The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-1142 https://linux.oracle.com/errata/ELSA-2024-1142.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: haproxy-2.4.22-3.el9_3.x86_64.rpm aarch64: haproxy-2.4.22-3.el9_3.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//haproxy-2.4.22-3.el9_3.src.rpm Related CVEs: CVE-2023-40225 CVE-2023-45539 Description of changes: [2.4.22-3] - Reject "#" as part of URI path component (CVE-2023-45539, RHEL-18169) [2.4.22-2] - Reject any empty content-length header value (CVE-2023-40225, RHEL-7736) _______________________________________________ El-errata mailing list
An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. SUSE Security Update: Security update for lighttpd ______________________________________________________________________________ Announcement ID: SUSE-SU-2014:0474-1 Rating: important References: #867350 Cross-References: CVE-2014-2323 CVE-2014-2324 Affected Products: SUSE Linux Enterprise Software Development Kit 11 SP3 SUSE Linux Enterprise High Availability Extension 11 SP3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: The HTTP server lighttpd was updated to fix the following security issues: * CVE-2014-2323: SQL injection vulnerability in mod_mysql_vhost.c in lighttpd allowed remote attackers to execute arbitrary SQL commands via the host name. * CVE-2014-2323: Multiple directory traversal vulnerabilities in mod_evhost and mod_simple_vhost in lighttpd allowed remote attackers to read arbitrary files via .. (dot dot) in the host name. More information can be found on the lighttpd advisory page: 014_01.txt Security Issues references: * CVE-2014-2323 * CVE-2014-2324 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP3: zypper in -t patch sdksp3-lighttpd-9031 - SUSE Linux Enterprise High Availability Extension 11 SP3: zypper in -t patch slehasp3-lighttpd-9031 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP3 (i586 ia64 ppc64 s390x x86_64): lighttpd-1.4.20-2.54.1 lighttpd-mod_cml-1.4.20-2.54.1 lighttpd-mod_magnet-1.4.20-2.54.1 lighttpd-mod_mysql_vhost-1.4.20-2.54.1 lighttpd-mod_rrdtool-1.4.20-2.54.1 lighttpd-mod_trigger_b4_dl-1.4.20-2.54.1 lighttpd-mod_webdav-1.4.20-2.54.1 - SUSE Linux Enterprise High Availability Extension 11 SP3 (i586 ia64 ppc64 s390x x86_64): lighttpd-1.4.20-2.54.1 References: https://www.suse.com/security/cve/CVE-2014-2323.html https://www.suse.com/security/cve/CVE-2014-2324.html https://scc.suse.com:443/patches/ . A significant patch for lighttpd resolves vulnerabilities related to SQL injection and directory traversal on SUSE Linux platforms.. lighttpd update, SQL injection, path traversal, SUSE security, software patch. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.