The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4935 http://linux.oracle.com/errata/ELSA-2024-4935.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: freeradius-3.0.21-40.el9_4.x86_64.rpm freeradius-devel-3.0.21-40.el9_4.x86_64.rpm freeradius-doc-3.0.21-40.el9_4.x86_64.rpm freeradius-krb5-3.0.21-40.el9_4.x86_64.rpm freeradius-ldap-3.0.21-40.el9_4.x86_64.rpm freeradius-utils-3.0.21-40.el9_4.x86_64.rpm python3-freeradius-3.0.21-40.el9_4.x86_64.rpm freeradius-mysql-3.0.21-40.el9_4.x86_64.rpm freeradius-perl-3.0.21-40.el9_4.x86_64.rpm freeradius-postgresql-3.0.21-40.el9_4.x86_64.rpm freeradius-rest-3.0.21-40.el9_4.x86_64.rpm freeradius-sqlite-3.0.21-40.el9_4.x86_64.rpm freeradius-unixODBC-3.0.21-40.el9_4.x86_64.rpm aarch64: freeradius-3.0.21-40.el9_4.aarch64.rpm freeradius-devel-3.0.21-40.el9_4.aarch64.rpm freeradius-doc-3.0.21-40.el9_4.aarch64.rpm freeradius-krb5-3.0.21-40.el9_4.aarch64.rpm freeradius-ldap-3.0.21-40.el9_4.aarch64.rpm freeradius-utils-3.0.21-40.el9_4.aarch64.rpm python3-freeradius-3.0.21-40.el9_4.aarch64.rpm freeradius-mysql-3.0.21-40.el9_4.aarch64.rpm freeradius-perl-3.0.21-40.el9_4.aarch64.rpm freeradius-postgresql-3.0.21-40.el9_4.aarch64.rpm freeradius-rest-3.0.21-40.el9_4.aarch64.rpm freeradius-sqlite-3.0.21-40.el9_4.aarch64.rpm freeradius-unixODBC-3.0.21-40.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//freeradius-3.0.21-40.el9_4.src.rpm Related CVEs: CVE-2024-3596 Description of changes: [3.0.21-40] - Backport fixes for BlastRADIUS CVE Resolves: RHEL-46566 _______________________________________________ El-errata mailing list
Moderate: gvisor-tap-vsock security and bug fix update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:3830", "synopsis": "Moderate: gvisor-tap-vsock security and bug fix update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for gvisor-tap-vsock.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "A replacement for libslirp and VPNKit, written in pure Go. It is based on the network stack of gVisor and is used to provide networking for podman-machine virtual machines. Compared to libslirp, gvisor-tap-vsock brings a configurable DNS server and dynamic port forwarding.\n\nSecurity Fix(es):\n\n* golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2268017", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2268017", "description": ""}], "cves": [{"name": "CVE-2023-45290", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-45290", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-06-14T14:00:40.182624Z", "rpms": {"Rocky Linux 9": {"nvras": ["gvisor-tap-vsock-6:0.7.3-3.el9_4.aarch64.rpm", "gvisor-tap-vsock-6:0.7.3-3.el9_4.ppc64le.rpm", "gvisor-tap-vsock-6:0.7.3-3.el9_4.s390x.rpm", "gvisor-tap-vsock-6:0.7.3-3.el9_4.src.rpm", "gvisor-tap-vsock-6:0.7.3-3.el9_4.x86_64.rpm", "gvisor-tap-vsock-debuginfo-6:0.7.3-3.el9_4.aarch64.rpm", "gvisor-tap-vsock-debuginfo-6:0.7.3-3.el9_4.ppc64le.rpm", "gvisor-tap-vsock-debuginfo-6:0.7.3-3.el9_4.s390x.rpm", "gvisor-tap-vsock-debuginfo-6:0.7.3-3.el9_4.x86_64.rpm", "gvisor-tap-vsock-debugsource-6:0.7.3-3.el9_4.aarch64.rpm", "gvisor-tap-vsock-debugsource-6:0.7.3-3.el9_4.ppc64le.rpm", "gvisor-tap-vsock-debugsource-6:0.7.3-3.el9_4.s390x.rpm","gvisor-tap-vsock-debugsource-6:0.7.3-3.el9_4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. gvisor-tap-vsock undergoes a significant security and stability patch for Ubuntu 22.04 to improve its networking performance.. gvisor-tap-vsock update, Rocky Linux security, gvisor-tap-vsock fix, networking issues, moderate severity update. . LinuxSecurity.com Team
SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002. (CVE-2023-23589) References: . MGASA-2023-0017 - Updated tor packages fix security vulnerability Publication date: 24 Jan 2023 URL: https://advisories.mageia.org/MGASA-2023-0017.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-23589 SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002. (CVE-2023-23589) References: - https://bugs.mageia.org/show_bug.cgi?id=31414 - https://forum.torproject.org/t/stable-release-0-4-5-16-and-0-4-7-13/6216 - https://lists.debian.org/debian-security-announce/2023/msg00009.html - https://www.cve.org/CVERecord?id=CVE-2023-23589 SRPMS: - 8/core/tor-0.4.5.16-1.mga8 . Enhanced security features in Mageia 8 system are provided by updated Tor packages, fixing a logical flaw in the SafeSocks setting.. Tor Security Update,Mageia 8,SOCKS4 Vulnerability,Secure Networking. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-9270 https://linux.oracle.com/errata/ELSA-2022-9270.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-4.14.35-2047.511.5.8.el7uek.x86_64.rpm kernel-uek-debug-4.14.35-2047.511.5.8.el7uek.x86_64.rpm kernel-uek-debug-devel-4.14.35-2047.511.5.8.el7uek.x86_64.rpm kernel-uek-devel-4.14.35-2047.511.5.8.el7uek.x86_64.rpm kernel-uek-tools-4.14.35-2047.511.5.8.el7uek.x86_64.rpm kernel-uek-doc-4.14.35-2047.511.5.8.el7uek.noarch.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/kernel-uek-4.14.35-2047.511.5.8.el7uek.src.rpm Related CVEs: CVE-2022-1016 Description of changes: [4.14.35-2047.511.5.8.el7uek] - netfilter: nf_tables: initialize registers in nft_do_chain() (Pablo Neira Ayuso) [Orabug: 34048826] {CVE-2022-1016}" _______________________________________________ El-errata mailing list
Update to 85.0.4183.121. Why? Because security, that's why. It fixes these CVEs: CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 It also has a fix for an issue where networking... uh... didn't. ---- Update Chromium to 85.0.4183.102. Fix issue where unpackaged components prevented hardware accelerated rendering from. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-aea86f913e 2020-10-03 01:53:36.346935 --------------------------------------------------------------------------------Name : chromium Product : Fedora 31 Version : 85.0.4183.121 Release : 1.fc31 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Update to 85.0.4183.121. Why? Because security, that's why. It fixes these CVEs: CVE-2020-15960 CVE-2020-15961 CVE-2020-15962 CVE-2020-15963 CVE-2020-15964 CVE-2020-15965 CVE-2020-15966 It also has a fix for an issue where networking... uh... didn't. ---- Update Chromium to 85.0.4183.102. Fix issue where unpackaged components prevented hardware accelerated rendering from working. Also fixes the following security issues: CVE-2020-6573 CVE-2020-6574 CVE-2020-6575 CVE-2020-6576 CVE-2020-15959 --------------------------------------------------------------------------------ChangeLog: * Mon Sep 21 2020 Tom Callaway - 85.0.4183.121-1 - update to 85.0.4183.121 - apply upstream fix for networking issue with CookieMonster * Tue Sep 8 2020 Tom Callaway - 85.0.4183.102-1 - update to 85.0.4183.102 - install ANGLE so files (libEGL.so, libGLESv2.so) --------------------------------------------------------------------------------References: [ 1 ] Bug #1877090 - CVE-2020-6573 chromium-browser: Use after free invideo https://bugzilla.redhat.com/show_bug.cgi?id=1877090 [ 2 ] Bug #1877091 - CVE-2020-6574 chromium-browser: Insufficient policy enforcement in installer https://bugzilla.redhat.com/show_bug.cgi?id=1877091 [ 3 ] Bug #1877093 - CVE-2020-6575 chromium-browser: Race in Mojo https://bugzilla.redhat.com/show_bug.cgi?id=1877093 [ 4 ] Bug #1877094 - CVE-2020-6576 chromium-browser: Use after free in offscreen canvas https://bugzilla.redhat.com/show_bug.cgi?id=1877094 [ 5 ] Bug #1877095 - CVE-2020-15959 chromium-browser: Insufficient policy enforcement in networking https://bugzilla.redhat.com/show_bug.cgi?id=1877095 [ 6 ] Bug #1881593 - CVE-2020-15960 chromium-browser: Out of bounds read in storage https://bugzilla.redhat.com/show_bug.cgi?id=1881593 [ 7 ] Bug #1881595 - CVE-2020-15961 chromium-browser: Insufficient policy enforcement in extensions https://bugzilla.redhat.com/show_bug.cgi?id=1881595 [ 8 ] Bug #1881596 - CVE-2020-15962 chromium-browser: Insufficient policy enforcement in serial https://bugzilla.redhat.com/show_bug.cgi?id=1881596 [ 9 ] Bug #1881597 - CVE-2020-15963 chromium-browser: Insufficient policy enforcement in extensions https://bugzilla.redhat.com/show_bug.cgi?id=1881597 [ 10 ] Bug #1881598 - CVE-2020-15965 chromium-browser: Out of bounds write in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1881598 [ 11 ] Bug #1881599 - CVE-2020-15966 chromium-browser: Insufficient policy enforcement in extensions https://bugzilla.redhat.com/show_bug.cgi?id=1881599 [ 12 ] Bug #1881600 - CVE-2020-15964 chromium-browser: Insufficient data validation in media https://bugzilla.redhat.com/show_bug.cgi?id=1881600 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-aea86f913e' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: java-1.8.0-openjdk security update Advisory ID: RHSA-2019:3134-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:3134 Issue date: 2019-10-17 CVE Names: CVE-2019-2945 CVE-2019-2949 CVE-2019-2962 CVE-2019-2964 CVE-2019-2973 CVE-2019-2975 CVE-2019-2978 CVE-2019-2981 CVE-2019-2983 CVE-2019-2987 CVE-2019-2988 CVE-2019-2989 CVE-2019-2992 CVE-2019-2999 ==================================================================== 1. Summary: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix(es): * OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302) (CVE-2019-2949) * OpenJDK: Unexpected exception thrown during regular expression processing in Nashorn (Scripting, 8223518) (CVE-2019-2975) * OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) (CVE-2019-2978) * OpenJDK: Incorrect handling of HTTP proxy responses inHttpURLConnection (Networking, 8225298) (CVE-2019-2989) * OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573) (CVE-2019-2945) * OpenJDK: NULL pointer dereference in DrawGlyphList (2D, 8222690) (CVE-2019-2962) * OpenJDK: Unexpected exception thrown by Pattern processing crafted regular expression (Concurrency, 8222684) (CVE-2019-2964) * OpenJDK: Unexpected exception thrown by XPathParser processing crafted XPath expression (JAXP, 8223505) (CVE-2019-2973) * OpenJDK: Unexpected exception thrown by XPath processing crafted XPath expression (JAXP, 8224532) (CVE-2019-2981) * OpenJDK: Unexpected exception thrown during Font object deserialization (Serialization, 8224915) (CVE-2019-2983) * OpenJDK: Missing glyph bitmap image dimension check in FreetypeFontScaler (2D, 8225286) (CVE-2019-2987) * OpenJDK: Integer overflow in bounds check in SunGraphics2D (2D, 8225292) (CVE-2019-2988) * OpenJDK: Excessive memory allocation in CMap when reading TrueType font (2D, 8225597) (CVE-2019-2992) * OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765) (CVE-2019-2999) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of OpenJDK Java must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1760963 - CVE-2019-2964 OpenJDK: Unexpected exception thrown by Pattern processing crafted regular expression (Concurrency, 8222684) 1760969 - CVE-2019-2975 OpenJDK: Unexpected exception thrown during regular expression processing in Nashorn (Scripting, 8223518) 1760978 - CVE-2019-2973 OpenJDK: Unexpected exception thrown by XPathParser processing crafted XPath expression (JAXP, 8223505) 1760980 - CVE-2019-2981 OpenJDK:Unexpected exception thrown by XPath processing crafted XPath expression (JAXP, 8224532) 1760992 - CVE-2019-2999 OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765) 1760999 - CVE-2019-2988 OpenJDK: Integer overflow in bounds check in SunGraphics2D (2D, 8225292) 1761006 - CVE-2019-2978 OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) 1761146 - CVE-2019-2992 OpenJDK: Excessive memory allocation in CMap when reading TrueType font (2D, 8225597) 1761149 - CVE-2019-2987 OpenJDK: Missing glyph bitmap image dimension check in FreetypeFontScaler (2D, 8225286) 1761262 - CVE-2019-2983 OpenJDK: Unexpected exception thrown during Font object deserialization (Serialization, 8224915) 1761266 - CVE-2019-2962 OpenJDK: NULL pointer dereference in DrawGlyphList (2D, 8222690) 1761594 - CVE-2019-2949 OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302) 1761596 - CVE-2019-2945 OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573) 1761601 - CVE-2019-2989 OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298) 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: java-1.8.0-openjdk-1.8.0.232.b09-0.el8_0.src.rpm aarch64: java-1.8.0-openjdk-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-accessibility-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-debugsource-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-demo-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-demo-debuginfo-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-demo-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-devel-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-devel-debuginfo-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-devel-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-headless-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-headless-debuginfo-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-headless-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.aarch64.rpm java-1.8.0-openjdk-src-1.8.0.232.b09-0.el8_0.aarch64.rpm noarch: java-1.8.0-openjdk-javadoc-1.8.0.232.b09-0.el8_0.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.232.b09-0.el8_0.noarch.rpm ppc64le: java-1.8.0-openjdk-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-accessibility-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-debuginfo-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-debugsource-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-demo-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-demo-debuginfo-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-demo-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-devel-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-devel-debuginfo-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-devel-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-headless-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-headless-debuginfo-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-headless-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.ppc64le.rpm java-1.8.0-openjdk-src-1.8.0.232.b09-0.el8_0.ppc64le.rpm s390x: java-1.8.0-openjdk-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-accessibility-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-debuginfo-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-debugsource-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-demo-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-demo-debuginfo-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-devel-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-devel-debuginfo-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-headless-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-headless-debuginfo-1.8.0.232.b09-0.el8_0.s390x.rpm java-1.8.0-openjdk-src-1.8.0.232.b09-0.el8_0.s390x.rpm x86_64: java-1.8.0-openjdk-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-debugsource-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-demo-debuginfo-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-demo-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-devel-debuginfo-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-devel-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-headless-debuginfo-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-headless-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-slowdebug-debuginfo-1.8.0.232.b09-0.el8_0.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.232.b09-0.el8_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2019-2945 https://access.redhat.com/security/cve/CVE-2019-2949 https://access.redhat.com/security/cve/CVE-2019-2962 https://access.redhat.com/security/cve/CVE-2019-2964 https://access.redhat.com/security/cve/CVE-2019-2973 https://access.redhat.com/security/cve/CVE-2019-2975 https://access.redhat.com/security/cve/CVE-2019-2978 https://access.redhat.com/security/cve/CVE-2019-2981 https://access.redhat.com/security/cve/CVE-2019-2983 https://access.redhat.com/security/cve/CVE-2019-2987 https://access.redhat.com/security/cve/CVE-2019-2988 https://access.redhat.com/security/cve/CVE-2019-2989 https://access.redhat.com/security/cve/CVE-2019-2992 https://access.redhat.com/security/cve/CVE-2019-2999 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXag7Q9zjgjWX9erEAQiONA//Y1kSORqSNyCRxNhf9HwDd1YHU4Kn4lwg f3gkfaS7qsbI9FvnGFSVQl5qlctD4c25Ji6sZCtGHSxn6EUhKSMfDOUaVl17RJMd FnpaJLkWS+MX5jXsau/P4MGVkKj95moINMrXDlRo2/oTRp8G3gE1es7KJi18Hgmk 8rC/3HVLwKRbUeGUEOQp2b/9feAPhD2afelkuMbc3RvYjrzh6PyqeJKH8QhXB5PO CNO2Q3LQqboDqAIBrgNwf+xcaFaZgNlysbeFCybcykqQvOWCKR3f3niByy4uyWfe PjsswTsXNeAbikk6feLBufm1n6Rr5sR6Ei55rGqTXOjcDYFaxlhKWlJO9AFF/fZ5 X+9vbqz/3cGkssdHSBzzGGaATO4ELvZsowh5AXQ3Xs0rJ0rTVdtcHdkvHzsdpCd0 JpAHHI42dQGZD+rHsfYCCDWcGZmxhVgQwukyKr8FPbSbixOOVBaHQwOl9uid3Jz+ saGgQZEYy95qtlJNbFxMRgH7UO/9upEAH0qp3tjbz+2DTjE/dxpSSh2SyhQWM3Am u+/dRXulerJEBMPtFDLGtbrhnCFrL1GmdR+jEmCDNYEFekycbAXSPJBaQJXnobQd vsKV0S8DT4RPFkLinkaDCXymeebNkmo05Ubu3b02GSJEE2WUYWzZfxMRZG95bhvX 59zcazFtZ5M=VFnx -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.