Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Out-of-bounds read due to insufficient length checks in winbindd_pam_auth_crap.c (CVE-2022-2127) Improper SMB2 packet signing mechanism leading to man in the middle risk (CVE-2023-3347) Infinite loop vulnerability was found in Samba's mdssvc RPC service for . MGASA-2023-0247 - Updated samba packages fix security vulnerability Publication date: 23 Aug 2023 URL: https://advisories.mageia.org/MGASA-2023-0247.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-2127, CVE-2023-3347, CVE-2023-34966, CVE-2023-34967, CVE-2023-34968 Out-of-bounds read due to insufficient length checks in winbindd_pam_auth_crap.c (CVE-2022-2127) Improper SMB2 packet signing mechanism leading to man in the middle risk (CVE-2023-3347) Infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight (CVE-2023-34966) Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight (CVE-2023-34967) Path disclosure vulnerability in the Spotlight protocol (CVE-2023-34968) References: - https://bugs.mageia.org/show_bug.cgi?id=32152 - - - - - - - - https://www.cve.org/CVERecord?id=CVE-2022-2127 - https://www.cve.org/CVERecord?id=CVE-2023-3347 - https://www.cve.org/CVERecord?id=CVE-2023-34966 - https://www.cve.org/CVERecord?id=CVE-2023-34967 - https://www.cve.org/CVERecord?id=CVE-2023-34968 SRPMS: - 8/core/samba-4.16.11-1.mga8 . Revised Samba distributions address multiple security flaws, including improper memory access and inadequate packet authentication. Learn more!. Samba Security Fix, Mageia Samba Update, Out-of-Bounds Read Defense, Security Package Management. . LinuxSecurity.com Team
Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling or MITM attacks. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5153-1
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for pidgin ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1665-1 Rating: important References: #1199025 Cross-References: CVE-2022-26491 CVSS scores: CVE-2022-26491 (SUSE): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Workstation Extension 15-SP3 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for pidgin fixes the following issues: - CVE-2022-26491: Fixed MITM vulnerability when DNSSEC wasn't used (bsc#1199025). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1665=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1665=1 - SUSE Linux Enterprise Workstation Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-WE-15-SP3-2022-1665=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-1665=1 Package List: - openSUSE Leap 15.4(aarch64 ppc64le s390x x86_64): finch-2.13.0-150200.12.6.1 finch-debuginfo-2.13.0-150200.12.6.1 finch-devel-2.13.0-150200.12.6.1 libpurple-2.13.0-150200.12.6.1 libpurple-debuginfo-2.13.0-150200.12.6.1 libpurple-devel-2.13.0-150200.12.6.1 libpurple-plugin-sametime-2.13.0-150200.12.6.1 libpurple-plugin-sametime-debuginfo-2.13.0-150200.12.6.1 libpurple-tcl-2.13.0-150200.12.6.1 libpurple-tcl-debuginfo-2.13.0-150200.12.6.1 pidgin-2.13.0-150200.12.6.1 pidgin-debuginfo-2.13.0-150200.12.6.1 pidgin-debugsource-2.13.0-150200.12.6.1 pidgin-devel-2.13.0-150200.12.6.1 - openSUSE Leap 15.4 (noarch): libpurple-branding-upstream-2.13.0-150200.12.6.1 libpurple-lang-2.13.0-150200.12.6.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): finch-2.13.0-150200.12.6.1 finch-debuginfo-2.13.0-150200.12.6.1 finch-devel-2.13.0-150200.12.6.1 libpurple-2.13.0-150200.12.6.1 libpurple-debuginfo-2.13.0-150200.12.6.1 libpurple-devel-2.13.0-150200.12.6.1 libpurple-plugin-sametime-2.13.0-150200.12.6.1 libpurple-plugin-sametime-debuginfo-2.13.0-150200.12.6.1 libpurple-tcl-2.13.0-150200.12.6.1 libpurple-tcl-debuginfo-2.13.0-150200.12.6.1 pidgin-2.13.0-150200.12.6.1 pidgin-debuginfo-2.13.0-150200.12.6.1 pidgin-debugsource-2.13.0-150200.12.6.1 pidgin-devel-2.13.0-150200.12.6.1 - openSUSE Leap 15.3 (noarch): libpurple-branding-upstream-2.13.0-150200.12.6.1 libpurple-lang-2.13.0-150200.12.6.1 - SUSE Linux Enterprise Workstation Extension 15-SP3 (noarch): libpurple-branding-upstream-2.13.0-150200.12.6.1 libpurple-lang-2.13.0-150200.12.6.1 - SUSE Linux Enterprise Workstation Extension 15-SP3 (x86_64): libpurple-2.13.0-150200.12.6.1 libpurple-debuginfo-2.13.0-150200.12.6.1 libpurple-devel-2.13.0-150200.12.6.1 libpurple-plugin-sametime-2.13.0-150200.12.6.1 libpurple-plugin-sametime-debuginfo-2.13.0-150200.12.6.1 pidgin-2.13.0-150200.12.6.1 pidgin-debuginfo-2.13.0-150200.12.6.1 pidgin-debugsource-2.13.0-150200.12.6.1 pidgin-devel-2.13.0-150200.12.6.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (aarch64 ppc64le s390x): finch-2.13.0-150200.12.6.1 finch-debuginfo-2.13.0-150200.12.6.1 finch-devel-2.13.0-150200.12.6.1 libpurple-2.13.0-150200.12.6.1 libpurple-debuginfo-2.13.0-150200.12.6.1 libpurple-devel-2.13.0-150200.12.6.1 libpurple-plugin-sametime-2.13.0-150200.12.6.1 libpurple-plugin-sametime-debuginfo-2.13.0-150200.12.6.1 libpurple-tcl-2.13.0-150200.12.6.1 libpurple-tcl-debuginfo-2.13.0-150200.12.6.1 pidgin-2.13.0-150200.12.6.1 pidgin-debuginfo-2.13.0-150200.12.6.1 pidgin-debugsource-2.13.0-150200.12.6.1 pidgin-devel-2.13.0-150200.12.6.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (noarch): libpurple-branding-upstream-2.13.0-150200.12.6.1 libpurple-lang-2.13.0-150200.12.6.1 References: https://www.suse.com/security/cve/CVE-2022-26491.html https://bugzilla.suse.com/1199025 . Important security patch issued for Pidgin by SUSE to address an MITM vulnerability. Users are urged to update to ensure system safety.. SUSE Pidgin Update, Important Security Patch, Man In The Middle. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for apache-commons-httpclient ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3149-1 Rating: important References: #1178171 #945190 Cross-References: CVE-2014-3577 CVE-2015-5262 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Enterprise Storage 5 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for apache-commons-httpclient fixes the following issues: - http/conn/ssl/SSLConnectionSocketFactory.java ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors. [bsc#945190, CVE-2015-5262] - org.apache.http.conn.ssl.AbstractVerifier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows MITM attackers to spoof SSL servers via a "CN="string in a field in the distinguished name (DN) of a certificate. [bsc#1178171, CVE-2014-3577] Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2020-3149=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-3149=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2020-3149=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2020-3149=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-3149=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2020-3149=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2020-3149=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2020-3149=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-3149=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2020-3149=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2020-3149=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2020-3149=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2020-3149=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2020-3149=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2020-3149=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2020-3149=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE OpenStack Cloud Crowbar 8 (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE OpenStack Cloud 9 (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE OpenStack Cloud 8 (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE OpenStack Cloud 7 (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Linux Enterprise Server 12-SP3-BCL (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): apache-commons-httpclient-3.1-6.3.1 - SUSE Enterprise Storage 5 (noarch): apache-commons-httpclient-3.1-6.3.1 - HPE Helion Openstack 8 (noarch): apache-commons-httpclient-3.1-6.3.1 References: https://www.suse.com/security/cve/CVE-2014-3577.html https://www.suse.com/security/cve/CVE-2015-5262.html https://bugzilla.suse.com/1178171 https://bugzilla.suse.com/945190 . SUSE has issued a Security Update to fix vulnerabilities in Apache Commons HttpClient as noted in SUSE-SU-2020:3149-1. Apply the patches promptly to protect your systems. SUSE Security Update, Apache HttpClient, OpenStack Cloud, Denial of Service, Man In The Middle. . Severity: Important. LinuxSecurity.com Team
An update for gnutls is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: gnutls security update Advisory ID: RHSA-2020:2639-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2639 Issue date: 2020-06-22 CVE Names: CVE-2020-13777 ==================================================================== 1. Summary: An update for gnutls is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.0) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS E4S (v. 8.0) - aarch64, ppc64le, s390x, x86_64 3. Description: The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS. Security Fix(es): * gnutls: session resumption works without master key allowing MITM (CVE-2020-13777) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1843723 -CVE-2020-13777 gnutls: session resumption works without master key allowing MITM 6. Package List: Red Hat Enterprise Linux AppStream E4S (v. 8.0): aarch64: gnutls-c++-3.6.5-3.el8_0.aarch64.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.aarch64.rpm gnutls-dane-3.6.5-3.el8_0.aarch64.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.aarch64.rpm gnutls-debuginfo-3.6.5-3.el8_0.aarch64.rpm gnutls-debugsource-3.6.5-3.el8_0.aarch64.rpm gnutls-devel-3.6.5-3.el8_0.aarch64.rpm gnutls-utils-3.6.5-3.el8_0.aarch64.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.aarch64.rpm ppc64le: gnutls-c++-3.6.5-3.el8_0.ppc64le.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.ppc64le.rpm gnutls-dane-3.6.5-3.el8_0.ppc64le.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.ppc64le.rpm gnutls-debuginfo-3.6.5-3.el8_0.ppc64le.rpm gnutls-debugsource-3.6.5-3.el8_0.ppc64le.rpm gnutls-devel-3.6.5-3.el8_0.ppc64le.rpm gnutls-utils-3.6.5-3.el8_0.ppc64le.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.ppc64le.rpm s390x: gnutls-c++-3.6.5-3.el8_0.s390x.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.s390x.rpm gnutls-dane-3.6.5-3.el8_0.s390x.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.s390x.rpm gnutls-debuginfo-3.6.5-3.el8_0.s390x.rpm gnutls-debugsource-3.6.5-3.el8_0.s390x.rpm gnutls-devel-3.6.5-3.el8_0.s390x.rpm gnutls-utils-3.6.5-3.el8_0.s390x.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.s390x.rpm x86_64: gnutls-c++-3.6.5-3.el8_0.i686.rpm gnutls-c++-3.6.5-3.el8_0.x86_64.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.i686.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.x86_64.rpm gnutls-dane-3.6.5-3.el8_0.i686.rpm gnutls-dane-3.6.5-3.el8_0.x86_64.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.i686.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.x86_64.rpm gnutls-debuginfo-3.6.5-3.el8_0.i686.rpm gnutls-debuginfo-3.6.5-3.el8_0.x86_64.rpm gnutls-debugsource-3.6.5-3.el8_0.i686.rpm gnutls-debugsource-3.6.5-3.el8_0.x86_64.rpm gnutls-devel-3.6.5-3.el8_0.i686.rpm gnutls-devel-3.6.5-3.el8_0.x86_64.rpm gnutls-utils-3.6.5-3.el8_0.x86_64.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.i686.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.x86_64.rpm Red Hat Enterprise LinuxBaseOS E4S (v. 8.0): Source: gnutls-3.6.5-3.el8_0.src.rpm aarch64: gnutls-3.6.5-3.el8_0.aarch64.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.aarch64.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.aarch64.rpm gnutls-debuginfo-3.6.5-3.el8_0.aarch64.rpm gnutls-debugsource-3.6.5-3.el8_0.aarch64.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.aarch64.rpm ppc64le: gnutls-3.6.5-3.el8_0.ppc64le.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.ppc64le.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.ppc64le.rpm gnutls-debuginfo-3.6.5-3.el8_0.ppc64le.rpm gnutls-debugsource-3.6.5-3.el8_0.ppc64le.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.ppc64le.rpm s390x: gnutls-3.6.5-3.el8_0.s390x.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.s390x.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.s390x.rpm gnutls-debuginfo-3.6.5-3.el8_0.s390x.rpm gnutls-debugsource-3.6.5-3.el8_0.s390x.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.s390x.rpm x86_64: gnutls-3.6.5-3.el8_0.i686.rpm gnutls-3.6.5-3.el8_0.x86_64.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.i686.rpm gnutls-c++-debuginfo-3.6.5-3.el8_0.x86_64.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.i686.rpm gnutls-dane-debuginfo-3.6.5-3.el8_0.x86_64.rpm gnutls-debuginfo-3.6.5-3.el8_0.i686.rpm gnutls-debuginfo-3.6.5-3.el8_0.x86_64.rpm gnutls-debugsource-3.6.5-3.el8_0.i686.rpm gnutls-debugsource-3.6.5-3.el8_0.x86_64.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.i686.rpm gnutls-utils-debuginfo-3.6.5-3.el8_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-13777 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXvBSUtzjgjWX9erEAQizAxAAppK/Wcbxqwfd8z9XNYXwk6s78mqWW7D2 8Vq1DJdYG9k8JaVxgRwzhSaifqdWx5xgZsM4HOVRAixQQRMZm7CkNibVgYyQ7Gkf +bfYPTYWN77DxzjFzDhOAKNXTpVP4SYGaNcJbTIWUHj7Ou3SZDGCSyGIQs8JJc0L RXM/CLVKP4gSWvWIW17WIiSxcR4+IrjOVTkrWDTy4v7j8uEUW3l5HWBRz/+bWctS D6DoG48hqRzhdjkD/A5YV00eS8ZeUj4dCMIkr1qnTow9Qv1QnQJq8p4xTCh3qklP 2UB0vVU8si583EY1wOrLEvaM71LEOpwStcZKaRDwpv93PsEbJ6VBxDxIDElqIRSJ 34VXBzh6B+V/J6z8PiGza4Z84WO3x9arjMRYHIUhWgjuEoZNxreqyzgFqR8dpfEi LFipP8vXG6jo6EXUOTtYoZ+dV6PbvW7N1XQI6CG+BVAjuaQ020RzZjDZdM5oCsCY 9BX9/4RMfPzLAWNPhKjJVHUQxTkW7+d+ki7zh9TY7cJuIUy23stEszzpc2p6J7Hj Fpv+rPpk3KzW3QoY2g6DMkBbnGFLIr9uCb+SFDUuZfgb0WQ8YA63pdImGQTe4ZL2 hxMU4WnvROUbmCZT81iA6Bu7wKlSi00gftv8k6watSbArGnGKUSlOGMCGxqQ2gD4 S1uVYOlZFnU=tYke -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Updated jss packages fix security vulnerability: A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS CryptoManager, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly . MGASA-2020-0018 - Updated jss packages fix security vulnerability Publication date: 05 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0018.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-14823 Updated jss packages fix security vulnerability: A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS CryptoManager, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the Middle (CVE-2019-14823). References: - https://bugs.mageia.org/show_bug.cgi?id=25958 - https://lists.fedoraproject.org/archives/list/
A security update is now available for Open Liberty 19.0.0.12 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Open Liberty 19.0.0.12 Runtime security update Advisory ID: RHSA-2019:4117-01 Product: Open Liberty Advisory URL: https://access.redhat.com/errata/RHSA-2019:4117 Issue date: 2019-12-09 ==================================================================== 1. Summary: A security update is now available for Open Liberty 19.0.0.12 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the originating Security Bulletin link(s) in the References section. 2. Description: Open Liberty is a lightweight open framework for building fast and efficient cloud-native Java microservices. This release of Open Liberty 19.0.0.12 serves as a replacement for Open Liberty 19.0.0.11 and includes bug fixes, enhancements, and security fixes. For specific information about this release, see links in the References section. Security Fix(es): * Information disclosure vulnerability in WebSphere Application Server (CVE-2019-4441) * Man in the middle vulnerability in WebSphere Application Server Liberty (CVE-2014-3603) * (CVE-2019-4663) For more details about the security issue(s), see the IBM Security Bulletin links for each CVE, listed in the References section. 3. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains adownload link (you must log in to download the update). 4. References: https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=open.liberty&downloadType=distributions&version=19.0.0.12 https://www.ibm.com/support/pages/security-bulletin-information-disclosure-vulnerability-websphere-application-server-cve-2019-4441 https://www.ibm.com/support/pages/security-bulletin-man-middle-vulnerability-websphere-application-server-liberty-cve-2014-3603 https://access.redhat.com/articles/4544981 5. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXe5lqtzjgjWX9erEAQhNWQ//Xk+PeuJgLHstwIil06tNre6EmjZmTIoW 0FVDY32xoAYacPvyHE/0O2TNQexd+CoS8x1cL6tgDKXx0lcfvpW2tXXBjUI4zfhy OGjEFn6r/2Z0m2IOJMDDC1Cy3Fp/rftbUl9FJYLtcvHgXYI5nRPA1taqfq20zqIp zbAvgfG8SVRC31FvHoAf8HA6wrYrjK6JUvp1+KbVk12xkkfnHchZg3GBXyViakQn lMmXenMGGXFJaaPfnqErWFDiE9bvSKtQBbQWW7fWViaPASGI0ESnbTFf+Unzxht2 jf9/5313g54U8q7NXjucP/TsJi0VuwfkLZJVGXuMUUVNKxWXzjJL0aoLyIPAkuj7 X+cOJXnHWxVTqaTIsyMi+tZICoQqvYS98fuPYLXSoK9gnf+cZHefDEcvWJRPIa0g D6PNVUvj7Nwi4zqrxAuxPEW0oIuw5O2u8fsAORrzI4hGv+6KeVQ2IK2OGK/T9S7a kDS8nG+rZT7+/10xI7VLyHwR93xT8aE8NGBPquKE3g5K1yTeCnQsn3JShVdfgm5g YorqYZWZrerKBwL70z1wQTYl747VSsykUrtJKBHhgYI0bmBa38weF/CCELrQE3B9 VzSfPI1jtUgAolbs6euQbGVhrsQ3rjdNgi4GfH+HhC6cv/+Dz4yU3Abs0Kvk+eC6 A2wdk90F/kI=xUYG -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for qpid-proton is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: qpid-proton security update Advisory ID: RHSA-2019:1400-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2019:1400 Issue date: 2019-06-06 CVE Names: CVE-2019-0223 ==================================================================== 1. Summary: An update for qpid-proton is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 13.0 - ppc64le, x86_64 3. Description: The AMQ Client enables connecting, sending, and receiving messages over the AMQP 1.0 wire transport protocol. Security Fix(es): * qpid-proton: TLS Man in the Middle Vulnerability (CVE-2019-0223) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. This update provides various bug fixes and enhancements in addition to the client package versions previously released on Red Hat Enterprise Linux 7. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1702439 - CVE-2019-0223 qpid-proton: TLS Man in theMiddle Vulnerability 1704978 - AMQ Interconnect edge mode doesn't work with anonymous channels; rebuild container after resolved to 1.4 version [openstack-13] 1717133 - add jsoncpp for dep of qpid-proton for fixing CVE-2019-0223 6. Package List: Red Hat OpenStack Platform 13.0: Source: jsoncpp-1.7.7-1.el7.src.rpm qpid-proton-0.27.0-3.el7.src.rpm ppc64le: jsoncpp-1.7.7-1.el7.ppc64le.rpm jsoncpp-debuginfo-1.7.7-1.el7.ppc64le.rpm python-qpid-proton-0.27.0-3.el7.ppc64le.rpm qpid-proton-c-0.27.0-3.el7.ppc64le.rpm qpid-proton-cpp-0.27.0-3.el7.ppc64le.rpm qpid-proton-debuginfo-0.27.0-3.el7.ppc64le.rpm x86_64: jsoncpp-1.7.7-1.el7.x86_64.rpm jsoncpp-debuginfo-1.7.7-1.el7.x86_64.rpm python-qpid-proton-0.27.0-3.el7.x86_64.rpm qpid-proton-c-0.27.0-3.el7.x86_64.rpm qpid-proton-cpp-0.27.0-3.el7.x86_64.rpm qpid-proton-debuginfo-0.27.0-3.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-0223 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXPk3l9zjgjWX9erEAQisGw/9HrWTr6H1mCSe3e3ZAUNwCqghiJ752W4Q OTp2xwQ5APHTjpQQqOkJyV6P413wtWc3NCYon4ATgN2r7+uBk93Lsu4QOpiGytCv z4M1iZ1AyefQIps50UAozS/moBwf28700HaCoJe6TLstBHZ0zRpSxlu/WMr0FItq z4jfL5RqcJY23T5eBeM4u0J4XURthRq4ZBMhEci5q/97VUuvwFpUhcQ7Jks7t04b EUYezxPr2H+YaWRMHhiiiDhvbynppIGmWbJ/qZXD7N7dqUKxqhdxz15Q+hOUNd6b beoX3QRSbp8ckZCVvYl9yl8mTOoJxg6TG0It+AkuFuSHxlsRTyFZZ4lhmQG0Fxfa TtKhv5KRfGUE8ifE1S6WoqgjCNQmzedxjaAXF+W5CDLzQW4l35Tt8HVT9ZwHCVGp Sgpyr7o3rGZ7d44vk+DE+2kIxtCECezGFy5ZYJCPSLMmYUa5RiySRmXrufohulcP SoDWXTlT32EHams7UJw8hVNdCu4ad3tqdP7408koeMMbxgEsD3hE2GlQIVETmu5s Nm/K8+FJlHPpuKCM9fzIKQoRKxKG0JkK0vZ3H8UAUv3Xj0KKX/QK7YPPRxDEfl7J YakccH6AM4CxNz00LWKayiLuetaw6LjPHm7bD/ovCKYZLR5VZGIr6UHgS7hLWyAY MTiAnsfNvog=PwoV -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.