The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4354 https://linux.oracle.com/errata/ELSA-2023-4354.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: curl-7.76.1-23.el9_2.2.x86_64.rpm curl-minimal-7.76.1-23.el9_2.2.x86_64.rpm libcurl-7.76.1-23.el9_2.2.i686.rpm libcurl-7.76.1-23.el9_2.2.x86_64.rpm libcurl-devel-7.76.1-23.el9_2.2.i686.rpm libcurl-devel-7.76.1-23.el9_2.2.x86_64.rpm libcurl-minimal-7.76.1-23.el9_2.2.i686.rpm libcurl-minimal-7.76.1-23.el9_2.2.x86_64.rpm aarch64: curl-7.76.1-23.el9_2.2.aarch64.rpm curl-minimal-7.76.1-23.el9_2.2.aarch64.rpm libcurl-7.76.1-23.el9_2.2.aarch64.rpm libcurl-devel-7.76.1-23.el9_2.2.aarch64.rpm libcurl-minimal-7.76.1-23.el9_2.2.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//curl-7.76.1-23.el9_2.2.src.rpm Related CVEs: CVE-2023-28321 CVE-2023-28322 Description of changes: [7.76.1-23.el9_2.2] - unify the upload/method handling (CVE-2023-28322) - fix host name wildcard checking (CVE-2023-28321) _______________________________________________ El-errata mailing list
Class compilation issue. (CVE-2022-21540) Improper restriction of MethodHandle.invokeBasic(). (CVE-2022-21541) Integer truncation issue in Xalan-J. (CVE-2022-34169) Improper MultiByte conversion can lead to buffer overflow. (CVE-2022-21618) Improper handling of long NTLM client hostnames. (CVE-2022-21619) . MGASA-2022-0435 - Updated java packages fix security vulnerability Publication date: 24 Nov 2022 URL: https://advisories.mageia.org/MGASA-2022-0435.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-21540, CVE-2022-21541, CVE-2022-21618, CVE-2022-21619, CVE-2022-21624, CVE-2022-21626, CVE-2022-21628, CVE-2022-34169, CVE-2022-39399 Class compilation issue. (CVE-2022-21540) Improper restriction of MethodHandle.invokeBasic(). (CVE-2022-21541) Integer truncation issue in Xalan-J. (CVE-2022-34169) Improper MultiByte conversion can lead to buffer overflow. (CVE-2022-21618) Improper handling of long NTLM client hostnames. (CVE-2022-21619) Insufficient randomization of JNDI DNS port numbers. (CVE-2022-21624) Excessive memory allocation in X.509 certificate parsing. (CVE-2022-21626) HttpServer no connection count limit. (CVE-2022-21628) Missing SNI caching in HTTP/2. (CVE-2022-39399) References: - https://bugs.mageia.org/show_bug.cgi?id=30753 - https://access.redhat.com/errata/RHSA-2022:5696 - https://access.redhat.com/errata/RHSA-2022:5683 - https://www.oracle.com/security-alerts/cpujul2022.html#AppendixJAVA - https://access.redhat.com/errata/RHSA-2022:7007 - https://access.redhat.com/errata/RHSA-2022:7013 - https://www.oracle.com/security-alerts/cpuoct2022.html#AppendixJAVA - https://www.cve.org/CVERecord?id=CVE-2022-21540 - https://www.cve.org/CVERecord?id=CVE-2022-21541 - https://www.cve.org/CVERecord?id=CVE-2022-21618 - https://www.cve.org/CVERecord?id=CVE-2022-21619 - https://www.cve.org/CVERecord?id=CVE-2022-21624 - https://www.cve.org/CVERecord?id=CVE-2022-21626 - https://www.cve.org/CVERecord?id=CVE-2022-21628 -https://www.cve.org/CVERecord?id=CVE-2022-34169 - https://www.cve.org/CVERecord?id=CVE-2022-39399 SRPMS: - 8/core/java-1.8.0-openjdk-1.8.0.352.b08-1.1.mga8 - 8/core/java-11-openjdk-11.0.17.0.8-1.1.mga8 - 8/core/timezone-2022e-1.mga8 . Recent enhancements to Java packages in Mageia tackle essential concerns such as function management and memory overflow risks.. Java Security Update, Mageia Patch, Buffer Overflow Fix, JNDI DNS Security, NTLM Hostname Issue. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.