Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update is now available for Red Hat Satellite 6.13. The release contains a new version of Satellite and important security fixes for various components.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Satellite 6.13 Release Advisory ID: RHSA-2023:2097-03 Product: Red Hat Satellite 6 Advisory URL: https://access.redhat.com/errata/RHSA-2023:2097 Issue date: 2023-05-03 CVE Names: CVE-2022-1471 CVE-2022-22577 CVE-2022-23514 CVE-2022-23515 CVE-2022-23516 CVE-2022-23517 CVE-2022-23518 CVE-2022-23519 CVE-2022-23520 CVE-2022-25857 CVE-2022-27777 CVE-2022-31163 CVE-2022-32224 CVE-2022-33980 CVE-2022-38749 CVE-2022-38750 CVE-2022-38751 CVE-2022-38752 CVE-2022-41323 CVE-2022-41946 CVE-2022-42003 CVE-2022-42004 CVE-2022-42889 CVE-2023-23969 CVE-2023-24580 ==================================================================== 1. Summary: An update is now available for Red Hat Satellite 6.13. The release contains a new version of Satellite and important security fixes for various components. 2. Relevant releases/architectures: Red Hat Satellite 6.13 for RHEL 8 - noarch, x86_64 3. Description: Red Hat Satellite is a systems management tool for Linux-based infrastructure. It allows for provisioning, remote management, and monitoring of multiple Linux deployments with a single centralized tool. Security Fix(es): * CVE-2022-1471 CVE-2022-25857 CVE-2022-38749 CVE-2022-38750 CVE-2022-38751 CVE-2022-38752 candlepin and puppetserver: various flaws * CVE-2022-22577 tfm-rubygem-actionpack: rubygem-actionpack: Possible cross-site scripting vulnerability in Action Pack * CVE-2022-23514 rubygem-loofah: inefficient regular expression leading to denial of service * CVE-2022-23515 rubygem-loofah:rubygem-loofah: Improper neutralization of data URIs leading to Cross Site Scripting * CVE-2022-23516 rubygem-loofah: Uncontrolled Recursion leading to denial of service * CVE-2022-23517 tfm-rubygem-rails-html-sanitizer: rubygem-rails-html-sanitizer: Inefficient Regular Expression leading to denial of service * CVE-2022-23518 tfm-rubygem-rails-html-sanitizer: rubygem-rails-html-sanitizer: Improper neutralization of data URIs leading to Cross site scripting * CVE-2022-23519 tfm-rubygem-rails-html-sanitizer: rubygem-rails-html-sanitizer: Cross site scripting vulnerability with certain configurations * CVE-2022-23520 tfm-rubygem-rails-html-sanitizer: rubygem-rails-html-sanitizer: Cross site scripting vulnerability with certain configurations * CVE-2022-27777 tfm-rubygem-actionview: Possible cross-site scripting vulnerability in Action View tag helpers* CVE-2022-31163 rubygem-tzinfo: rubygem-tzinfo: arbitrary code execution * CVE-2022-32224 tfm-rubygem-activerecord: activerecord: Possible RCE escalation bug with Serialized Columns in Active Record * CVE-2022-33980 candlepin: apache-commons-configuration2: Apache Commons Configuration insecure interpolation defaults * CVE-2022-41323 satellite-capsule:el8/python-django: Potential denial-of-service vulnerability in internationalized URLs * CVE-2022-41946 candlepin: postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions * CVE-2022-42003 CVE-2022-42004 candlepin: various flaws * CVE-2022-42889 candlepin: apache-commons-text: variable interpolation RCE * CVE-2022-23514 rubygem-loofah: inefficient regular expression leading to denial of service * CVE-2023-23969 python-django: Potential denial-of-service via Accept-Language headers* CVE-2023-24580 python-django: Potential denial-of-service vulnerability in file uploads For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. AdditionalChanges: The items above are not a complete list of changes. This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document. 4. Solution: For Red Hat Satellite 6.13, see the following documentation for the release. https://docs.redhat.com/en/documentation/red_hat_satellite/6.13 The important instructions on how to upgrade are available below. https://docs.redhat.com/en/documentation/red_hat_satellite/6.13/html/upgrading_and_updating_red_hat_satellite/index 5. Bugs fixed (https://bugzilla.redhat.com/): 1225819 - [RFE] Ability to sync from closest CDN mirror for Capsule 1266407 - IPA (external users) not able to authenticate using hammer CLI: invalid user / SSO failed 1630294 - [RFE] Remote execution overview dashboard should be more interactive like the Monitor Dashboard 1638226 - [RFE] Show difference in errata between ContentViewVersions 1650468 - [RFE] Allow to export Docker images from content views or as repository as part ISS 1761012 - [RFE] Ability to generate a report for ansible/remote execution task result. 1786358 - [RFE] Ability to make persistent changes in "ansible.cfg" on Satellite Server. 1787456 - [RFE] Candlepin log rotation settings should be user-configurable 1813274 - [RFE] Allow customers to be able to add more columns to 'All Hosts' page in Red Hat Satellite 6 webui. 1826648 - [RFE] new report template to list all the installed packages 1837767 - Errata search filtered with ID does not work in Web UI 1841534 - Provide support for "Privileged User" session when host console is being taken via cockpit from Satellite 6.7 UI 1845489 - Audit page shows "auditable id / Host2" for "Host1" but Host2 does not exist or deleted from the all hosts 1880947 - Satellite fails with "HTTP error (500 - Internal Server Error): PG::UniqueViolation: ERROR: duplicate key value violates unique constraint" while running concurrent registrations 1888667 - "Applied Errata" report template does not consider input "Up to" and"Since" in WebUI, hammer works 1895976 - Hammer Allows Invalid Release Version to be Set on Activation Key 1920810 - Error message related to Trend in production log 1931027 - Entitlement certificate is missing content section for a custom product 1931533 - Update foreman-bootloaders-redhat to 202102220000 to add efinet module to Grub2 modules 1950468 - root_pass setting does not enforce minimum length of 8 characters as the host and hostgroups forms do 1952529 - Package and Errata actions on content hosts selected using the "select all hosts" option fails. 1956210 - Health check should use hostname -f 1956985 - [RFE] Capsule Last Sync date and status should not be based on task data. 1963266 - [RFE]: Provide Capsule Load Balancer as an option for Global Registration Feature 1964037 - wrong generation of /etc/tomcat/cert-users.properties 1965871 - Change /var/log/candlepin directory owner/group to candlepin with 750 permission 1978683 - [global registration] - puppet configuration are not inherited to host from host-group while global registration 1978995 - [RFE] The satellite-installer should display the mismatched FQDN additionally rather than just showing the commands to verify the output 1990790 - [RFE] add possibility to resize bookmarks dropdown menu 1990875 - Update the foreman-discovery-image to inject the latest e1000e NIC drivers for I219-LM network cards 1995097 - Tuning profile 'default' requires at least 8 GB of memory and 1 CPU cores 1995470 - Activation key can be deleted, but still shows up in hostgroup configuration 1997186 - [regression] data.yml is referring to old sync plain id which does not exist in katello_sync_plans 1997199 - Can't create bookmarks under Lifecyle Environments 2026151 - Can't sync private Azure registry to Satellite 2029402 - [RFE] Add functionality in Hammer to Add/Delete a single Ansible role to Hostgroup without defining every role. 2032040 - Enhance foreman-rake katello:correct_repositories to handle Katello::Errors::CandlepinError: Unable to find content with the ID"xxxxxxxxxxx". 2043600 - consumer certificate is generated with validity after 19th Jan 2038 which is causing 2038 bug on 32bit systems 2050234 - pulp_streamer runs out of file descriptors when upstream server is unavailable 2052904 - [RFE] Prevent the deletion of content credentials when they are in use in Satellite 6.x 2056402 - [RFE] New hosts page doesn't show global and host parameters2057314 - RHEL 9 as Guest OS is not available on Satellite 6.11 2060099 - [RFE] ouia-ID for tile cards in the new host details page 2062526 - Another deadlock issue when syncing repos with high concurrency 2063999 - No profiles are shown for any module streams 2066323 - [RFE] Satellite should use the newer asynchronous endpoint to export manifests 2069438 - [RFE] new host ui details, tracer tab, page reload required after change 2073847 - Restarting postgres just before task finish causes discrepancy between foreman and dynflow task status - forever 2077363 - Fail to sync kickstart repositories with same sub repositories concurrently 2080296 - CVE-2022-27777 tfm-rubygem-actionview: Possible cross-site scripting vulnerability in Action View tag helpers2080302 - CVE-2022-22577 rubygem-actionpack: Possible cross-site scripting vulnerability in Action Pack 2088156 - Broken Link in the Realms section of Satellite 2088529 - ForemanCustomScript in Host provisioned on Azure CR fails with `command not found` 2094912 - Unable to search the hosts based on the query "ansible_role", if the roles are inherited from the hostgroup. 2098079 - [RFE] Add an ability to search by Insights status 2101708 - when host is deleted on hypervisor while ansible job is running, hosts gets deleted on hypervisor level 2102078 - podman run returns Error: unexpected end of JSON input on image pulled from satellite 2103936 - Execution of satellite-installer raises multiple "warning: URI.escape is obsolete" messages in Red Hat Satellite 6.11 2104247 - [RFE] version non-specific flag to enable puppet on Red Hat Satellite. 2105067 - CVE-2022-33980apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults 2105441 - RHEL 9 provisioned host goes into emergency mode after initial reboot 2106475 - [RFE] Enhance puppet agent deployment for external puppetserver 2106753 - [RFE] Allow user to choose between Graphical and Text mode anaconda installer during system build via Satellite 6 2107011 - [RFE] Keep notifications from RSS feed in Notifications drawer in Satellite webui for a longer period of time 2107758 - [RFE] Upgrade to Redis 6 2108997 - CVE-2022-32224 activerecord: Possible RCE escalation bug with Serialized Columns in Active Record 2109634 - Add module profile information to modulemd enpoints 2110551 - CVE-2022-31163 rubygem-tzinfo: arbitrary code execution 2111159 - Refreshing Alternate Content Source complains about invalid remote URL 2115970 - Sync container images of existing docker type repositories fail with 404 - Not found 2116375 - Even in 6.11.1, sync summary email notification shows the incorrect summary for newly added errata. 2118651 - pull-provider rex jobs hang if host is not configured correctly 2119053 - [RFE] X509 Certification Authorities" and "Optional HTTP headers as JSON (ERB allowed)" fields need to be included via Hammer CLI for "hammer webhook create" and "hammer webhook update" sub-options 2119155 - With every edit of an exising webhook, the value in password field disappears in Satellite 6.10/6.11/6.12 2119911 - VMware Image based Provisioning fails with error- : Could not find virtual machine network interface matching 2120640 - New host details Insights tab doesn't work with breadcrumb switcher 2121210 - [RFE] Add call-to-action empty states 2121288 - Still getting API request timeout when indexing contents. 2122617 - Kerberos authentication fails for POST, PUT and DELETE api calls 2123593 - Satellite should be able to process (and publish) compressed comps.xml / groups metadata 2123696 - The Value of "Allowed bootdisk types" shows up as subnetfull_host where as it is set assubnet,full_host in Satellite 6.12 2123835 - System build based on "PXELess Discovery" will always fail if the "Installation token lifetime" has been disabled in Satellite 6.12 2123932 - Unable to "Remove" a repository directly if the repo is part of a CV as well as CCV in Satellite 6.12 2124419 - Jobs pushed in MQTT queue is not delivered if yggdrasild was not running and communicating with the right broker before the jobs were pushed 2124520 - Changing the Capsule parameter post the curl command generated in Global Registration template failed with error "There was an error while generating the command, see the logs for more information." 2125424 - Mismatched files between stage 1 and stage 2 kernel images during kickstart provisioning 2125444 - Syncable exports across partitions causes ' Invalid cross-device link' error 2126200 - CV version details repository tab links to library_instance_inverse version and lets you use it like a regular library repo 2126349 - Missing cron job for ACS refresh in /etc/cron.d/katello 2126372 - Refreshing ACS with --name instead of --id fails with "Error: Found more than one alternate_content_source." 2126695 - Wrong Ansible documentation links 2126789 - CVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collections 2126905 - Packages tab - Add dropdown to select upgrade version 2127180 - random failure of Inventory Sync 2127470 - Content view publish fails when the content view and repository both have a large name with : Error message: the server returns an error HTTP status code: 500 2127998 - RHEL 9 appstream and baseos kickstart repositories not showing as recommended repositories 2128038 - [RFE] Add Templates tab in the new UI, under (Hosts > All Hosts > Host ) 2128256 - Insights recommendation sync failing in Satelliite 2128864 - Repo Deletion with no feed url causes a `ArgumentError` 2128894 - [RFE] Need syncable yum-format repository imports 2129706 - CVE-2022-38749 snakeyaml: Uncaught exception inorg.yaml.snakeyaml.composer.Composer.composeSequenceNode 2129707 - CVE-2022-38750 snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject 2129709 - CVE-2022-38751 snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match 2129710 - CVE-2022-38752 snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode 2129950 - ISE when creating a CV with org_id specified as array 2130596 - insights-client --register --verbose throwing error UnicodeEncodeError: 'ascii' codec can't encode character '\ufffd' in position 94: ordinal not in range(128) 2130698 - New Host UI: Toggle group is hidden when host has no installable errata 2131312 - Satellite 6.9\6.10\6.11 suddenly cannot enable or sync satellite-tools repo for rhel 8 but the same works for rhel 7 2131369 - Updating subscription attributes of a host, such as CV and LCE fails with "Katello::Resources::Candlepin::Consumer: 400 Bad Request" and "Cannot construct instance of `org.candlepin.dto.api.v1.GuestIdDTO`" error 2131839 - re-enabling sync plans [FAIL] Could not update the sync plan: ERF28-1357 [ForemanTasks::RecurringLogicCancelledException]: Cannot update a cancelled Recurring Logic. 2132452 - Missing ouia-id for content view 2133343 - Content view filter will include module streams of other repos/arches if the errata contain rpms in different repos/arches. 2133615 - Content view filter included errata not in the filter date range 2134283 - SSH key passphrase is not working if password was set previously 2134682 - Getting "undefined method `schema_version' for nil:NilClass" while syncing from quay.io 2135244 - CVE-2022-42003 jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS 2135247 - CVE-2022-42004 jackson-databind: use of deeply nested arrays 2135418 - rubygem-foreman_hooks scriptlet issues an error message 2135435 - CVE-2022-42889 apache-commons-text: variable interpolation RCE 2136130 - CVE-2022-41323 python-django:Potential denial-of-service vulnerability in internationalized URLs 2137318 - hammer content-view purge only deletes up to "Entries per page" versions 2137350 - hammer repository types command is missing options 2137539 - mosquitto service is missing in `satellite-maintain service status -b` output 2138887 - [RFE] Add content export to FAM 2139209 - Don't use the term 'Subscription Watch' anymore 2139418 - MQTT ReX mode makes it too easy to to DDOS Satellite 2139441 - Improve empty state design when a host has applicable errata but no installable errata 2139545 - Registration error: PG::UniqueViolation: ERROR: duplicate key value violates unique constraint "katello_available_module_streams_name_stream_context" 2140628 - Preupgrade and upgrade jobs should not mention RHEL 7 2140807 - Show include all RPM without errata and the 3 other checkboxes for rpm and module stream filters outside table so they don't get hidden by empty state. 2141136 - Orphaned ACSs should be cleaned from smart proxies 2141187 - Searchbar disappears when trying to select a bookmark as user without bookmark permissions 2141455 - New host details - Move Details tab out of experimental labs 2141719 - While selecting "Enable debugging output" option, Satellite generates ahv virt-who confirguration with "internal_debug=true" which is not recognized by virt-who 2141810 - When working with CCV, include and exclude filters, eventually the number of packages in the CCV will not be as expected, causing problems to the customer 2142514 - Satellite-clone not working if ansible-core 2.13 is installed 2142555 - import puppet classes permission filter does not work 2143451 - Satellite upgrades should not require enabling the next versions Satellite repository, and should rely only on the Maintenance repository 2143497 - Can't perform incremental content exports in syncable format 2143515 - ERROR -- /parallel-executor-core: no manager for Dynflow::Director::Event for event: #
FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a5e10b188a 2023-03-14 00:16:44.047436 --------------------------------------------------------------------------------Name : retroarch Product : Fedora 38 Version : 1.15.0 Release : 4.fc38 URL : Summary : Cross-platform, sophisticated frontend for the libretro API. Description : libretro is an API that exposes generic audio/video/input callbacks. A frontend for libretro (such as RetroArch) handles video output, audio output, input and application lifecycle. A libretro core written in portable C or C++ can run seamlessly on many platforms with very little to no porting effort. While RetroArch is the reference frontend for libretro, several other projects have used the libretro interface to include support for emulators and/or game engines. libretro is completely open and free for anyone to use. To download and install more libretro cores please read included README.Fedora file: $ xdg-open /usr/share/doc/retroarch/README.fedora.md --------------------------------------------------------------------------------Update Information: FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226CVE-2023-1227 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 12 2023 Neal Gompa - 1.15.0-4 - Rebuild for ffmpeg 6.0 - fix build on big-endian (Dominik Mierzejewski) * Sat Mar 11 2023 Artem Polishchuk - 1.15.0-3 - chore: Update to 1.15.0 * Fri Jan 20 2023 Fedora Release Engineering - 1.14.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1944122 - notcurses-2.3.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=1944122 [ 2 ] Bug #2022640 - notcurses-2.4.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2022640 [ 3 ] Bug #2028587 - notcurses-3.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2028587 [ 4 ] Bug #2045133 - notcurses: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045133 [ 5 ] Bug #2053373 - notcurses-3.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2053373 [ 6 ] Bug #2172934 - CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2172934 [ 7 ] Bug #2173846 - ffmpeg-6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2173846 [ 8 ] Bug #2174875 - k3b-22.12.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2174875 [ 9 ] Bug #2176135 - mlt-7.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2176135 [ 10 ] Bug #2176519 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176519 [ 11 ] Bug #2176520 - CVE-2023-1213CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176520 [ 12 ] Bug #2177300 - retroarch-1.15.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177300 [ 13 ] Bug #2177550 - nv-codec-headers-12.0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a5e10b188a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could result in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202211-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Mozilla Thunderbird: Multiple Vulnerabilities Date: November 22, 2022 Bugs: #881407 ID: 202211-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could result in arbitrary code execution. Background ========= Mozilla Thunderbird is a popular open-source email client from the Mozilla project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-client/thunderbird < 102.5.0 > = 102.5.0 2 mail-client/thunderbird-bin < 102.5.0 > = 102.5.0 Description ========== Multiple vulnerabilities have been discovered in Mozilla Thunderbird. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Mozilla Thunderbird binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-client/thunderbird-bin-102.5.0" All Mozilla Thunderbird users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-client/thunderbird-102.5.0" References ========= [ 1 ]CVE-2022-45403 https://nvd.nist.gov/vuln/detail/CVE-2022-45403 [ 2 ] CVE-2022-45404 https://nvd.nist.gov/vuln/detail/CVE-2022-45404 [ 3 ] CVE-2022-45405 https://nvd.nist.gov/vuln/detail/CVE-2022-45405 [ 4 ] CVE-2022-45406 https://nvd.nist.gov/vuln/detail/CVE-2022-45406 [ 5 ] CVE-2022-45408 https://nvd.nist.gov/vuln/detail/CVE-2022-45408 [ 6 ] CVE-2022-45409 https://nvd.nist.gov/vuln/detail/CVE-2022-45409 [ 7 ] CVE-2022-45410 https://nvd.nist.gov/vuln/detail/CVE-2022-45410 [ 8 ] CVE-2022-45411 https://nvd.nist.gov/vuln/detail/CVE-2022-45411 [ 9 ] CVE-2022-45412 https://nvd.nist.gov/vuln/detail/CVE-2022-45412 [ 10 ] CVE-2022-45416 https://nvd.nist.gov/vuln/detail/CVE-2022-45416 [ 11 ] CVE-2022-45418 https://nvd.nist.gov/vuln/detail/CVE-2022-45418 [ 12 ] CVE-2022-45420 https://nvd.nist.gov/vuln/detail/CVE-2022-45420 [ 13 ] CVE-2022-45421 https://nvd.nist.gov/vuln/detail/CVE-2022-45421 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202211-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202102-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Mozilla Firefox: Multiple vulnerabilities Date: February 01, 2021 Bugs: #767334 ID: 202102-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code. Background ========= Mozilla Firefox is a popular open-source web browser from the Mozilla project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/firefox < 85.0 > = 78.7.0:0/esr78 > = 85.0 2 www-client/firefox-bin < 85.0 > = 78.7.0:0/esr78 > = 85.0 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in Mozilla Firefox. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Mozilla Firefox ESR users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-client/firefox-78.7.0" All Mozilla Firefox ESR binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/firefox-bin-78.7.0" All Mozilla Firefox users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/firefox-85.0" All Mozilla Firefox binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/firefox-bin-85.0" References ========= [ 1 ] CVE-2021-23953 https://nvd.nist.gov/vuln/detail/CVE-2021-23953 [ 2 ] CVE-2021-23954 https://nvd.nist.gov/vuln/detail/CVE-2021-23954 [ 3 ] CVE-2021-23955 https://nvd.nist.gov/vuln/detail/CVE-2021-23955 [ 4 ] CVE-2021-23956 https://nvd.nist.gov/vuln/detail/CVE-2021-23956 [ 5 ] CVE-2021-23958 https://nvd.nist.gov/vuln/detail/CVE-2021-23958 [ 6 ] CVE-2021-23960 https://nvd.nist.gov/vuln/detail/CVE-2021-23960 [ 7 ] CVE-2021-23961 https://nvd.nist.gov/vuln/detail/CVE-2021-23961 [ 8 ] CVE-2021-23962 https://nvd.nist.gov/vuln/detail/CVE-2021-23962 [ 9 ] CVE-2021-23963 https://nvd.nist.gov/vuln/detail/CVE-2021-23963 [ 10 ] CVE-2021-23964 https://nvd.nist.gov/vuln/detail/CVE-2021-23964 [ 11 ] CVE-2021-23965 https://nvd.nist.gov/vuln/detail/CVE-2021-23965 [ 12 ] CVE-2021-26976 https://nvd.nist.gov/vuln/detail/CVE-2021-26976 [ 13 ] Upstream advisory (MFSA-2021-03) https://www.mozilla.org/en-US/security/advisories/mfsa2021-03/ [ 14 ] Upstream advisory (MFSA-2021-04) https://www.mozilla.org/en-US/security/advisories/mfsa2021-04/ Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202102-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto
Multiple vulnerabilities have been found in libxml2, the worst of which could result in a Denial of Service condition.. Gentoo Linux Security Advisory GLSA 202010-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libxml2: Multiple vulnerabilities Date: October 20, 2020 Bugs: #710748 ID: 202010-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libxml2, the worst of which could result in a Denial of Service condition. Background ========= libxml2 is the XML (eXtended Markup Language) C parser and toolkit initially developed for the Gnome project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/libxml2 < 2.9.10 > = 2.9.10 Description ========== Multiple vulnerabilities have been discovered in libxml2. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All libxml2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libxml2-2.9.10" References ========= [ 1 ] CVE-2019-20388 https://nvd.nist.gov/vuln/detail/CVE-2019-20388 [ 2 ] CVE-2020-7595 https://nvd.nist.gov/vuln/detail/CVE-2020-7595 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202010-04 Concerns? ======== Security is a primary focus of Gentoo Linuxand ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Chromium-browser 78.0.3904.87 fixes security issues: Multiple flaws were found in the way Chromium 77.0.3865.120 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose . MGASA-2019-0320 - Updated chromium-browser-stable packages fix security vulnerabilities Publication date: 07 Nov 2019 URL: https://advisories.mageia.org/MGASA-2019-0320.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-13699, CVE-2019-13700, CVE-2019-13701, CVE-2019-13702, CVE-2019-13703, CVE-2019-13704, CVE-2019-13705, CVE-2019-13706, CVE-2019-13707, CVE-2019-13708, CVE-2019-13709, CVE-2019-13710, CVE-2019-13711, CVE-2019-13713, CVE-2019-13714, CVE-2019-13715, CVE-2019-13716, CVE-2019-13717, CVE-2019-13718, CVE-2019-13719, CVE-2019-13720, CVE-2019-13721 Chromium-browser 78.0.3904.87 fixes security issues: Multiple flaws were found in the way Chromium 77.0.3865.120 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information. (CVE-2019-13699, CVE-2019-13700, CVE-2019-13701, CVE-2019-13702, CVE-2019-13703, CVE-2019-13704, CVE-2019-13705, CVE-2019-13706, CVE-2019-13707, CVE-2019-13708, CVE-2019-13709, CVE-2019-13710, CVE-2019-13711, CVE-2019-13713, CVE-2019-13714, CVE-2019-13715, CVE-2019-13716, CVE-2019-13717, CVE-2019-13718, CVE-2019-13719, CVE-2019-13720, CVE-2019-13721) References: - https://bugs.mageia.org/show_bug.cgi?id=25655 - https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_22.html - https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html - https://www.cve.org/CVERecord?id=CVE-2019-13699 - https://www.cve.org/CVERecord?id=CVE-2019-13700 - https://www.cve.org/CVERecord?id=CVE-2019-13701 -https://www.cve.org/CVERecord?id=CVE-2019-13702 - https://www.cve.org/CVERecord?id=CVE-2019-13703 - https://www.cve.org/CVERecord?id=CVE-2019-13704 - https://www.cve.org/CVERecord?id=CVE-2019-13705 - https://www.cve.org/CVERecord?id=CVE-2019-13706 - https://www.cve.org/CVERecord?id=CVE-2019-13707 - https://www.cve.org/CVERecord?id=CVE-2019-13708 - https://www.cve.org/CVERecord?id=CVE-2019-13709 - https://www.cve.org/CVERecord?id=CVE-2019-13710 - https://www.cve.org/CVERecord?id=CVE-2019-13711 - https://www.cve.org/CVERecord?id=CVE-2019-13713 - https://www.cve.org/CVERecord?id=CVE-2019-13714 - https://www.cve.org/CVERecord?id=CVE-2019-13715 - https://www.cve.org/CVERecord?id=CVE-2019-13716 - https://www.cve.org/CVERecord?id=CVE-2019-13717 - https://www.cve.org/CVERecord?id=CVE-2019-13718 - https://www.cve.org/CVERecord?id=CVE-2019-13719 - https://www.cve.org/CVERecord?id=CVE-2019-13720 - https://www.cve.org/CVERecord?id=CVE-2019-13721 SRPMS: - 7/core/chromium-browser-stable-78.0.3904.87-1.mga7 . The latest update to Mageia's chromium-browser addresses numerous vulnerabilities, improving overall robustness and minimizing the chances of unauthorized code execution.. Mageia Chromium Browser Update, Security Flaw Fixes, Browser Security Issues. . Severity: Critical. LinuxSecurity.com Team
This is new version of putty.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-2eddaf40d0 2019-03-29 19:07:28.734295 --------------------------------------------------------------------------------Name : putty Product : Fedora 30 Version : 0.71 Release : 1.fc30 URL : https://www.chiark.greenend.org.uk/~sgtatham/putty/ Summary : SSH, Telnet and Rlogin client Description : Putty is a SSH, Telnet & Rlogin client - this time for Linux. --------------------------------------------------------------------------------Update Information: This is new version of putty. --------------------------------------------------------------------------------References: [ 1 ] Bug #1690382 - CVE-2019-9894 CVE-2019-9895 CVE-2019-9898 CVE-2019-9897 putty: multiple vulnerabilities https://bugzilla.redhat.com/show_bug.cgi?id=1690382 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-2eddaf40d0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The package powerdns-recursor before version 4.1.9-1 is vulnerable to multiple issues including insufficient validation and access restriction bypass. . Arch Linux Security Advisory ASA-201901-13 ========================================= Severity: Medium Date : 2019-01-24 CVE-ID : CVE-2019-3806 CVE-2019-3807 Package : powerdns-recursor Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-856 Summary ====== The package powerdns-recursor before version 4.1.9-1 is vulnerable to multiple issues including insufficient validation and access restriction bypass. Resolution ========= Upgrade to 4.1.9-1. # pacman -Syu "powerdns-recursor> =4.1.9-1" The problems have been fixed upstream in version 4.1.9. Workaround ========= None. Description ========== - CVE-2019-3806 (access restriction bypass) An issue has been found in PowerDNS Recursor before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua. - CVE-2019-3807 (insufficient validation) An issue has been found in PowerDNS Recursor before 4.1.9 where records in the answer section of responses received from authoritative serverswith the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation. Impact ===== A remote attacker can bypass access restrictions by doing a TCP query or bypass DNSSEC validation for records where the AA flag was not set. References ========= https://blog.powerdns.com/2019/01/21/powerdns-recursor-4-1-9-released https://security.archlinux.org/CVE-2019-3806 https://security.archlinux.org/CVE-2019-3807 . Arch Linux Advisory addressing possible vulnerabilities within powerdns-recursor, emphasizing concerns regarding access controls and integrity checks.. Security Advisory, Arch Linux, PowerDNS, Access Restriction Issues, Validation Flaws. . Severity: Medium. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.