfo-3.3.1-2.9.FC3.x86_64.rpm 4ef5aaa433f4108d56110118c35e3f7f x86_64/kdelibs-3.3.1-2.9.FC3.i386.rpm 4ef5aaa433f4108d56110118c35e3f7f i386/kdelibs-3.3.1-2.9.FC3.i386.rpm 5aca755d133987148fb5885b08daad24 i386/kdelibs-devel-3.3.1-2.9.FC3.i386.rpm f79bcea56792848db679d141f9bd903b i386/debug/kdelibs-debuginfo-3.3.1-2.9.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agentwith the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.