Explore top 10 tips to secure your open-source projects now. Read More
×This update upgrades Thunderbird to version 115.4.1. --- This content is derived from https://access.redhat.com/errata/RHSA-2023:6193 SL7 srpm thunderbird-0:115.4.1-1.el7_9.src x86_64 thunderbird-0:115.4.1-1.el7_9.x86_64 - Scientific Linux Development Team . Red Hat Security Advisory: thunderbird security update Advisory ID: SLSA-2023:6193 Issue Date: 2023-10-30 CVE Numbers: None -- Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.4.1. Security Fix(es): --- This content is derived from https://access.redhat.com/errata/RHSA-2023:6193 -- SL7 srpm thunderbird-0:115.4.1-1.el7_9.src x86_64 thunderbird-0:115.4.1-1.el7_9.x86_64 - Scientific Linux Development Team . Upgrade Thunderbird to version 115.4.1 on Scientific Linux to bolster email security measures.. thunderbird security update, scientific linux advisory, mail client upgrade. . LinuxSecurity.com Team
This update upgrades Firefox to version 115.3.1 ESR. * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-20 23-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 1 15.3 (CVE-2023-5176) * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE- [More...] . Red Hat Security Advisory: firefox security update Advisory ID: SLSA-2023:5477 Issue Date: 2023-10-05 CVE Numbers: CVE-2023-3600 CVE-2023-5169 CVE-2023-5171 CVE-2023-5176 CVE-2023-5217 -- Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.3.1 ESR. Security Fix(es): * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176) * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217) --- This content is derived from https://access.redhat.com/errata/RHSA-2023:5477 -- SL7 srpm firefox-0:115.3.1-1.el7_9.src x86_64 firefox-0:115.3.1-1.el7_9.x86_64 i386 firefox-0:115.3.1-1.el7_9.i686 - Scientific Linux Development Team . Red Hat Security Bulletin for Firefox enhancement on SL7 tackling severe memory integrity vulnerabilities and buffer overflow risks.. firefox update, critical vulnerabilities, scientific linux. . Severity: Critical. LinuxSecurity.com Team
This update upgrades Firefox to version 115.3.1 ESR. * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176) * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE- [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2023:5477-1 Issue Date: 2023-10-05 CVE Numbers: CVE-2023-3600 CVE-2023-5169 CVE-2023-5171 CVE-2023-5176 CVE-2023-5217 -- This update upgrades Firefox to version 115.3.1 ESR. Security Fix(es): * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176) * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 firefox-115.3.1-1.el7_9.x86_64.rpm firefox-debuginfo-115.3.1-1.el7_9.x86_64.rpm firefox-115.3.1-1.el7_9.i686.rpm firefox-debuginfo-115.3.1-1.el7_9.i686.rpm - Scientific Linux Development Team . Urgent patch released for Firefox tackling major security vulnerabilities, impacting editions within Scientific Linux 7.x systems.. Firefox Update, Scientific Linux, Mozilla Issues, Security Advisory, Critical Fix. . Severity: Critical. LinuxSecurity.com Team
ImageMagick: Division by zero in ReadEnhMetaFile lead to DoS (CVE-2021-40211) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 ImageMagick-6.9.10.68-7.el7_9.i686.rpm ImageMagick-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.el7_9.i686.rpm ImageMagick-c++-6 [More...]. Synopsis: Important: ImageMagick security update Advisory ID: SLSA-2023:5461-1 Issue Date: 2023-10-05 CVE Numbers: CVE-2021-40211 -- Security Fix(es): * ImageMagick: Division by zero in ReadEnhMetaFile lead to DoS (CVE-2021-40211) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 ImageMagick-6.9.10.68-7.el7_9.i686.rpm ImageMagick-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.el7_9.i686.rpm ImageMagick-c++-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-debuginfo-6.9.10.68-7.el7_9.i686.rpm ImageMagick-debuginfo-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-c++-devel-6.9.10.68-7.el7_9.i686.rpm ImageMagick-c++-devel-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-devel-6.9.10.68-7.el7_9.i686.rpm ImageMagick-devel-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-doc-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-perl-6.9.10.68-7.el7_9.x86_64.rpm - Scientific Linux Development Team . Critical patch released for ImageMagick resolves a denial-of-service vulnerability affecting Scientific Linux 7.x x86_64 environments.. ImageMagick, DoS Issue, Security Update, Scientific Linux, Security Fix. . Severity: Critical. LinuxSecurity.com Team
This update upgrades Thunderbird to version 102.15.1. * libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 thunderbird-102.15.1-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el7_9.x86_64.rpm - Scientific Linux D [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2023:5191-1 Issue Date: 2023-09-19 CVE Numbers: CVE-2023-4863 -- This update upgrades Thunderbird to version 102.15.1. Security Fix(es): * libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 thunderbird-102.15.1-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el7_9.x86_64.rpm - Scientific Linux Development Team . Significant Thunderbird upgrade for Scientific Linux addresses major buffer overflow vulnerability within WebP Codec.. Thunderbird Update, Scientific Linux Security, Buffer Overflow, Software Upgrade. . Severity: Important. LinuxSecurity.com Team
This update upgrades Thunderbird to version 102.15.0. * Mozilla: Memory corruption in IPC CanvasTranslator (CVE-2023-4573) * Mozilla: Memory corruption in IPC ColorPickerShownCallback (CVE-2023-4574) * Mozilla: Memory corruption in IPC FilePickerShownCallback (CVE-2023-4575) * Mozilla: Memory corruption in JIT UpdateRegExpStatics (CVE-2023-4577) * Mozilla: Memory safety bugs fixed in Firefo [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2023:4945-1 Issue Date: 2023-09-05 CVE Numbers: CVE-2023-4573 CVE-2023-4574 CVE-2023-4575 CVE-2023-4577 CVE-2023-4051 CVE-2023-4578 CVE-2023-4053 CVE-2023-4580 CVE-2023-4581 CVE-2023-4583 CVE-2023-4584 CVE-2023-4585 -- This update upgrades Thunderbird to version 102.15.0. Security Fix(es): * Mozilla: Memory corruption in IPC CanvasTranslator (CVE-2023-4573) * Mozilla: Memory corruption in IPC ColorPickerShownCallback (CVE-2023-4574) * Mozilla: Memory corruption in IPC FilePickerShownCallback (CVE-2023-4575) * Mozilla: Memory corruption in JIT UpdateRegExpStatics (CVE-2023-4577) * Mozilla: Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2 (CVE-2023-4584) * Mozilla: Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2 (CVE-2023-4585) * Mozilla: Full screen notification obscured by file open dialog (CVE-2023-4051) * Mozilla: Full screen notification obscured by external program (CVE-2023-4053) * Mozilla: Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception (CVE-2023-4578) * Mozilla: Push notifications saved to disk unencrypted (CVE-2023-4580) * Mozilla: XLL file extensions were downloadable without warnings (CVE-2023-4581) * Mozilla: Browsing Context potentially notcleared when closing Private Window (CVE-2023-4583) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 thunderbird-102.15.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.15.0-1.el7_9.x86_64.rpm - Scientific Linux Development Team . Important Thunderbird patch resolves various memory security vulnerabilities identified in Mozilla applications; recommended for SL7.x users.. Scientific Linux, Thunderbird, Memory Issues, Mozilla, Security Update. . Severity: Critical. LinuxSecurity.com Team
openssh: Remote code execution in ssh-agent PKCS#11 support (CVE-2023-38408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssh-7.4p1-23.el7_9.x86_64.rpm openssh-askpass-7.4p1-23.el7_9.x86_64.rpm openssh-clients-7.4p1-23.el7_9.x86_64.rpm openssh-debuginfo-7.4p1 [More...]. Synopsis: Important: openssh security update Advisory ID: SLSA-2023:4382-1 Issue Date: 2023-08-03 CVE Numbers: CVE-2023-38408 -- Security Fix(es): * openssh: Remote code execution in ssh-agent PKCS#11 support (CVE-2023-38408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 openssh-7.4p1-23.el7_9.x86_64.rpm openssh-askpass-7.4p1-23.el7_9.x86_64.rpm openssh-clients-7.4p1-23.el7_9.x86_64.rpm openssh-debuginfo-7.4p1-23.el7_9.x86_64.rpm openssh-keycat-7.4p1-23.el7_9.x86_64.rpm openssh-server-7.4p1-23.el7_9.x86_64.rpm openssh-cavs-7.4p1-23.el7_9.x86_64.rpm openssh-debuginfo-7.4p1-23.el7_9.i686.rpm openssh-ldap-7.4p1-23.el7_9.x86_64.rpm openssh-server-sysvinit-7.4p1-23.el7_9.x86_64.rpm pam_ssh_agent_auth-0.10.3-2.23.el7_9.i686.rpm pam_ssh_agent_auth-0.10.3-2.23.el7_9.x86_64.rpm - Scientific Linux Development Team . Critical security patch for OpenSSH mitigating remote execution vulnerabilities in SSH, identified by Advisory ID SLSA-2023:4382-2.. openssh update, remote code execution, scientific linux advisory, ssh-agent security. . Severity: Important. LinuxSecurity.com Team
OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Prepare for the next quarterly OpenJDK upstream releas [More...]. Synopsis: Moderate: java-1.8.0-openjdk security and bug fix update Advisory ID: SLSA-2023:4166-1 Issue Date: 2023-07-24 CVE Numbers: CVE-2023-22045 CVE-2023-22049 -- Security Fix(es): * OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Prepare for the next quarterly OpenJDK upstream release (2023-07, 8u382) -- SL7 x86_64 java-1.8.0-openjdk-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-headless-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-accessibility-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-demo-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-devel-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-src-1.8.0.382.b05-1.el7_9.x86_64.rpm noarch java-1.8.0-openjdk-javadoc-1.8.0.382.b05-1.el7_9.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.382.b05-1.el7_9.noarch.rpm - Scientific Linux Development Team . Recent OpenJDK enhancements focused on URI management and indexing anomalies on Scientific Linux 7.x platforms. Explore for further insights.. OpenJDK Update, Java Fix, Scientific Linux Security, Security Update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.