Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
98

Red Hat RHSA-2023-1102-01 Moderate: MySQL Security Update

An update for rh-mysql80-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-mysql80-mysql security update Advisory ID: RHSA-2023:1102-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2023:1102 Issue date: 2023-03-07 CVE Names: CVE-2022-21594 CVE-2022-21599 CVE-2022-21604 CVE-2022-21608 CVE-2022-21611 CVE-2022-21617 CVE-2022-21625 CVE-2022-21632 CVE-2022-21633 CVE-2022-21637 CVE-2022-21640 CVE-2022-39400 CVE-2022-39408 CVE-2022-39410 CVE-2023-21836 CVE-2023-21863 CVE-2023-21864 CVE-2023-21865 CVE-2023-21867 CVE-2023-21868 CVE-2023-21869 CVE-2023-21870 CVE-2023-21871 CVE-2023-21873 CVE-2023-21874 CVE-2023-21875 CVE-2023-21876 CVE-2023-21877 CVE-2023-21878 CVE-2023-21879 CVE-2023-21880 CVE-2023-21881 CVE-2023-21882 CVE-2023-21883 CVE-2023-21887 ==================================================================== 1. Summary: An update for rh-mysql80-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation(v. 7) - x86_64 3. Description: MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs. The following packages have been upgraded to a later upstream version: rh-mysql80-mysql (8.0.32). (BZ#2142971, BZ#2162319) Security Fix(es): * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) (CVE-2022-21594) * mysql: Server: Stored Procedure unspecified vulnerability (CPU Oct 2022) (CVE-2022-21599) * mysql: InnoDB unspecified vulnerability (CPU Oct 2022) (CVE-2022-21604) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) (CVE-2022-21608) * mysql: InnoDB unspecified vulnerability (CPU Oct 2022) (CVE-2022-21611) * mysql: Server: Connection Handling unspecified vulnerability (CPU Oct 2022) (CVE-2022-21617) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) (CVE-2022-21625) * mysql: Server: Security: Privileges unspecified vulnerability (CPU Oct 2022) (CVE-2022-21632) * mysql: Server: Replication unspecified vulnerability (CPU Oct 2022) (CVE-2022-21633) * mysql: InnoDB unspecified vulnerability (CPU Oct 2022) (CVE-2022-21637) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) (CVE-2022-21640) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) (CVE-2022-39400) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) (CVE-2022-39408) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) (CVE-2022-39410) * mysql: Server: DML unspecified vulnerability (CPU Jan 2023) (CVE-2023-21836) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21863) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21864) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21865) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21867) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21868) * mysql: InnoDBunspecified vulnerability (CPU Jan 2023) (CVE-2023-21869) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21870) * mysql: InnoDB unspecified vulnerability (CPU Jan 2023) (CVE-2023-21871) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21873) * mysql: Server: Security: Encryption unspecified vulnerability (CPU Jan 2023) (CVE-2023-21875) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21876) * mysql: InnoDB unspecified vulnerability (CPU Jan 2023) (CVE-2023-21877) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21878) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21879) * mysql: InnoDB unspecified vulnerability (CPU Jan 2023) (CVE-2023-21880) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21881) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21883) * mysql: Server: GIS unspecified vulnerability (CPU Jan 2023) (CVE-2023-21887) * mysql: Server: Thread Pooling unspecified vulnerability (CPU Jan 2023) (CVE-2023-21874) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) (CVE-2023-21882) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 2142861 - CVE-2022-21594 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) 2142863 - CVE-2022-21599 mysql: Server: Stored Procedure unspecified vulnerability (CPU Oct 2022) 2142865 - CVE-2022-21604 mysql: InnoDB unspecified vulnerability (CPU Oct 2022) 2142868 - CVE-2022-21608 mysql: Server:Optimizer unspecified vulnerability (CPU Oct 2022) 2142869 - CVE-2022-21611 mysql: InnoDB unspecified vulnerability (CPU Oct 2022) 2142870 - CVE-2022-21617 mysql: Server: Connection Handling unspecified vulnerability (CPU Oct 2022) 2142871 - CVE-2022-21625 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) 2142872 - CVE-2022-21632 mysql: Server: Security: Privileges unspecified vulnerability (CPU Oct 2022) 2142873 - CVE-2022-21633 mysql: Server: Replication unspecified vulnerability (CPU Oct 2022) 2142875 - CVE-2022-21637 mysql: InnoDB unspecified vulnerability (CPU Oct 2022) 2142877 - CVE-2022-21640 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) 2142879 - CVE-2022-39400 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) 2142880 - CVE-2022-39408 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) 2142881 - CVE-2022-39410 mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2022) 2162268 - CVE-2023-21836 mysql: Server: DML unspecified vulnerability (CPU Jan 2023) 2162270 - CVE-2023-21863 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162271 - CVE-2023-21864 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162272 - CVE-2023-21865 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162274 - CVE-2023-21867 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162275 - CVE-2023-21868 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162276 - CVE-2023-21869 mysql: InnoDB unspecified vulnerability (CPU Jan 2023) 2162277 - CVE-2023-21870 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162278 - CVE-2023-21871 mysql: InnoDB unspecified vulnerability (CPU Jan 2023) 2162280 - CVE-2023-21873 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162281 - CVE-2023-21874 mysql: Server: Thread Pooling unspecified vulnerability (CPU Jan 2023) 2162282 - CVE-2023-21875 mysql: Server: Security: Encryption unspecified vulnerability (CPU Jan2023) 2162283 - CVE-2023-21876 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162284 - CVE-2023-21877 mysql: InnoDB unspecified vulnerability (CPU Jan 2023) 2162285 - CVE-2023-21878 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162286 - CVE-2023-21879 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162287 - CVE-2023-21880 mysql: InnoDB unspecified vulnerability (CPU Jan 2023) 2162288 - CVE-2023-21881 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162289 - CVE-2023-21882 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162290 - CVE-2023-21883 mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2023) 2162291 - CVE-2023-21887 mysql: Server: GIS unspecified vulnerability (CPU Jan 2023) 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-mysql80-mysql-8.0.32-1.el7.src.rpm ppc64le: rh-mysql80-mysql-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-common-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-config-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-config-syspaths-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-debuginfo-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-devel-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-errmsg-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-icu-data-files-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-server-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-server-syspaths-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-syspaths-8.0.32-1.el7.ppc64le.rpm rh-mysql80-mysql-test-8.0.32-1.el7.ppc64le.rpm s390x: rh-mysql80-mysql-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-common-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-config-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-config-syspaths-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-debuginfo-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-devel-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-errmsg-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-icu-data-files-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-server-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-server-syspaths-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-syspaths-8.0.32-1.el7.s390x.rpm rh-mysql80-mysql-test-8.0.32-1.el7.s390x.rpm x86_64: rh-mysql80-mysql-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-common-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-config-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-config-syspaths-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-debuginfo-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-devel-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-errmsg-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-icu-data-files-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-server-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-server-syspaths-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-syspaths-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-test-8.0.32-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v.7): Source: rh-mysql80-mysql-8.0.32-1.el7.src.rpm x86_64: rh-mysql80-mysql-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-common-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-config-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-config-syspaths-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-debuginfo-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-devel-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-errmsg-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-icu-data-files-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-server-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-server-syspaths-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-syspaths-8.0.32-1.el7.x86_64.rpm rh-mysql80-mysql-test-8.0.32-1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2022-21594 https://access.redhat.com/security/cve/CVE-2022-21599 https://access.redhat.com/security/cve/CVE-2022-21604 https://access.redhat.com/security/cve/CVE-2022-21608 https://access.redhat.com/security/cve/CVE-2022-21611 https://access.redhat.com/security/cve/CVE-2022-21617 https://access.redhat.com/security/cve/CVE-2022-21625 https://access.redhat.com/security/cve/CVE-2022-21632 https://access.redhat.com/security/cve/CVE-2022-21633 https://access.redhat.com/security/cve/CVE-2022-21637 https://access.redhat.com/security/cve/CVE-2022-21640 https://access.redhat.com/security/cve/CVE-2022-39400 https://access.redhat.com/security/cve/CVE-2022-39408 https://access.redhat.com/security/cve/CVE-2022-39410 https://access.redhat.com/security/cve/CVE-2023-21836 https://access.redhat.com/security/cve/CVE-2023-21863 https://access.redhat.com/security/cve/CVE-2023-21864 https://access.redhat.com/security/cve/CVE-2023-21865 https://access.redhat.com/security/cve/CVE-2023-21867 https://access.redhat.com/security/cve/CVE-2023-21868 https://access.redhat.com/security/cve/CVE-2023-21869 https://access.redhat.com/security/cve/CVE-2023-21870 https://access.redhat.com/security/cve/CVE-2023-21871 https://access.redhat.com/security/cve/CVE-2023-21873 https://access.redhat.com/security/cve/CVE-2023-21874 https://access.redhat.com/security/cve/CVE-2023-21875 https://access.redhat.com/security/cve/CVE-2023-21876 https://access.redhat.com/security/cve/CVE-2023-21877 https://access.redhat.com/security/cve/CVE-2023-21878 https://access.redhat.com/security/cve/CVE-2023-21879 https://access.redhat.com/security/cve/CVE-2023-21880 https://access.redhat.com/security/cve/CVE-2023-21881 https://access.redhat.com/security/cve/CVE-2023-21882 https://access.redhat.com/security/cve/CVE-2023-21883 https://access.redhat.com/security/cve/CVE-2023-21887 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZAcuG9zjgjWX9erEAQiCZg//RX3U55Hsa1yStZrZLZLP+nt+h0/LlXRj 4dixNgz2Zvy9rMQ6mTLuxuxcFDLraLUOLKWi8ZDe3iuZfU5bc+wkyrkdnEBMoZW5 yidR3Qz8hBBU6CD1VB9bTPmxVPsKlnw272h943XbOUH4JtZvRGTf3O8xpuS0WrEL ZGq9SJCDv7MQCL5JhAMODdrED/yFlW5I17CWhRoSi1u8nBW7qeO5Kig/sNFpJQtz BYegMWTJx/WFQfCRn0nGck0G8WJkQF3j0hCi+FHDSyHIgYG8XZ5sQX/3Nb6YmV0Q d9mQY71oI5ix5mFNdgOAl/xpVKqkV4Ea3sebTB2GGq6N61jRBD+VKy6iiZoKI4S4 rVj9VIcKvO4gY6Fnag1wd9Kt/iZLbMNBPtLmXjhW8D6YSfiBSieS5Y7BYMSCdyTC QwkQPFEy+NNaS4JcbIo5mbth7YshGue3HKT2Ci0z4czP8UxPiVd3+XfRnZcWX6J1 TyN5qSOXot66HoGWKi4lfDMaM3JHvclVZ0xZc2kUA+tdgzlkY/EWJhFBzJQmpTaV Gg5JGAkyaMy8kUWEkvcNFJ/+kztHt2XxofxbDZhqKR9DNqHwbkC6lDfB9I3EIPg0 LjVBxhMI2o5zReVEeYr8onJSdn6GaF2KLpesPzKm3Elrr2c95pyukcwERJDIJjHm n0kK9NnNg94=3Az9 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important security patch released for rh-postgresql12-postgresql on Red Hat Software Collections. Ensure your systems are protected!. Red Hat, MySQL Update, Software Collections, Database Security. . LinuxSecurity.com Team

Calendar 2 Mar 07, 2023 Red Hat
98

Red Hat RHSA-2022:1662-01 Important: Command Injection in Maven

An update for rh-maven36-maven-shared-utils is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-maven36-maven-shared-utils security update Advisory ID: RHSA-2022:1662-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2022:1662 Issue date: 2022-05-02 CVE Names: CVE-2022-29599 ==================================================================== 1. Summary: An update for rh-maven36-maven-shared-utils is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch 3. Description: The Apache Maven Shared Utils project aims to be an improved functional replacement for plexus-utils in Maven. Security Fix(es): * maven-shared-utils: Command injection via Commandline class (CVE-2022-29599) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2066479 - CVE-2022-29599 maven-shared-utils: Command injectionvia Commandline class 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-maven36-maven-shared-utils-3.2.1-0.2.3.el7.src.rpm noarch: rh-maven36-maven-shared-utils-3.2.1-0.2.3.el7.noarch.rpm rh-maven36-maven-shared-utils-javadoc-3.2.1-0.2.3.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-maven36-maven-shared-utils-3.2.1-0.2.3.el7.src.rpm noarch: rh-maven36-maven-shared-utils-3.2.1-0.2.3.el7.noarch.rpm rh-maven36-maven-shared-utils-javadoc-3.2.1-0.2.3.el7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-29599 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYm+vmNzjgjWX9erEAQicKBAAh4PjLHwqnQhS4+jK+qcxA4PZgSYiJXzz gN11pblWOSkInbl4AMV8jZ/172iW5T9RFQsoo6ZeRYPl+NWyjGDheEwXM1Sk8VYd UMUB0bR/62Y0MRy69Yay/QJBxhYUL+Zxn9+9kcAWk7yNIoXu6KxmviO7qVNWwUGx LACa/MastbQzHfKJhAz0bm/hPdhJr+oB9Px5l/TxaKP5Q8uWeffwaCfZcI/PRBR+ k91K0Nl5u+6C0LqIuxDgjcbx92vyRcQtshDaEZrhB4fP30xDeX7/OPDXDpbKCizE Xa1X1wE5xBDCHgnMi4mQZOmK+quiIngKCbSHNKqr2MFZZcU14sRqRbx1pVHfGsNS s/CKxhBL3Fjb3ROQgGNZs9Kz0v+an9rTUUHNx+kdJaQe8Ox2QO83WJj/7rAhQzoJ xZPZxMGMwB08oInenAu2poijOTyMbPfEcxvXihyMNeuofjIRLzaeC96zg5kCEwXc FRajO+R6yaGI5vhR2avkWEIbQTZQgK/40JCH5mh9nKwzYV+8cjVyYFfaPZmpjaHI w4tYNDJtvMQzzPbCj5IeZlCXUFb+mBmYL2nAOO2Hog3kKF4CvcQsQVgqFQi8fENd r9Hlz3BkqpkuhPA8GiXD+NSi/CeoKbEVjyMqnLcB/jHdxJQC0SQhXhmmBCRUcs59 dCyGhmOTwVc=m06W -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Critical notification regarding rh-maven36-maven-shared-utilities addressing acommand injection vulnerability classified as critical.. rh-maven36-maven-shared-utils, command injection, software update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 02, 2022 Important Red Hat
98

Red Hat: RHSA-2022-0303-01 Important: httpd24-httpd Buffer Overflow Risk

An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: httpd24-httpd security update Advisory ID: RHSA-2022:0303-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2022:0303 Issue date: 2022-01-27 CVE Names: CVE-2021-44790 ==================================================================== 1. Summary: An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): * httpd: mod_lua: Possible buffer overflow when parsing multipart content (CVE-2021-44790) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. 5. Bugs fixed(https://bugzilla.redhat.com/): 2034674 - CVE-2021-44790 httpd: mod_lua: Possible buffer overflow when parsing multipart content 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: httpd24-httpd-2.4.34-23.el7.1.src.rpm noarch: httpd24-httpd-manual-2.4.34-23.el7.1.noarch.rpm ppc64le: httpd24-httpd-2.4.34-23.el7.1.ppc64le.rpm httpd24-httpd-debuginfo-2.4.34-23.el7.1.ppc64le.rpm httpd24-httpd-devel-2.4.34-23.el7.1.ppc64le.rpm httpd24-httpd-tools-2.4.34-23.el7.1.ppc64le.rpm httpd24-mod_ldap-2.4.34-23.el7.1.ppc64le.rpm httpd24-mod_proxy_html-2.4.34-23.el7.1.ppc64le.rpm httpd24-mod_session-2.4.34-23.el7.1.ppc64le.rpm httpd24-mod_ssl-2.4.34-23.el7.1.ppc64le.rpm s390x: httpd24-httpd-2.4.34-23.el7.1.s390x.rpm httpd24-httpd-debuginfo-2.4.34-23.el7.1.s390x.rpm httpd24-httpd-devel-2.4.34-23.el7.1.s390x.rpm httpd24-httpd-tools-2.4.34-23.el7.1.s390x.rpm httpd24-mod_ldap-2.4.34-23.el7.1.s390x.rpm httpd24-mod_proxy_html-2.4.34-23.el7.1.s390x.rpm httpd24-mod_session-2.4.34-23.el7.1.s390x.rpm httpd24-mod_ssl-2.4.34-23.el7.1.s390x.rpm x86_64: httpd24-httpd-2.4.34-23.el7.1.x86_64.rpm httpd24-httpd-debuginfo-2.4.34-23.el7.1.x86_64.rpm httpd24-httpd-devel-2.4.34-23.el7.1.x86_64.rpm httpd24-httpd-tools-2.4.34-23.el7.1.x86_64.rpm httpd24-mod_ldap-2.4.34-23.el7.1.x86_64.rpm httpd24-mod_proxy_html-2.4.34-23.el7.1.x86_64.rpm httpd24-mod_session-2.4.34-23.el7.1.x86_64.rpm httpd24-mod_ssl-2.4.34-23.el7.1.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: httpd24-httpd-2.4.34-23.el7.1.src.rpm noarch: httpd24-httpd-manual-2.4.34-23.el7.1.noarch.rpm x86_64: httpd24-httpd-2.4.34-23.el7.1.x86_64.rpm httpd24-httpd-debuginfo-2.4.34-23.el7.1.x86_64.rpm httpd24-httpd-devel-2.4.34-23.el7.1.x86_64.rpm httpd24-httpd-tools-2.4.34-23.el7.1.x86_64.rpm httpd24-mod_ldap-2.4.34-23.el7.1.x86_64.rpm httpd24-mod_proxy_html-2.4.34-23.el7.1.x86_64.rpm httpd24-mod_session-2.4.34-23.el7.1.x86_64.rpm httpd24-mod_ssl-2.4.34-23.el7.1.x86_64.rpm These packages areGPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-44790 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYfJ/gNzjgjWX9erEAQjFuQ//QvhnMlzCeWvHaIcVI5FG/NXNTVi7cqK4 UTb7iLZPMrIO5f/w/zwSMpKzQ/322CtvtMVYQA0Jv5XsbwRXYciGnKcNU9WWb3ab jq9g6kWhuqGuAQ2OGjjpzvirouG8RZ/iVlc3MqsAlNHO33EJwU9iUGv1eTZP2sOm hvlUuzWQ9fCxDaBAlD0vMiIf2v3uE/6aOqip8pHnhwp6hzLY+14azMvR5xJs9A5t fKG9c8orv9sVXIejS7p0HUhNd+CG14uWEFKP3kQ2Otz05QrdlMQsMgKyKmIIt2BB TbUiJORVPE4NbHnlF3JzXasRPm1n4aoQjUt1ixR4QKHF8yiWCbH3/nJSXU7QkY/9 2jdMT4AHoyk27pkuERzRJdx3UVMDMnUXyTXEKgukIPdXLfeoL14YXjbHcEHaBnyi fSIWIkyVczFfEyjVCRHmy0NucPq+YHGzVgrppawLRWRRKxYHgf07XP6/5gCR8qd8 agdhJd10yJqP9UcJlANJQwTfWoh24BTFjvrD2JOZOG+Hi29k8dIYEqVN+W7VpDAm DwqNKAXZ9Z2Or9hsW72qe04ZVRDcNTJD+bJK5hSu2lXG8y6VNT2lZ2hdG3jssZI9 IVHfEFAcsHxO6aS4uaLyu6SBGFPW52LDOPXYBr+9GqNC48i71L6drEwD1yppZ1r5 1QvYdSW/nAs=OFnV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical Red Hat notice regarding httpd24-httpd featuring security patches addressing buffer overflow vulnerabilities along with available upgrades.. Red Hat Security Update,httpd24-httpd Update,Software Collections Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 27, 2022 Important Red Hat
98

Red Hat Software Collections: RHSA-2020-2895-01 Important: Node.js DoS Fix

An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-nodejs12-nodejs security update Advisory ID: RHSA-2020:2895-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2020:2895 Issue date: 2020-07-13 CVE Names: CVE-2020-7598 CVE-2020-8172 CVE-2020-8174 CVE-2020-10531 CVE-2020-11080 ==================================================================== 1. Summary: An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: rh-nodejs12-nodejs (12.18.2). Security Fix(es): * ICU: Integer overflow in UnicodeString::doAppend() (CVE-2020-10531) * nghttp2: overly large SETTINGS framescan lead to DoS (CVE-2020-11080) * nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload (CVE-2020-7598) * nodejs: TLS session reuse can lead to hostname verification bypass (CVE-2020-8172) * nodejs: memory corruption in napi_get_value_string_* functions (CVE-2020-8174) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1807349 - CVE-2020-10531 ICU: Integer overflow in UnicodeString::doAppend() 1813344 - CVE-2020-7598 nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload 1844929 - CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS 1845247 - CVE-2020-8172 nodejs: TLS session reuse can lead to hostname verification bypass 1845256 - CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-nodejs12-nodejs-12.18.2-1.el7.src.rpm aarch64: rh-nodejs12-nodejs-12.18.2-1.el7.aarch64.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.aarch64.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.aarch64.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.aarch64.rpm noarch: rh-nodejs12-nodejs-docs-12.18.2-1.el7.noarch.rpm ppc64le: rh-nodejs12-nodejs-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.ppc64le.rpm s390x: rh-nodejs12-nodejs-12.18.2-1.el7.s390x.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.s390x.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.s390x.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.s390x.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-nodejs12-nodejs-12.18.2-1.el7.src.rpm aarch64: rh-nodejs12-nodejs-12.18.2-1.el7.aarch64.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.aarch64.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.aarch64.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.aarch64.rpm noarch: rh-nodejs12-nodejs-docs-12.18.2-1.el7.noarch.rpm ppc64le: rh-nodejs12-nodejs-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.ppc64le.rpm s390x: rh-nodejs12-nodejs-12.18.2-1.el7.s390x.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.s390x.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.s390x.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.s390x.rpm x86_64: rh-nodejs12-nodejs-12.18.2-1.el7.x86_64.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.x86_64.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.x86_64.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.6): Source: rh-nodejs12-nodejs-12.18.2-1.el7.src.rpm noarch: rh-nodejs12-nodejs-docs-12.18.2-1.el7.noarch.rpm ppc64le: rh-nodejs12-nodejs-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.ppc64le.rpm s390x: rh-nodejs12-nodejs-12.18.2-1.el7.s390x.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.s390x.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.s390x.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.s390x.rpm x86_64: rh-nodejs12-nodejs-12.18.2-1.el7.x86_64.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.x86_64.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.x86_64.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7): Source: rh-nodejs12-nodejs-12.18.2-1.el7.src.rpm noarch: rh-nodejs12-nodejs-docs-12.18.2-1.el7.noarch.rpm ppc64le: rh-nodejs12-nodejs-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.ppc64le.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.ppc64le.rpm s390x: rh-nodejs12-nodejs-12.18.2-1.el7.s390x.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.s390x.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.s390x.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.s390x.rpm x86_64: rh-nodejs12-nodejs-12.18.2-1.el7.x86_64.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.x86_64.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.x86_64.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-nodejs12-nodejs-12.18.2-1.el7.src.rpm noarch: rh-nodejs12-nodejs-docs-12.18.2-1.el7.noarch.rpm x86_64: rh-nodejs12-nodejs-12.18.2-1.el7.x86_64.rpm rh-nodejs12-nodejs-debuginfo-12.18.2-1.el7.x86_64.rpm rh-nodejs12-nodejs-devel-12.18.2-1.el7.x86_64.rpm rh-nodejs12-npm-6.14.5-12.18.2.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-7598 https://access.redhat.com/security/cve/CVE-2020-8172 https://access.redhat.com/security/cve/CVE-2020-8174 https://access.redhat.com/security/cve/CVE-2020-10531 https://access.redhat.com/security/cve/CVE-2020-11080 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXww8LtzjgjWX9erEAQjSpA/9E6XQExV/PXW40ykSQFgUkmaOFQNe7iV3 AVIdw/0qsh1JzMlk59s2OtmN+dzbbwfjcl6rBEYAiKBfWHiLaEIcUxXSTqt5kSw1 PXePxC7ZAEB/Ed+/1Uro1sPcdvsYUxMbZmb9+2ClBwlwLcWCNnsL7q5u9BcmwdNU TsImNAj3tpdJO4W+GpY5epVRHB+jYvmdh4jD23u2VuSLTkaKTqIDZxhCDqr3DHzH v/r6a8tPAPn0vDzv736XtAnaXYqzbl2gyhoJjYPxLIv4EmrSgN4jKEgi9yJiR1Ls jrJiIxEBfTt+zws8AWiFot/ULNUNh1Qi1o4qe/Ox8CkVz+hSgv4y4cY/j8xjdrYE gk5OQBP+1/8VPXiidhrCtQe06roSWWpoeKtCm9EsYZYxhoOyz9EG3GC5fB2sq5Ab PtgFnLqIiBCfzHUCy+uPFK8goeQqV5wI4g3Nq+PFHO5pXtUpTfKn4LUWcUfT76oN H0hN8WLoMhm//VauOJfyxNYUEmXZdzkUjLPNrerVY+oNSjETBIYCTBBzq3eGscH6 eP18M1vxH568u08FaW2wco87VDiGtmKVA+208RaZMOqzH4VUg50qqsRFMK/BHxXx 21Fvn8kVuAxYAfm44Y9M93tPadehRTqbs7nq4VWFlYCdsqI33lzFco6Cg10Z5X7Y YUZqoTrKyDY=jhzz -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical patch is unveiled for rh-nodejs14-nodejs within Red Hat Software Collections, resolving multiple vulnerabilities.. nodejs update, rh-nodejs12-nodejs, red hat software collection, important security updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 13, 2020 Important Red Hat
98

Red Hat 7: RHSA-2020:2817-01 Moderate: nginx HTTP Request Smuggling

An update for rh-nginx116-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-nginx116-nginx security update Advisory ID: RHSA-2020:2817-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2020:2817 Issue date: 2020-07-02 CVE Names: CVE-2019-20372 ==================================================================== 1. Summary: An update for rh-nginx116-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): * nginx: HTTP request smuggling via error pages in http/ngx_http_special_response.c (CVE-2019-20372) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details onhow to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The rh-nginx116-nginx service must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1790277 - CVE-2019-20372 nginx: HTTP request smuggling via error pages in http/ngx_http_special_response.c 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-nginx116-nginx-1.16.1-4.el7.1.src.rpm aarch64: rh-nginx116-nginx-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.aarch64.rpm ppc64le: rh-nginx116-nginx-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.ppc64le.rpm s390x: rh-nginx116-nginx-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.s390x.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-nginx116-nginx-1.16.1-4.el7.1.src.rpm aarch64: rh-nginx116-nginx-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.aarch64.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.aarch64.rpm ppc64le: rh-nginx116-nginx-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.ppc64le.rpm s390x: rh-nginx116-nginx-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.s390x.rpm x86_64: rh-nginx116-nginx-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.6): Source: rh-nginx116-nginx-1.16.1-4.el7.1.src.rpm ppc64le: rh-nginx116-nginx-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.ppc64le.rpm s390x: rh-nginx116-nginx-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.s390x.rpm x86_64: rh-nginx116-nginx-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.7): Source: rh-nginx116-nginx-1.16.1-4.el7.1.src.rpm ppc64le: rh-nginx116-nginx-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.ppc64le.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.ppc64le.rpm s390x: rh-nginx116-nginx-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.s390x.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.s390x.rpm x86_64: rh-nginx116-nginx-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-nginx116-nginx-1.16.1-4.el7.1.src.rpm x86_64: rh-nginx116-nginx-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-debuginfo-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-image-filter-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-perl-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-http-xslt-filter-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-mail-1.16.1-4.el7.1.x86_64.rpm rh-nginx116-nginx-mod-stream-1.16.1-4.el7.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2019-20372 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXv4IytzjgjWX9erEAQgI8w//alf18YgkOK3ZimuqZGLrc386g6bq2isJ z+iUvXMTN5lN9otTy0Zs/VUsCIdiXeCmdQJ3s0O7ZD+rjJMpKOQViYRyDShPFPfB JzqGRC3/KVQ/e33BkmLufWoJ2a8XiOaX99p+V3utpdT/wpZwe/FMZif/knldYo9Q gBYxrpbPC+e4G9NUVnCWP4jTfNPZlnThOk3xF0H+L8dTs1z59ZVdu9k7tDS32Lgv nuCkGWQuAbdeTJJtxUwCBVIQoJqYSn27ZZTGGI0odz2EvqmBmnapfs3197Qd0ETY FEG+1K1t5B/baFUu77x0ES2PikDuE+PxhXM8bh53NuX4qmygH/yvrgkhsBXZQ910 Ns6v7aHgdUHheNzZgA7Z6Aw1PUR0Bay2o2Hs88nNAOlrNtTapIyU0C5CNv734YJn d03+9zZKwLlCU+Jz3ykLvdLDXIr9yytJUu7fw/rYdcV9lBNZIg8lQaaFIKKjFT+b 70h5dgL3MJbXv0Opyv8p6SMrwTiaG9wegAT8qXBAaQSHTj94aL5u8HpWXCC4Xlvl 5vxOHH5bJTSQEsH9CJqyhfINVFzQ6HYTWK7m4hBv/jVtD9nduusH0qbIh7VvdZl7 HRAwK4lOoysHqCSfPj8Q+zQUa3+crI+MdqgblL1L2+i0CgK8dO5cOHVvLf5Gj472 svCw1SFlJ1g=shRv -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Substantial safety enhancement for rh-nginx116-nginx tackles HTTP request smuggling. Implement updates to boost protection.. Red Hat Software Collections, rh-nginx116-nginx, security update, security advisory, HTTP request. . LinuxSecurity.com Team

Calendar 2 Jul 02, 2020 Red Hat
98

RedHat: RHSA-2020-1290-01 Critical: rh-haproxy HTTP/2 Out-of-Bounds Write

An update for rh-haproxy18-haproxy is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Critical: rh-haproxy18-haproxy security update Advisory ID: RHSA-2020:1290-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2020:1290 Issue date: 2020-04-02 CVE Names: CVE-2020-11100 ==================================================================== 1. Summary: An update for rh-haproxy18-haproxy is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: HAProxy is a TCP/HTTP reverse proxy which is particularly suited for high availability environments. Security Fix(es): * haproxy: malformed HTTP/2 requests can lead to out-of-bounds writes (CVE-2020-11100) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how toapply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1819111 - CVE-2020-11100 haproxy: malformed HTTP/2 requests can lead to out-of-bounds writes 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-haproxy18-haproxy-1.8.17-1.el7.1.src.rpm x86_64: rh-haproxy18-haproxy-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-debuginfo-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-syspaths-1.8.17-1.el7.1.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5): Source: rh-haproxy18-haproxy-1.8.17-1.el7.1.src.rpm x86_64: rh-haproxy18-haproxy-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-debuginfo-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-syspaths-1.8.17-1.el7.1.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6): Source: rh-haproxy18-haproxy-1.8.17-1.el7.1.src.rpm x86_64: rh-haproxy18-haproxy-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-debuginfo-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-syspaths-1.8.17-1.el7.1.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7): Source: rh-haproxy18-haproxy-1.8.17-1.el7.1.src.rpm x86_64: rh-haproxy18-haproxy-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-debuginfo-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-syspaths-1.8.17-1.el7.1.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-haproxy18-haproxy-1.8.17-1.el7.1.src.rpm x86_64: rh-haproxy18-haproxy-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-debuginfo-1.8.17-1.el7.1.x86_64.rpm rh-haproxy18-haproxy-syspaths-1.8.17-1.el7.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2020-11100 https://access.redhat.com/security/updates/classification#critical https://access.redhat.com/security/vulnerabilities/haproxy 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXoXtkdzjgjWX9erEAQiZBRAAnTiOfqORylZUmXt9PROKH9TK/wBUhIJl TQLbBa6l7dbwTfqP6QJ1BKFyJZM4NQfhNddDajdppRaNOhLH5c91/Iu10J6GUpSe 7Hn/KOu5hDR2yiwZlCrS0/tGLACc9mlcw81xAGJqsI2/k+9s5IzV6EoxLNgLXs50 3oKU0ancV93FzwoKWR41oSewwZKn69OMUQPbNI/bS+KAN1acuJuuV+zWOxhiKMPj j8NzxwjhH1tEbWpfQGGuVOLUKA/+6gce+c/kd7qoLARf3Eu5l59efR2P+5YQpw+J VbrLopQVmMkk9gAmOCtfBnBCRLIfbDl1NbPnpnfh8c2D+M5f7cAz7WcLfkzGjdMZ ytozQDUGFhBjKxRaMIH0OrWm+/Tn5y+w88BRIX5B9zXyxTa/fNPZiijjMMJCxhEe ygW3bbrdfeH6Q+X4sXLiaKlbOQQADTLmGooY6o3b1i7SOGPvnDPOgdOXzCJYiExn BqOHNZyQyNvSFt+IIwzLofQyCdYTpOnw5oH2Yox/ypE7p+kvgZV6a9qFpoqaKFfv b3ujfuxfKqvI+f6OLzXvL6dFbkmPJHZC4di4eEwEoxhh5c2+25JzKWvzwb9R6Z+r rBMKuAuSfhmfMzhl+bgj+sUNcF4by4inEWBVSyJTsoKtpASa96EkpFDxty2tKDU/ GquL9K9cjUs=KSQN -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important notice regarding rh-haproxy: a critical defect related to out-of-bounds writes that affects Red Hat Software Collections has been identified. Further information is available within.. rh-haproxy critical update, out-of-bounds security fix, Red Hat Software Collections, HTTP/2 request issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 02, 2020 Critical Red Hat
98

RedHat RHSA-2019-4192-01 Crucial Update for rh-maven35-jackson-databind

An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-maven35-jackson-databind security update Advisory ID: RHSA-2019:4192-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2019:4192 Issue date: 2019-12-10 CVE Names: CVE-2019-17531 ==================================================================== 1. Summary: An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch 3. Description: The jackson-databind package provides general data-binding functionality for Jackson, which works on top of Jackson core streaming API. Security Fix(es): * jackson-databind: polymorphic typing issue when enabling default typing for an externally exposed JSON endpoint and having apache-log4j-extra in the classpath leads to code execution (CVE-2019-17531) For more details about the security issue(s), including theimpact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1775293 - CVE-2019-17531 jackson-databind: polymorphic typing issue when enabling default typing for an externally exposed JSON endpoint and having apache-log4j-extra in the classpath leads to code execution 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-maven35-jackson-databind-2.7.6-2.8.el7.src.rpm noarch: rh-maven35-jackson-databind-2.7.6-2.8.el7.noarch.rpm rh-maven35-jackson-databind-javadoc-2.7.6-2.8.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-maven35-jackson-databind-2.7.6-2.8.el7.src.rpm noarch: rh-maven35-jackson-databind-2.7.6-2.8.el7.noarch.rpm rh-maven35-jackson-databind-javadoc-2.7.6-2.8.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5): Source: rh-maven35-jackson-databind-2.7.6-2.8.el7.src.rpm noarch: rh-maven35-jackson-databind-2.7.6-2.8.el7.noarch.rpm rh-maven35-jackson-databind-javadoc-2.7.6-2.8.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6): Source: rh-maven35-jackson-databind-2.7.6-2.8.el7.src.rpm noarch: rh-maven35-jackson-databind-2.7.6-2.8.el7.noarch.rpm rh-maven35-jackson-databind-javadoc-2.7.6-2.8.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7): Source: rh-maven35-jackson-databind-2.7.6-2.8.el7.src.rpm noarch: rh-maven35-jackson-databind-2.7.6-2.8.el7.noarch.rpm rh-maven35-jackson-databind-javadoc-2.7.6-2.8.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v.7): Source: rh-maven35-jackson-databind-2.7.6-2.8.el7.src.rpm noarch: rh-maven35-jackson-databind-2.7.6-2.8.el7.noarch.rpm rh-maven35-jackson-databind-javadoc-2.7.6-2.8.el7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-17531 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXe/EE9zjgjWX9erEAQjbSg/9Es7Ynk7fnzJ/nItJnbVu/cTlY8lczJuv liyhQ0a2uUPbeO7zcEibUnPjZ+asqkUO8Jv524iyIOoi/eBhqAhh2vvLUif73xg+ qbd/7viSBQDt45pb/M0bniSXP4EfSPMEq1xJYLl7yckCzhMakDFxJ9Yd2QjcCsiT 8fDPZR2GdYRyyB0nhUK2Emjhn5+yBwGjUBRpla3uxNJTd/ByFGHm7M0GNOvKSiXR gjAGrum1a6CqTNBdB420s9c/rt+KQp5dKGUo8YVCCW8Y4wJ0irt5aD8MUNvjJOrX Ds0PvGUEmZqwmARyBW2yHOJah9JaEY/v55wHXp30lxFgcb4T3WktHrpUVzYgVKdk qO1Ajpgr14kkTXMLlPWtGpt9Hy+dA1s/1rfCp4skIHJT9ofyuWVyBGKiFBY5hj04 GMMLm4LU7cxOGlIw7/361eFdc8fCBVt3NM2H+Lpm69rpXFVhek/1unN7NeCFNCfS NAgqyd6zF56Q9mY26T1brxWj1voemUgVPk7M+cV0fycDp8rPC62rRRQb59b8lnEl lhx12iA3PZnrp0vPJMiNOk1ge3eD+Bzm/Z3HESRg2b33ti7TK7S9ox3JtdsTAaOO Fg3iEiZfA2C5MX3x0+VR2FVh+yWzDDx4ziIAAGQGo96sDxCs0kyXFRoe4LohLxQu 8T9ef7CVfqQ=yBJc -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover critical safety enhancements for rh-maven35-jackson-databind in Red Hat Software Collections that are vital for your awareness.. red hat, jackson-databind, security update, important advisory, code execution. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 10, 2019 Important Red Hat
98

RedHat: RHSA-2019-3299-01 Critical: rh-php72-php Security Update

An update for rh-php72-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Critical: rh-php72-php security update Advisory ID: RHSA-2019:3299-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2019:3299 Issue date: 2019-11-01 CVE Names: CVE-2016-10166 CVE-2018-20783 CVE-2019-6977 CVE-2019-9020 CVE-2019-9021 CVE-2019-9022 CVE-2019-9023 CVE-2019-9024 CVE-2019-9637 CVE-2019-9638 CVE-2019-9639 CVE-2019-9640 CVE-2019-11034 CVE-2019-11035 CVE-2019-11036 CVE-2019-11038 CVE-2019-11039 CVE-2019-11040 CVE-2019-11041 CVE-2019-11042 CVE-2019-11043 ==================================================================== 1. Summary: An update for rh-php72-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64le, s390x, x86_64 Red Hat Software Collections for Red HatEnterprise Linux Workstation (v. 7) - x86_64 3. Description: PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. The following packages have been upgraded to a later upstream version: rh-php72-php (7.2.24). (BZ#1766603) Security Fix(es): * php: underflow in env_path_info in fpm_main.c (CVE-2019-11043) * gd: Unsigned integer underflow _gdContributionsAlloc() (CVE-2016-10166) * gd: Heap based buffer overflow in gdImageColorMatch() in gd_color_match.c (CVE-2019-6977) * php: Invalid memory access in function xmlrpc_decode() (CVE-2019-9020) * php: File rename across filesystems may allow unwanted access during processing (CVE-2019-9637) * php: Uninitialized read in exif_process_IFD_in_MAKERNOTE (CVE-2019-9638) * php: Uninitialized read in exif_process_IFD_in_MAKERNOTE (CVE-2019-9639) * php: Invalid read in exif_process_SOFn() (CVE-2019-9640) * php: Out-of-bounds read due to integer overflow in iconv_mime_decode_headers() (CVE-2019-11039) * php: Buffer over-read in exif_read_data() (CVE-2019-11040) * php: Buffer over-read in PHAR reading functions (CVE-2018-20783) * php: Heap-based buffer over-read in PHAR reading functions (CVE-2019-9021) * php: memcpy with negative length via crafted DNS response (CVE-2019-9022) * php: Heap-based buffer over-read in mbstring regular expression functions (CVE-2019-9023) * php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c (CVE-2019-9024) * php: Heap buffer overflow in function exif_process_IFD_TAG() (CVE-2019-11034) * php: Heap buffer overflow in function exif_iif_add_value() (CVE-2019-11035) * php: Buffer over-read in exif_process_IFD_TAG() leading to information disclosure (CVE-2019-11036) * gd: Information disclosure in gdImageCreateFromXbm() (CVE-2019-11038) * php: heap buffer over-read in exif_scan_thumbnail() (CVE-2019-11041) * php: heap buffer over-read in exif_process_user_comment() (CVE-2019-11042) For more details aboutthe security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon must be restarted for the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1418983 - CVE-2016-10166 gd: Unsigned integer underflow _gdContributionsAlloc() 1672207 - CVE-2019-6977 gd: Heap based buffer overflow in gdImageColorMatch() in gd_color_match.c 1680545 - CVE-2018-20783 php: Buffer over-read in PHAR reading functions 1685123 - CVE-2019-9020 php: Invalid memory access in function xmlrpc_decode() 1685132 - CVE-2019-9021 php: Heap-based buffer over-read in PHAR reading functions 1685398 - CVE-2019-9023 php: Heap-based buffer over-read in mbstring regular expression functions 1685404 - CVE-2019-9024 php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c 1685412 - CVE-2019-9022 php: memcpy with negative length via crafted DNS response 1688897 - CVE-2019-9637 php: File rename across filesystems may allow unwanted access during processing 1688922 - CVE-2019-9638 php: Uninitialized read in exif_process_IFD_in_MAKERNOTE 1688934 - CVE-2019-9639 php: Uninitialized read in exif_process_IFD_in_MAKERNOTE 1688939 - CVE-2019-9640 php: Invalid read in exif_process_SOFn() 1702246 - CVE-2019-11035 php: Heap buffer overflow in function exif_iif_add_value() 1702256 - CVE-2019-11034 php: Heap buffer overflow in function exif_process_IFD_TAG() 1707299 - CVE-2019-11036 php: Buffer over-read in exif_process_IFD_TAG() leading to information disclosure 1724149 - CVE-2019-11038 gd: Information disclosure in gdImageCreateFromXbm() 1724152 - CVE-2019-11039 php: Out-of-bounds read due to integer overflow in iconv_mime_decode_headers() 1724154 - CVE-2019-11040 php: Bufferover-read in exif_read_data() 1739459 - CVE-2019-11041 php: heap buffer over-read in exif_scan_thumbnail() 1739465 - CVE-2019-11042 php: heap buffer over-read in exif_process_user_comment() 1766378 - CVE-2019-11043 php: underflow in env_path_info in fpm_main.c 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-php72-php-7.2.24-1.el7.src.rpm aarch64: rh-php72-php-7.2.24-1.el7.aarch64.rpm rh-php72-php-bcmath-7.2.24-1.el7.aarch64.rpm rh-php72-php-cli-7.2.24-1.el7.aarch64.rpm rh-php72-php-common-7.2.24-1.el7.aarch64.rpm rh-php72-php-dba-7.2.24-1.el7.aarch64.rpm rh-php72-php-dbg-7.2.24-1.el7.aarch64.rpm rh-php72-php-debuginfo-7.2.24-1.el7.aarch64.rpm rh-php72-php-devel-7.2.24-1.el7.aarch64.rpm rh-php72-php-embedded-7.2.24-1.el7.aarch64.rpm rh-php72-php-enchant-7.2.24-1.el7.aarch64.rpm rh-php72-php-fpm-7.2.24-1.el7.aarch64.rpm rh-php72-php-gd-7.2.24-1.el7.aarch64.rpm rh-php72-php-gmp-7.2.24-1.el7.aarch64.rpm rh-php72-php-intl-7.2.24-1.el7.aarch64.rpm rh-php72-php-json-7.2.24-1.el7.aarch64.rpm rh-php72-php-ldap-7.2.24-1.el7.aarch64.rpm rh-php72-php-mbstring-7.2.24-1.el7.aarch64.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.aarch64.rpm rh-php72-php-odbc-7.2.24-1.el7.aarch64.rpm rh-php72-php-opcache-7.2.24-1.el7.aarch64.rpm rh-php72-php-pdo-7.2.24-1.el7.aarch64.rpm rh-php72-php-pgsql-7.2.24-1.el7.aarch64.rpm rh-php72-php-process-7.2.24-1.el7.aarch64.rpm rh-php72-php-pspell-7.2.24-1.el7.aarch64.rpm rh-php72-php-recode-7.2.24-1.el7.aarch64.rpm rh-php72-php-snmp-7.2.24-1.el7.aarch64.rpm rh-php72-php-soap-7.2.24-1.el7.aarch64.rpm rh-php72-php-xml-7.2.24-1.el7.aarch64.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.aarch64.rpm rh-php72-php-zip-7.2.24-1.el7.aarch64.rpm ppc64le: rh-php72-php-7.2.24-1.el7.ppc64le.rpm rh-php72-php-bcmath-7.2.24-1.el7.ppc64le.rpm rh-php72-php-cli-7.2.24-1.el7.ppc64le.rpm rh-php72-php-common-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dba-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dbg-7.2.24-1.el7.ppc64le.rpm rh-php72-php-debuginfo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-devel-7.2.24-1.el7.ppc64le.rpm rh-php72-php-embedded-7.2.24-1.el7.ppc64le.rpm rh-php72-php-enchant-7.2.24-1.el7.ppc64le.rpm rh-php72-php-fpm-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-intl-7.2.24-1.el7.ppc64le.rpm rh-php72-php-json-7.2.24-1.el7.ppc64le.rpm rh-php72-php-ldap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mbstring-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-odbc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-opcache-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pdo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pgsql-7.2.24-1.el7.ppc64le.rpm rh-php72-php-process-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pspell-7.2.24-1.el7.ppc64le.rpm rh-php72-php-recode-7.2.24-1.el7.ppc64le.rpm rh-php72-php-snmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-soap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xml-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-zip-7.2.24-1.el7.ppc64le.rpm s390x: rh-php72-php-7.2.24-1.el7.s390x.rpm rh-php72-php-bcmath-7.2.24-1.el7.s390x.rpm rh-php72-php-cli-7.2.24-1.el7.s390x.rpm rh-php72-php-common-7.2.24-1.el7.s390x.rpm rh-php72-php-dba-7.2.24-1.el7.s390x.rpm rh-php72-php-dbg-7.2.24-1.el7.s390x.rpm rh-php72-php-debuginfo-7.2.24-1.el7.s390x.rpm rh-php72-php-devel-7.2.24-1.el7.s390x.rpm rh-php72-php-embedded-7.2.24-1.el7.s390x.rpm rh-php72-php-enchant-7.2.24-1.el7.s390x.rpm rh-php72-php-fpm-7.2.24-1.el7.s390x.rpm rh-php72-php-gd-7.2.24-1.el7.s390x.rpm rh-php72-php-gmp-7.2.24-1.el7.s390x.rpm rh-php72-php-intl-7.2.24-1.el7.s390x.rpm rh-php72-php-json-7.2.24-1.el7.s390x.rpm rh-php72-php-ldap-7.2.24-1.el7.s390x.rpm rh-php72-php-mbstring-7.2.24-1.el7.s390x.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.s390x.rpm rh-php72-php-odbc-7.2.24-1.el7.s390x.rpm rh-php72-php-opcache-7.2.24-1.el7.s390x.rpm rh-php72-php-pdo-7.2.24-1.el7.s390x.rpm rh-php72-php-pgsql-7.2.24-1.el7.s390x.rpm rh-php72-php-process-7.2.24-1.el7.s390x.rpm rh-php72-php-pspell-7.2.24-1.el7.s390x.rpm rh-php72-php-recode-7.2.24-1.el7.s390x.rpm rh-php72-php-snmp-7.2.24-1.el7.s390x.rpm rh-php72-php-soap-7.2.24-1.el7.s390x.rpm rh-php72-php-xml-7.2.24-1.el7.s390x.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.s390x.rpm rh-php72-php-zip-7.2.24-1.el7.s390x.rpm Red Hat Software Collections for Red HatEnterprise Linux Server (v.7): Source: rh-php72-php-7.2.24-1.el7.src.rpm aarch64: rh-php72-php-7.2.24-1.el7.aarch64.rpm rh-php72-php-bcmath-7.2.24-1.el7.aarch64.rpm rh-php72-php-cli-7.2.24-1.el7.aarch64.rpm rh-php72-php-common-7.2.24-1.el7.aarch64.rpm rh-php72-php-dba-7.2.24-1.el7.aarch64.rpm rh-php72-php-dbg-7.2.24-1.el7.aarch64.rpm rh-php72-php-debuginfo-7.2.24-1.el7.aarch64.rpm rh-php72-php-devel-7.2.24-1.el7.aarch64.rpm rh-php72-php-embedded-7.2.24-1.el7.aarch64.rpm rh-php72-php-enchant-7.2.24-1.el7.aarch64.rpm rh-php72-php-fpm-7.2.24-1.el7.aarch64.rpm rh-php72-php-gd-7.2.24-1.el7.aarch64.rpm rh-php72-php-gmp-7.2.24-1.el7.aarch64.rpm rh-php72-php-intl-7.2.24-1.el7.aarch64.rpm rh-php72-php-json-7.2.24-1.el7.aarch64.rpm rh-php72-php-ldap-7.2.24-1.el7.aarch64.rpm rh-php72-php-mbstring-7.2.24-1.el7.aarch64.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.aarch64.rpm rh-php72-php-odbc-7.2.24-1.el7.aarch64.rpm rh-php72-php-opcache-7.2.24-1.el7.aarch64.rpm rh-php72-php-pdo-7.2.24-1.el7.aarch64.rpm rh-php72-php-pgsql-7.2.24-1.el7.aarch64.rpm rh-php72-php-process-7.2.24-1.el7.aarch64.rpm rh-php72-php-pspell-7.2.24-1.el7.aarch64.rpm rh-php72-php-recode-7.2.24-1.el7.aarch64.rpm rh-php72-php-snmp-7.2.24-1.el7.aarch64.rpm rh-php72-php-soap-7.2.24-1.el7.aarch64.rpm rh-php72-php-xml-7.2.24-1.el7.aarch64.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.aarch64.rpm rh-php72-php-zip-7.2.24-1.el7.aarch64.rpm ppc64le: rh-php72-php-7.2.24-1.el7.ppc64le.rpm rh-php72-php-bcmath-7.2.24-1.el7.ppc64le.rpm rh-php72-php-cli-7.2.24-1.el7.ppc64le.rpm rh-php72-php-common-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dba-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dbg-7.2.24-1.el7.ppc64le.rpm rh-php72-php-debuginfo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-devel-7.2.24-1.el7.ppc64le.rpm rh-php72-php-embedded-7.2.24-1.el7.ppc64le.rpm rh-php72-php-enchant-7.2.24-1.el7.ppc64le.rpm rh-php72-php-fpm-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-intl-7.2.24-1.el7.ppc64le.rpm rh-php72-php-json-7.2.24-1.el7.ppc64le.rpm rh-php72-php-ldap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mbstring-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-odbc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-opcache-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pdo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pgsql-7.2.24-1.el7.ppc64le.rpm rh-php72-php-process-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pspell-7.2.24-1.el7.ppc64le.rpm rh-php72-php-recode-7.2.24-1.el7.ppc64le.rpm rh-php72-php-snmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-soap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xml-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-zip-7.2.24-1.el7.ppc64le.rpm s390x: rh-php72-php-7.2.24-1.el7.s390x.rpm rh-php72-php-bcmath-7.2.24-1.el7.s390x.rpm rh-php72-php-cli-7.2.24-1.el7.s390x.rpm rh-php72-php-common-7.2.24-1.el7.s390x.rpm rh-php72-php-dba-7.2.24-1.el7.s390x.rpm rh-php72-php-dbg-7.2.24-1.el7.s390x.rpm rh-php72-php-debuginfo-7.2.24-1.el7.s390x.rpm rh-php72-php-devel-7.2.24-1.el7.s390x.rpm rh-php72-php-embedded-7.2.24-1.el7.s390x.rpm rh-php72-php-enchant-7.2.24-1.el7.s390x.rpm rh-php72-php-fpm-7.2.24-1.el7.s390x.rpm rh-php72-php-gd-7.2.24-1.el7.s390x.rpm rh-php72-php-gmp-7.2.24-1.el7.s390x.rpm rh-php72-php-intl-7.2.24-1.el7.s390x.rpm rh-php72-php-json-7.2.24-1.el7.s390x.rpm rh-php72-php-ldap-7.2.24-1.el7.s390x.rpm rh-php72-php-mbstring-7.2.24-1.el7.s390x.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.s390x.rpm rh-php72-php-odbc-7.2.24-1.el7.s390x.rpm rh-php72-php-opcache-7.2.24-1.el7.s390x.rpm rh-php72-php-pdo-7.2.24-1.el7.s390x.rpm rh-php72-php-pgsql-7.2.24-1.el7.s390x.rpm rh-php72-php-process-7.2.24-1.el7.s390x.rpm rh-php72-php-pspell-7.2.24-1.el7.s390x.rpm rh-php72-php-recode-7.2.24-1.el7.s390x.rpm rh-php72-php-snmp-7.2.24-1.el7.s390x.rpm rh-php72-php-soap-7.2.24-1.el7.s390x.rpm rh-php72-php-xml-7.2.24-1.el7.s390x.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.s390x.rpm rh-php72-php-zip-7.2.24-1.el7.s390x.rpm x86_64: rh-php72-php-7.2.24-1.el7.x86_64.rpm rh-php72-php-bcmath-7.2.24-1.el7.x86_64.rpm rh-php72-php-cli-7.2.24-1.el7.x86_64.rpm rh-php72-php-common-7.2.24-1.el7.x86_64.rpm rh-php72-php-dba-7.2.24-1.el7.x86_64.rpm rh-php72-php-dbg-7.2.24-1.el7.x86_64.rpm rh-php72-php-debuginfo-7.2.24-1.el7.x86_64.rpm rh-php72-php-devel-7.2.24-1.el7.x86_64.rpm rh-php72-php-embedded-7.2.24-1.el7.x86_64.rpm rh-php72-php-enchant-7.2.24-1.el7.x86_64.rpm rh-php72-php-fpm-7.2.24-1.el7.x86_64.rpm rh-php72-php-gd-7.2.24-1.el7.x86_64.rpm rh-php72-php-gmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-intl-7.2.24-1.el7.x86_64.rpm rh-php72-php-json-7.2.24-1.el7.x86_64.rpm rh-php72-php-ldap-7.2.24-1.el7.x86_64.rpm rh-php72-php-mbstring-7.2.24-1.el7.x86_64.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.x86_64.rpm rh-php72-php-odbc-7.2.24-1.el7.x86_64.rpm rh-php72-php-opcache-7.2.24-1.el7.x86_64.rpm rh-php72-php-pdo-7.2.24-1.el7.x86_64.rpm rh-php72-php-pgsql-7.2.24-1.el7.x86_64.rpm rh-php72-php-process-7.2.24-1.el7.x86_64.rpm rh-php72-php-pspell-7.2.24-1.el7.x86_64.rpm rh-php72-php-recode-7.2.24-1.el7.x86_64.rpm rh-php72-php-snmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-soap-7.2.24-1.el7.x86_64.rpm rh-php72-php-xml-7.2.24-1.el7.x86_64.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.x86_64.rpm rh-php72-php-zip-7.2.24-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.5): Source: rh-php72-php-7.2.24-1.el7.src.rpm ppc64le: rh-php72-php-7.2.24-1.el7.ppc64le.rpm rh-php72-php-bcmath-7.2.24-1.el7.ppc64le.rpm rh-php72-php-cli-7.2.24-1.el7.ppc64le.rpm rh-php72-php-common-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dba-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dbg-7.2.24-1.el7.ppc64le.rpm rh-php72-php-debuginfo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-devel-7.2.24-1.el7.ppc64le.rpm rh-php72-php-embedded-7.2.24-1.el7.ppc64le.rpm rh-php72-php-enchant-7.2.24-1.el7.ppc64le.rpm rh-php72-php-fpm-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-intl-7.2.24-1.el7.ppc64le.rpm rh-php72-php-json-7.2.24-1.el7.ppc64le.rpm rh-php72-php-ldap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mbstring-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-odbc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-opcache-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pdo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pgsql-7.2.24-1.el7.ppc64le.rpm rh-php72-php-process-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pspell-7.2.24-1.el7.ppc64le.rpm rh-php72-php-recode-7.2.24-1.el7.ppc64le.rpm rh-php72-php-snmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-soap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xml-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-zip-7.2.24-1.el7.ppc64le.rpm s390x: rh-php72-php-7.2.24-1.el7.s390x.rpm rh-php72-php-bcmath-7.2.24-1.el7.s390x.rpm rh-php72-php-cli-7.2.24-1.el7.s390x.rpm rh-php72-php-common-7.2.24-1.el7.s390x.rpm rh-php72-php-dba-7.2.24-1.el7.s390x.rpm rh-php72-php-dbg-7.2.24-1.el7.s390x.rpm rh-php72-php-debuginfo-7.2.24-1.el7.s390x.rpm rh-php72-php-devel-7.2.24-1.el7.s390x.rpm rh-php72-php-embedded-7.2.24-1.el7.s390x.rpm rh-php72-php-enchant-7.2.24-1.el7.s390x.rpm rh-php72-php-fpm-7.2.24-1.el7.s390x.rpm rh-php72-php-gd-7.2.24-1.el7.s390x.rpm rh-php72-php-gmp-7.2.24-1.el7.s390x.rpm rh-php72-php-intl-7.2.24-1.el7.s390x.rpm rh-php72-php-json-7.2.24-1.el7.s390x.rpm rh-php72-php-ldap-7.2.24-1.el7.s390x.rpm rh-php72-php-mbstring-7.2.24-1.el7.s390x.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.s390x.rpm rh-php72-php-odbc-7.2.24-1.el7.s390x.rpm rh-php72-php-opcache-7.2.24-1.el7.s390x.rpm rh-php72-php-pdo-7.2.24-1.el7.s390x.rpm rh-php72-php-pgsql-7.2.24-1.el7.s390x.rpm rh-php72-php-process-7.2.24-1.el7.s390x.rpm rh-php72-php-pspell-7.2.24-1.el7.s390x.rpm rh-php72-php-recode-7.2.24-1.el7.s390x.rpm rh-php72-php-snmp-7.2.24-1.el7.s390x.rpm rh-php72-php-soap-7.2.24-1.el7.s390x.rpm rh-php72-php-xml-7.2.24-1.el7.s390x.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.s390x.rpm rh-php72-php-zip-7.2.24-1.el7.s390x.rpm x86_64: rh-php72-php-7.2.24-1.el7.x86_64.rpm rh-php72-php-bcmath-7.2.24-1.el7.x86_64.rpm rh-php72-php-cli-7.2.24-1.el7.x86_64.rpm rh-php72-php-common-7.2.24-1.el7.x86_64.rpm rh-php72-php-dba-7.2.24-1.el7.x86_64.rpm rh-php72-php-dbg-7.2.24-1.el7.x86_64.rpm rh-php72-php-debuginfo-7.2.24-1.el7.x86_64.rpm rh-php72-php-devel-7.2.24-1.el7.x86_64.rpm rh-php72-php-embedded-7.2.24-1.el7.x86_64.rpm rh-php72-php-enchant-7.2.24-1.el7.x86_64.rpm rh-php72-php-fpm-7.2.24-1.el7.x86_64.rpm rh-php72-php-gd-7.2.24-1.el7.x86_64.rpm rh-php72-php-gmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-intl-7.2.24-1.el7.x86_64.rpm rh-php72-php-json-7.2.24-1.el7.x86_64.rpm rh-php72-php-ldap-7.2.24-1.el7.x86_64.rpm rh-php72-php-mbstring-7.2.24-1.el7.x86_64.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.x86_64.rpm rh-php72-php-odbc-7.2.24-1.el7.x86_64.rpm rh-php72-php-opcache-7.2.24-1.el7.x86_64.rpm rh-php72-php-pdo-7.2.24-1.el7.x86_64.rpm rh-php72-php-pgsql-7.2.24-1.el7.x86_64.rpm rh-php72-php-process-7.2.24-1.el7.x86_64.rpm rh-php72-php-pspell-7.2.24-1.el7.x86_64.rpm rh-php72-php-recode-7.2.24-1.el7.x86_64.rpm rh-php72-php-snmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-soap-7.2.24-1.el7.x86_64.rpm rh-php72-php-xml-7.2.24-1.el7.x86_64.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.x86_64.rpm rh-php72-php-zip-7.2.24-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS(v.7.6): Source: rh-php72-php-7.2.24-1.el7.src.rpm ppc64le: rh-php72-php-7.2.24-1.el7.ppc64le.rpm rh-php72-php-bcmath-7.2.24-1.el7.ppc64le.rpm rh-php72-php-cli-7.2.24-1.el7.ppc64le.rpm rh-php72-php-common-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dba-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dbg-7.2.24-1.el7.ppc64le.rpm rh-php72-php-debuginfo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-devel-7.2.24-1.el7.ppc64le.rpm rh-php72-php-embedded-7.2.24-1.el7.ppc64le.rpm rh-php72-php-enchant-7.2.24-1.el7.ppc64le.rpm rh-php72-php-fpm-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-intl-7.2.24-1.el7.ppc64le.rpm rh-php72-php-json-7.2.24-1.el7.ppc64le.rpm rh-php72-php-ldap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mbstring-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-odbc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-opcache-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pdo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pgsql-7.2.24-1.el7.ppc64le.rpm rh-php72-php-process-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pspell-7.2.24-1.el7.ppc64le.rpm rh-php72-php-recode-7.2.24-1.el7.ppc64le.rpm rh-php72-php-snmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-soap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xml-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-zip-7.2.24-1.el7.ppc64le.rpm s390x: rh-php72-php-7.2.24-1.el7.s390x.rpm rh-php72-php-bcmath-7.2.24-1.el7.s390x.rpm rh-php72-php-cli-7.2.24-1.el7.s390x.rpm rh-php72-php-common-7.2.24-1.el7.s390x.rpm rh-php72-php-dba-7.2.24-1.el7.s390x.rpm rh-php72-php-dbg-7.2.24-1.el7.s390x.rpm rh-php72-php-debuginfo-7.2.24-1.el7.s390x.rpm rh-php72-php-devel-7.2.24-1.el7.s390x.rpm rh-php72-php-embedded-7.2.24-1.el7.s390x.rpm rh-php72-php-enchant-7.2.24-1.el7.s390x.rpm rh-php72-php-fpm-7.2.24-1.el7.s390x.rpm rh-php72-php-gd-7.2.24-1.el7.s390x.rpm rh-php72-php-gmp-7.2.24-1.el7.s390x.rpm rh-php72-php-intl-7.2.24-1.el7.s390x.rpm rh-php72-php-json-7.2.24-1.el7.s390x.rpm rh-php72-php-ldap-7.2.24-1.el7.s390x.rpm rh-php72-php-mbstring-7.2.24-1.el7.s390x.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.s390x.rpm rh-php72-php-odbc-7.2.24-1.el7.s390x.rpm rh-php72-php-opcache-7.2.24-1.el7.s390x.rpm rh-php72-php-pdo-7.2.24-1.el7.s390x.rpm rh-php72-php-pgsql-7.2.24-1.el7.s390x.rpm rh-php72-php-process-7.2.24-1.el7.s390x.rpm rh-php72-php-pspell-7.2.24-1.el7.s390x.rpm rh-php72-php-recode-7.2.24-1.el7.s390x.rpm rh-php72-php-snmp-7.2.24-1.el7.s390x.rpm rh-php72-php-soap-7.2.24-1.el7.s390x.rpm rh-php72-php-xml-7.2.24-1.el7.s390x.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.s390x.rpm rh-php72-php-zip-7.2.24-1.el7.s390x.rpm x86_64: rh-php72-php-7.2.24-1.el7.x86_64.rpm rh-php72-php-bcmath-7.2.24-1.el7.x86_64.rpm rh-php72-php-cli-7.2.24-1.el7.x86_64.rpm rh-php72-php-common-7.2.24-1.el7.x86_64.rpm rh-php72-php-dba-7.2.24-1.el7.x86_64.rpm rh-php72-php-dbg-7.2.24-1.el7.x86_64.rpm rh-php72-php-debuginfo-7.2.24-1.el7.x86_64.rpm rh-php72-php-devel-7.2.24-1.el7.x86_64.rpm rh-php72-php-embedded-7.2.24-1.el7.x86_64.rpm rh-php72-php-enchant-7.2.24-1.el7.x86_64.rpm rh-php72-php-fpm-7.2.24-1.el7.x86_64.rpm rh-php72-php-gd-7.2.24-1.el7.x86_64.rpm rh-php72-php-gmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-intl-7.2.24-1.el7.x86_64.rpm rh-php72-php-json-7.2.24-1.el7.x86_64.rpm rh-php72-php-ldap-7.2.24-1.el7.x86_64.rpm rh-php72-php-mbstring-7.2.24-1.el7.x86_64.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.x86_64.rpm rh-php72-php-odbc-7.2.24-1.el7.x86_64.rpm rh-php72-php-opcache-7.2.24-1.el7.x86_64.rpm rh-php72-php-pdo-7.2.24-1.el7.x86_64.rpm rh-php72-php-pgsql-7.2.24-1.el7.x86_64.rpm rh-php72-php-process-7.2.24-1.el7.x86_64.rpm rh-php72-php-pspell-7.2.24-1.el7.x86_64.rpm rh-php72-php-recode-7.2.24-1.el7.x86_64.rpm rh-php72-php-snmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-soap-7.2.24-1.el7.x86_64.rpm rh-php72-php-xml-7.2.24-1.el7.x86_64.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.x86_64.rpm rh-php72-php-zip-7.2.24-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS(v.7.7): Source: rh-php72-php-7.2.24-1.el7.src.rpm ppc64le: rh-php72-php-7.2.24-1.el7.ppc64le.rpm rh-php72-php-bcmath-7.2.24-1.el7.ppc64le.rpm rh-php72-php-cli-7.2.24-1.el7.ppc64le.rpm rh-php72-php-common-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dba-7.2.24-1.el7.ppc64le.rpm rh-php72-php-dbg-7.2.24-1.el7.ppc64le.rpm rh-php72-php-debuginfo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-devel-7.2.24-1.el7.ppc64le.rpm rh-php72-php-embedded-7.2.24-1.el7.ppc64le.rpm rh-php72-php-enchant-7.2.24-1.el7.ppc64le.rpm rh-php72-php-fpm-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-gmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-intl-7.2.24-1.el7.ppc64le.rpm rh-php72-php-json-7.2.24-1.el7.ppc64le.rpm rh-php72-php-ldap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mbstring-7.2.24-1.el7.ppc64le.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.ppc64le.rpm rh-php72-php-odbc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-opcache-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pdo-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pgsql-7.2.24-1.el7.ppc64le.rpm rh-php72-php-process-7.2.24-1.el7.ppc64le.rpm rh-php72-php-pspell-7.2.24-1.el7.ppc64le.rpm rh-php72-php-recode-7.2.24-1.el7.ppc64le.rpm rh-php72-php-snmp-7.2.24-1.el7.ppc64le.rpm rh-php72-php-soap-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xml-7.2.24-1.el7.ppc64le.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.ppc64le.rpm rh-php72-php-zip-7.2.24-1.el7.ppc64le.rpm s390x: rh-php72-php-7.2.24-1.el7.s390x.rpm rh-php72-php-bcmath-7.2.24-1.el7.s390x.rpm rh-php72-php-cli-7.2.24-1.el7.s390x.rpm rh-php72-php-common-7.2.24-1.el7.s390x.rpm rh-php72-php-dba-7.2.24-1.el7.s390x.rpm rh-php72-php-dbg-7.2.24-1.el7.s390x.rpm rh-php72-php-debuginfo-7.2.24-1.el7.s390x.rpm rh-php72-php-devel-7.2.24-1.el7.s390x.rpm rh-php72-php-embedded-7.2.24-1.el7.s390x.rpm rh-php72-php-enchant-7.2.24-1.el7.s390x.rpm rh-php72-php-fpm-7.2.24-1.el7.s390x.rpm rh-php72-php-gd-7.2.24-1.el7.s390x.rpm rh-php72-php-gmp-7.2.24-1.el7.s390x.rpm rh-php72-php-intl-7.2.24-1.el7.s390x.rpm rh-php72-php-json-7.2.24-1.el7.s390x.rpm rh-php72-php-ldap-7.2.24-1.el7.s390x.rpm rh-php72-php-mbstring-7.2.24-1.el7.s390x.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.s390x.rpm rh-php72-php-odbc-7.2.24-1.el7.s390x.rpm rh-php72-php-opcache-7.2.24-1.el7.s390x.rpm rh-php72-php-pdo-7.2.24-1.el7.s390x.rpm rh-php72-php-pgsql-7.2.24-1.el7.s390x.rpm rh-php72-php-process-7.2.24-1.el7.s390x.rpm rh-php72-php-pspell-7.2.24-1.el7.s390x.rpm rh-php72-php-recode-7.2.24-1.el7.s390x.rpm rh-php72-php-snmp-7.2.24-1.el7.s390x.rpm rh-php72-php-soap-7.2.24-1.el7.s390x.rpm rh-php72-php-xml-7.2.24-1.el7.s390x.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.s390x.rpm rh-php72-php-zip-7.2.24-1.el7.s390x.rpm x86_64: rh-php72-php-7.2.24-1.el7.x86_64.rpm rh-php72-php-bcmath-7.2.24-1.el7.x86_64.rpm rh-php72-php-cli-7.2.24-1.el7.x86_64.rpm rh-php72-php-common-7.2.24-1.el7.x86_64.rpm rh-php72-php-dba-7.2.24-1.el7.x86_64.rpm rh-php72-php-dbg-7.2.24-1.el7.x86_64.rpm rh-php72-php-debuginfo-7.2.24-1.el7.x86_64.rpm rh-php72-php-devel-7.2.24-1.el7.x86_64.rpm rh-php72-php-embedded-7.2.24-1.el7.x86_64.rpm rh-php72-php-enchant-7.2.24-1.el7.x86_64.rpm rh-php72-php-fpm-7.2.24-1.el7.x86_64.rpm rh-php72-php-gd-7.2.24-1.el7.x86_64.rpm rh-php72-php-gmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-intl-7.2.24-1.el7.x86_64.rpm rh-php72-php-json-7.2.24-1.el7.x86_64.rpm rh-php72-php-ldap-7.2.24-1.el7.x86_64.rpm rh-php72-php-mbstring-7.2.24-1.el7.x86_64.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.x86_64.rpm rh-php72-php-odbc-7.2.24-1.el7.x86_64.rpm rh-php72-php-opcache-7.2.24-1.el7.x86_64.rpm rh-php72-php-pdo-7.2.24-1.el7.x86_64.rpm rh-php72-php-pgsql-7.2.24-1.el7.x86_64.rpm rh-php72-php-process-7.2.24-1.el7.x86_64.rpm rh-php72-php-pspell-7.2.24-1.el7.x86_64.rpm rh-php72-php-recode-7.2.24-1.el7.x86_64.rpm rh-php72-php-snmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-soap-7.2.24-1.el7.x86_64.rpm rh-php72-php-xml-7.2.24-1.el7.x86_64.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.x86_64.rpm rh-php72-php-zip-7.2.24-1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation(v. 7): Source: rh-php72-php-7.2.24-1.el7.src.rpm x86_64: rh-php72-php-7.2.24-1.el7.x86_64.rpm rh-php72-php-bcmath-7.2.24-1.el7.x86_64.rpm rh-php72-php-cli-7.2.24-1.el7.x86_64.rpm rh-php72-php-common-7.2.24-1.el7.x86_64.rpm rh-php72-php-dba-7.2.24-1.el7.x86_64.rpm rh-php72-php-dbg-7.2.24-1.el7.x86_64.rpm rh-php72-php-debuginfo-7.2.24-1.el7.x86_64.rpm rh-php72-php-devel-7.2.24-1.el7.x86_64.rpm rh-php72-php-embedded-7.2.24-1.el7.x86_64.rpm rh-php72-php-enchant-7.2.24-1.el7.x86_64.rpm rh-php72-php-fpm-7.2.24-1.el7.x86_64.rpm rh-php72-php-gd-7.2.24-1.el7.x86_64.rpm rh-php72-php-gmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-intl-7.2.24-1.el7.x86_64.rpm rh-php72-php-json-7.2.24-1.el7.x86_64.rpm rh-php72-php-ldap-7.2.24-1.el7.x86_64.rpm rh-php72-php-mbstring-7.2.24-1.el7.x86_64.rpm rh-php72-php-mysqlnd-7.2.24-1.el7.x86_64.rpm rh-php72-php-odbc-7.2.24-1.el7.x86_64.rpm rh-php72-php-opcache-7.2.24-1.el7.x86_64.rpm rh-php72-php-pdo-7.2.24-1.el7.x86_64.rpm rh-php72-php-pgsql-7.2.24-1.el7.x86_64.rpm rh-php72-php-process-7.2.24-1.el7.x86_64.rpm rh-php72-php-pspell-7.2.24-1.el7.x86_64.rpm rh-php72-php-recode-7.2.24-1.el7.x86_64.rpm rh-php72-php-snmp-7.2.24-1.el7.x86_64.rpm rh-php72-php-soap-7.2.24-1.el7.x86_64.rpm rh-php72-php-xml-7.2.24-1.el7.x86_64.rpm rh-php72-php-xmlrpc-7.2.24-1.el7.x86_64.rpm rh-php72-php-zip-7.2.24-1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2016-10166 https://access.redhat.com/security/cve/CVE-2018-20783 https://access.redhat.com/security/cve/CVE-2019-6977 https://access.redhat.com/security/cve/CVE-2019-9020 https://access.redhat.com/security/cve/CVE-2019-9021 https://access.redhat.com/security/cve/CVE-2019-9022 https://access.redhat.com/security/cve/CVE-2019-9023 https://access.redhat.com/security/cve/CVE-2019-9024 https://access.redhat.com/security/cve/CVE-2019-9637 https://access.redhat.com/security/cve/CVE-2019-9638 https://access.redhat.com/security/cve/CVE-2019-9639 https://access.redhat.com/security/cve/CVE-2019-9640 https://access.redhat.com/security/cve/CVE-2019-11034 https://access.redhat.com/security/cve/CVE-2019-11035 https://access.redhat.com/security/cve/CVE-2019-11036 https://access.redhat.com/security/cve/CVE-2019-11038 https://access.redhat.com/security/cve/CVE-2019-11039 https://access.redhat.com/security/cve/CVE-2019-11040 https://access.redhat.com/security/cve/CVE-2019-11041 https://access.redhat.com/security/cve/CVE-2019-11042 https://access.redhat.com/security/cve/CVE-2019-11043 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPGv1 iQIVAwUBXbwslNzjgjWX9erEAQgZrA//YpBwARJTytrbpWQquZ4hnjbScNEZK1d4 sOOT+oiQSrzvghsNKNCKwEO1CLbNA9XOT7bCchtpD/HguTc4XeGNk7dAf/qA6UVB tJCxmqNBVBKqoe9UafmxLUFcVSkv/PHRVD2h+/TvmqdB8Uf2Z8hIIaBt7UsW34sb yBMLJVhyG98c/7VzwqFXW6Vm+Ly6+/ViYtloe5/Ex4D8FvB72Cc9uRvCTWdLLOXu PlwQKdaEt5CtUrTmLFEX+9t6tybwhNBf/dZ96nazCaSRtQVnhZI9s+wjoE6vEOOB +bOldvJ9tu7LclzMIz7SbSqjhPBSLtEMGZKcO1havVGDwcfPAEc12TW9DtVFDlqA Xq+dFW5vviRCoMlSmNBmSqQZSWMF64LdzjvWfW2G/nBnNLOdhu/Wufs1sJUOc+cp V9PgQH0iWut0N89DaOzTH+4PQvvvTw12HuKHk+P+/O8bBBdcI9gpd5klce/5jquc QXqhy49koz6BturNpVnXfSWjdLPwQ1pwhGJOkv7vLsdx6HVeuY6BsSE+C28cHFl+ z/AOZL4eCa9xKlePdGKCbqzTjMmCiJQbeShoBOKt1DtSgVVgtE0Kc5EZQcqop0aw RG304k1HSbrgsSRFxx6s1RophOQaC3ASvWkw5OY/8ylNrO9AAMxLRjZNCve6V7Rq 86WRMpuQxpE=winR -----END PGP SIGNATURE-------RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Oracle announced an important patch for java-11-openjdk, addressing multiple security flaws in Oracle's OpenJDK distribution.. Red Hat Software Collections, rh-php72-php, security updates, critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 01, 2019 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here