Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
100

SUSE: 2022:1806-1 Important: OpenJDK Development and Ncurses Update

The container bci/openjdk-devel was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:1806-1 Container Tags : bci/openjdk-devel:11 , bci/openjdk-devel:11-34.3 , bci/openjdk-devel:latest Container Release : 34.3 Severity : important Type : security References : 1198627 1201684 1201692 1201694 CVE-2022-21540 CVE-2022-21541 CVE-2022-29458 CVE-2022-34169 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2707-1 Released: Tue Aug 9 10:18:18 2022 Summary: Security update for java-11-openjdk Type: security Severity: important References: 1201684,1201692,1201694,CVE-2022-21540,CVE-2022-21541,CVE-2022-34169 This update for java-11-openjdk fixes the following issues: Update to upstream tag jdk-11.0.16+8 (July 2022 CPU) - CVE-2022-21540: Improve class compilation (bsc#1201694) - CVE-2022-21541: Enhance MethodHandle invocations (bsc#1201692) - CVE-2022-34169: Improve Xalan supports (bsc#1201684) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2717-1 Released: Tue Aug 9 12:54:16 2022 Summary: Security update for ncurses Type: security Severity: moderate References: 1198627,CVE-2022-29458 This update for ncurses fixes the following issues: - CVE-2022-29458: Fixed segfaulting out-of-bounds read in convert_strings in tinfo/read_entry.c (bsc#1198627). The following package changes have been done: - libncurses6-6.1-150000.5.12.1 updated - terminfo-base-6.1-150000.5.12.1 updated - ncurses-utils-6.1-150000.5.12.1 updated - java-11-openjdk-headless-11.0.16.0-150000.3.83.1 updated -java-11-openjdk-11.0.16.0-150000.3.83.1 updated - java-11-openjdk-devel-11.0.16.0-150000.3.83.1 updated - container:bci-openjdk-11-15.4-30.1 updated . Critical patches issued for bci/openjdk-devel and ncurses in the SUSE Container environment. Advisory Identifier: SUSE-CU-2022:1806-1.. Container Security, Java Updates, SUSE Security Advisories. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 10, 2022 Important SuSE
98

RedHat 6: RHSA-2020-4348-01 Moderate: OpenJDK Security Update

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: java-1.8.0-openjdk security update Advisory ID: RHSA-2020:4348-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4348 Issue date: 2020-10-26 CVE Names: CVE-2020-14779 CVE-2020-14781 CVE-2020-14782 CVE-2020-14792 CVE-2020-14796 CVE-2020-14797 CVE-2020-14803 ==================================================================== 1. Summary: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, noarch, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, noarch, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, noarch, x86_64 3. Description: The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix(es): * OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) (CVE-2020-14781) *OpenJDK: Certificate blacklist bypass via alternate certificate encodings (Libraries, 8237995) (CVE-2020-14782) * OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114) (CVE-2020-14792) * OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) (CVE-2020-14797) * OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) (CVE-2020-14803) * OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) (CVE-2020-14779) * OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) (CVE-2020-14796) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of OpenJDK Java must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1889271 - CVE-2020-14779 OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) 1889274 - CVE-2020-14781 OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) 1889280 - CVE-2020-14792 OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114) 1889290 - CVE-2020-14782 OpenJDK: Certificate blacklist bypass via alternate certificate encodings (Libraries, 8237995) 1889697 - CVE-2020-14796 OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) 1889717 - CVE-2020-14797 OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) 1889895 - CVE-2020-14803 OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) 6. Package List: Red Hat Enterprise Linux Desktop (v.6): Source: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.src.rpm i386: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-headless-1.8.0.272.b10-0.el6_10.i686.rpm x86_64: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.272.b10-0.el6_10.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): i386: java-1.8.0-openjdk-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-demo-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-demo-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-devel-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-devel-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-headless-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-src-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-src-debug-1.8.0.272.b10-0.el6_10.i686.rpm noarch: java-1.8.0-openjdk-javadoc-1.8.0.272.b10-0.el6_10.noarch.rpm java-1.8.0-openjdk-javadoc-debug-1.8.0.272.b10-0.el6_10.noarch.rpm x86_64: java-1.8.0-openjdk-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-demo-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-devel-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-src-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm Red Hat Enterprise Linux HPC Node (v.6): Source: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.src.rpm x86_64: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.272.b10-0.el6_10.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): noarch: java-1.8.0-openjdk-javadoc-1.8.0.272.b10-0.el6_10.noarch.rpm java-1.8.0-openjdk-javadoc-debug-1.8.0.272.b10-0.el6_10.noarch.rpm x86_64: java-1.8.0-openjdk-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-demo-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-devel-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-src-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.src.rpm i386: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-devel-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-headless-1.8.0.272.b10-0.el6_10.i686.rpm x86_64: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.272.b10-0.el6_10.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): i386: java-1.8.0-openjdk-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-demo-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-demo-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-devel-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-headless-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-src-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-src-debug-1.8.0.272.b10-0.el6_10.i686.rpm noarch: java-1.8.0-openjdk-javadoc-1.8.0.272.b10-0.el6_10.noarch.rpm java-1.8.0-openjdk-javadoc-debug-1.8.0.272.b10-0.el6_10.noarch.rpm x86_64: java-1.8.0-openjdk-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-demo-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-devel-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-src-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.src.rpm i386: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-devel-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-headless-1.8.0.272.b10-0.el6_10.i686.rpm x86_64: java-1.8.0-openjdk-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.272.b10-0.el6_10.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.6): i386: java-1.8.0-openjdk-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-demo-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-demo-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-devel-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-headless-debug-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-src-1.8.0.272.b10-0.el6_10.i686.rpm java-1.8.0-openjdk-src-debug-1.8.0.272.b10-0.el6_10.i686.rpm noarch: java-1.8.0-openjdk-javadoc-1.8.0.272.b10-0.el6_10.noarch.rpm java-1.8.0-openjdk-javadoc-debug-1.8.0.272.b10-0.el6_10.noarch.rpm x86_64: java-1.8.0-openjdk-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-demo-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-devel-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.272.b10-0.el6_10.x86_64.rpm java-1.8.0-openjdk-src-debug-1.8.0.272.b10-0.el6_10.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-14779 https://access.redhat.com/security/cve/CVE-2020-14781 https://access.redhat.com/security/cve/CVE-2020-14782 https://access.redhat.com/security/cve/CVE-2020-14792 https://access.redhat.com/security/cve/CVE-2020-14796 https://access.redhat.com/security/cve/CVE-2020-14797 https://access.redhat.com/security/cve/CVE-2020-14803 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX5drR9zjgjWX9erEAQi36BAAnLl0VO89OoR6p8ONebZaFGRjlO8t5i4m CorwLJD6D1lU6xfkqu7NpqP62fwNfEWnDw4Q42xZvfCsbnTfoQs0I+tcz4LohXFI qd5soEilgcHzRHkxoL1XY9Dut/Mo4KUGHLsEaemE/YzipBgDy/Wh9Y2mOnkD3NHZ fcovPp73+qVTldYSN7euzBkQOHf6/PCuznQ3dQdVr6SqdJ6yqQ8GrwK/OcPiGJJr ybrpmu9DvVD5D/E52UF7Q6vMzDDo7wOQGDmCEtJwKeti/5RM2SU02cSN225OO1mm XPiwngD3cb2k0GpkkyqEal9jwLAqDH7t7fOEyP7kqk5S1fCNPe4bzGG5jrCGKUvi fXxY1GixzHJgL1Q10WNaonsRSZcpBHEpL1pcAYV/jXCcgU7FZIIeOg+Tu25S6TaG aWBbzw9Q6VRT8uvYs/rXyj6BWSCLRdi0y0CN9miK62WYe2+h3DCXh0G5eIKMzhc0 jdkf8IHMORBElIXk0cJds3SABOK4G+RSxdu0rW87t/7uNoYuJKJLZAHqmWeWm+6O RU7SBWM+hOV1VlsTHTF62+raaCaJd8jZjB9r+c6JjL1rUpl4pa50lhri1+t5S47l QW/IjN7BvbWB0DK6n0n0y1BtpIktIPy/l/m/b9oM7f7xeEskCUd3v65PIABQoBwQ ZZCNds8zcTw=yMBf -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ====================================================. update, java-1, 0-openjdk, enterprise, linux, product. . LinuxSecurity.com Team

Calendar%202 Oct 26, 2020 Red Hat
98

RedHat: RHSA-2021-4456 Important: OpenJDK-12 Security Enhancement

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: java-11-openjdk security update Advisory ID: RHSA-2020:4307-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4307 Issue date: 2020-10-22 CVE Names: CVE-2020-14779 CVE-2020-14781 CVE-2020-14782 CVE-2020-14792 CVE-2020-14796 CVE-2020-14797 CVE-2020-14803 ==================================================================== 1. Summary: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. Security Fix(es): * OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) (CVE-2020-14781) * OpenJDK: Certificate blacklistbypass via alternate certificate encodings (Libraries, 8237995) (CVE-2020-14782) * OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114) (CVE-2020-14792) * OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) (CVE-2020-14797) * OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) (CVE-2020-14803) * OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) (CVE-2020-14779) * OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) (CVE-2020-14796) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of OpenJDK Java must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1889271 - CVE-2020-14779 OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) 1889274 - CVE-2020-14781 OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) 1889280 - CVE-2020-14792 OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114) 1889290 - CVE-2020-14782 OpenJDK: Certificate blacklist bypass via alternate certificate encodings (Libraries, 8237995) 1889697 - CVE-2020-14796 OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) 1889717 - CVE-2020-14797 OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) 1889895 - CVE-2020-14803 OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) 6. Package List: Red Hat Enterprise Linux Client (v.7): Source: java-11-openjdk-11.0.9.11-0.el7_9.src.rpm x86_64: java-11-openjdk-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: java-11-openjdk-11.0.9.11-0.el7_9.src.rpm x86_64: java-11-openjdk-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): x86_64: java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: java-11-openjdk-11.0.9.11-0.el7_9.src.rpm ppc64: java-11-openjdk-11.0.9.11-0.el7_9.ppc64.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.ppc64.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.ppc64.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.ppc64.rpm ppc64le: java-11-openjdk-11.0.9.11-0.el7_9.ppc64le.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.ppc64le.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.ppc64le.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.ppc64le.rpm s390x: java-11-openjdk-11.0.9.11-0.el7_9.s390x.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.s390x.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.s390x.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.s390x.rpm x86_64: java-11-openjdk-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.ppc64.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.ppc64.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.ppc64.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.ppc64.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.ppc64.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.ppc64.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.ppc64.rpm ppc64le: java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.ppc64le.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.ppc64le.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.ppc64le.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.ppc64le.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.ppc64le.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.ppc64le.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.ppc64le.rpm s390x: java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.s390x.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.s390x.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.s390x.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.s390x.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.s390x.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.s390x.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.s390x.rpm x86_64: java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v.7): Source: java-11-openjdk-11.0.9.11-0.el7_9.src.rpm x86_64: java-11-openjdk-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-devel-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-headless-11.0.9.11-0.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-debuginfo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-demo-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-javadoc-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-javadoc-zip-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-jmods-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-src-11.0.9.11-0.el7_9.x86_64.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.i686.rpm java-11-openjdk-static-libs-11.0.9.11-0.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-14779 https://access.redhat.com/security/cve/CVE-2020-14781 https://access.redhat.com/security/cve/CVE-2020-14782 https://access.redhat.com/security/cve/CVE-2020-14792 https://access.redhat.com/security/cve/CVE-2020-14796 https://access.redhat.com/security/cve/CVE-2020-14797 https://access.redhat.com/security/cve/CVE-2020-14803 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat,Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX5Gtg9zjgjWX9erEAQgP8RAAo4grN14ntCrhRdi2seeNfBm5SGFhYCBr HEfjx2s5j6V5empn/ueeyPGgUf4j3xLReTyx3mOaV2q9JLWvFz+fqz8PHR2XD7SA ML17aXI7+vT/XT5gW1ld0UfXtMioTPuI/Tjh/6a/zyadCquliOoNCaADpPDyAvOd NjPh9s/9i3xBhCyxel5RB7O7WqcHx9CYltPPzZKTbeXDpW30KmzKrM75z72E+74G FVEAjpRZAyucf+G5iN/OH0c+Vm+LwqOTmLUUV/ScYuNDpoNd0nBgK/Mv94lPnPCu K87oYHXyF4e6oC45bZhOdnTevA4wXHojrtp+uCXUjwRZ6Qh+XjU+1l9xsRLUdDER 7q5pTcNuzu9eCYtO/Qb9uO1VgYumer8g39RebJ33f7hu2A7BEPZMrjKjMex1ZCxC mgRhVNn+T8lr7xCpaePD9bN9lZQmEwmXE/70XPY7MPda3YDlABrgEtfVEceOL9DO I9sfNQTx3FT0pEbFUve+JPJUkXDmOZ+HQQRz9zcfGyjMK8ZXDtRSJXBNlPho4FkV 2YHArsMy3p/wjnxDzCCqWvmdrsdznverSeIWkApDMqGDzD3/wy5OMg20/vdH1Y3y V4P4x+sspYhtA5bjM/UZVYwRVALZNXE8Yj2qwKCPuJXQgs4zNc75XGoZ6s+jeMhR RJ7UuAe/GJs=9RLV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ====================================================. update, java-11-openjdk, enterprise, linux, product, secur. . LinuxSecurity.com Team

Calendar%202 Oct 22, 2020 Red Hat
89

Fedora 30: FEDORA-2019-a5ec38072a update for java-1.8.0-openjdk

8u222 update. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-a5ec38072a 2019-09-25 01:06:52.996157 --------------------------------------------------------------------------------Name : java-1.8.0-openjdk-aarch32 Product : Fedora 30 Version : 1.8.0.222.b10 Release : 1.fc30 URL : https://openjdk.org/ Summary : OpenJDK Runtime Environment 8 in a preview of the OpenJDK AArch32 project Description : A preview release of the upstream OpenJDK AArch32 porting project. The OpenJDK runtime environment. --------------------------------------------------------------------------------Update Information: 8u222 update --------------------------------------------------------------------------------ChangeLog: * Wed Sep 11 2019 Alex Kashchenko - 1:1.8.0.222.b10-1 - update sources to 8u221 - sync with mainline package * Thu Jul 25 2019 Fedora Release Engineering - 1:1.8.0.212.190430-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Mon May 6 2019 Alex Kashchenko - 1:1.8.0.212-1.190430 - update sources to 8u211 - sync with mainline package --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-a5ec38072a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora update notification for java-1.8.0-openjdk includes critical updates and details for installation.. Fedora Updates, OpenJDK AArch32, Java Runtime Environment. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 24, 2019 Critical Fedora
100

SUSE: 2013:1238-1 Important: 26 java-1_6_0-openjdk Security Issues

An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available.. SUSE Security Update: Security update for java-1_6_0-openjdk ______________________________________________________________________________ Announcement ID: SUSE-SU-2013:1238-1 Rating: important References: #829708 Cross-References: CVE-2013-1500 CVE-2013-1571 CVE-2013-2407 CVE-2013-2412 CVE-2013-2443 CVE-2013-2444 CVE-2013-2445 CVE-2013-2446 CVE-2013-2447 CVE-2013-2448 CVE-2013-2450 CVE-2013-2451 CVE-2013-2452 CVE-2013-2453 CVE-2013-2455 CVE-2013-2456 CVE-2013-2457 CVE-2013-2459 CVE-2013-2461 CVE-2013-2463 CVE-2013-2465 CVE-2013-2469 CVE-2013-2470 CVE-2013-2471 CVE-2013-2472 CVE-2013-2473 Affected Products: SUSE Linux Enterprise Desktop 11 SP2 ______________________________________________________________________________ An update that fixes 26 vulnerabilities is now available. Description: java-1_6_0-openjdk has been updated to Icedtea6-1.12.6 version. Security fixes: * S6741606, CVE-2013-2407: Integrate Apache Santuario * S7158805, CVE-2013-2445: Better rewriting of nested subroutine calls * S7170730, CVE-2013-2451: Improve Windows network stack support. * S8000638, CVE-2013-2450: Improve deserialization * S8000642, CVE-2013-2446: Better handling of objects for transportation * S8001032: Restrict object access * S8001033, CVE-2013-2452: Refactor network address handling in virtual machine identifiers * S8001034, CVE-2013-1500: Memory management improvements * S8001038, CVE-2013-2444: Resourcefully handle resources * S8001043: Clarify definition restrictions * S8001309: Better handling of annotation interfaces * S8001318, CVE-2013-2447: Socket.getLocalAddressnot consistent with InetAddress.getLocalHost * S8001330, CVE-2013-2443: Improve on checking order * S8003703, CVE-2013-2412: Update RMI connection dialog box * S8004584: Augment applet contextualization * S8005007: Better glyph processing * S8006328, CVE-2013-2448: Improve robustness of sound classes * S8006611: Improve scripting * S8007467: Improve robustness of JMX internal APIs * S8007471: Improve MBean notifications * S8007812, CVE-2013-2455: (reflect) Class.getEnclosingMethod problematic for some classes * S8008120, CVE-2013-2457: Improve JMX class checking * S8008124, CVE-2013-2453: Better compliance testing * S8008128: Better API coherence for JMX * S8008132, CVE-2013-2456: Better serialization support * S8008585: Better JMX data handling * S8008593: Better URLClassLoader resource management * S8008603: Improve provision of JMX providers Security Issue references: * CVE-2013-2407 * CVE-2013-2445 * CVE-2013-2451 * CVE-2013-2450 * CVE-2013-2446 * CVE-2013-2452 * CVE-2013-1500 * CVE-2013-2444 * CVE-2013-2447 * CVE-2013-2443 * CVE-2013-2412 * CVE-2013-2448 * CVE-2013-2455 * CVE-2013-2457 * CVE-2013-2453 * CVE-2013-2456 * CVE-2013-2459 * CVE-2013-2470 * CVE-2013-2471 * CVE-2013-2472 * CVE-2013-2473 * CVE-2013-1571 * CVE-2013-2463 * CVE-2013-2465 * CVE-2013-2469 * CVE-2013-2461 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-java-1_6_0-openjdk-8084 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64): java-1_6_0-openjdk-1.6.0.0_b27.1.12.6-0.2.1 java-1_6_0-openjdk-demo-1.6.0.0_b27.1.12.6-0.2.1 java-1_6_0-openjdk-devel-1.6.0.0_b27.1.12.6-0.2.1 References: https://www.suse.com/security/cve/CVE-2013-1500.html https://www.suse.com/security/cve/CVE-2013-1571.html https://www.suse.com/security/cve/CVE-2013-2407.html https://www.suse.com/security/cve/CVE-2013-2412.html https://www.suse.com/security/cve/CVE-2013-2443.html https://www.suse.com/security/cve/CVE-2013-2444.html https://www.suse.com/security/cve/CVE-2013-2445.html https://www.suse.com/security/cve/CVE-2013-2446.html https://www.suse.com/security/cve/CVE-2013-2447.html https://www.suse.com/security/cve/CVE-2013-2448.html https://www.suse.com/security/cve/CVE-2013-2450.html https://www.suse.com/security/cve/CVE-2013-2451.html https://www.suse.com/security/cve/CVE-2013-2452.html https://www.suse.com/security/cve/CVE-2013-2453.html https://www.suse.com/security/cve/CVE-2013-2455.html https://www.suse.com/security/cve/CVE-2013-2456.html https://www.suse.com/security/cve/CVE-2013-2457.html https://www.suse.com/security/cve/CVE-2013-2459.html https://www.suse.com/security/cve/CVE-2013-2461.html https://www.suse.com/security/cve/CVE-2013-2463.html https://www.suse.com/security/cve/CVE-2013-2465.html https://www.suse.com/security/cve/CVE-2013-2469.html https://www.suse.com/security/cve/CVE-2013-2470.html https://www.suse.com/security/cve/CVE-2013-2471.html https://www.suse.com/security/cve/CVE-2013-2472.html https://www.suse.com/security/cve/CVE-2013-2473.html https://login.microfocus.com/nidp/app/login?sid=0 https://login.microfocus.com/nidp/app/login?sid=0 . SUSE issued a significant enhancement for java-1_6_0-openjdk aimed at fixing 26 security flaws to improve overall system protection.. SUSE Linux Update, Java Security Issues, OpenJDK Update, Software Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2013 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200