Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
nodejs:18 enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2024:1140","synopsis":"nodejs:18 enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for nodejs-nodemon, nodejs-packaging, module.nodejs-packaging, module.nodejs-nodemon.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Node.js is a software development platform for building fast and scalable\nnetwork applications in the JavaScript programming language.\n\nEnhancement(s):\n\n* nodejs:18\/nodejs: Rebase to latest upstream version (JIRA:Rocky Linux-21438)","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[],"cves":[],"references":[],"publishedAt":"2025-05-07T19:13:09.903227Z","rpms":{"Rocky Linux 9":{"nvras":["nodejs-nodemon-0:3.0.1-1.module+el9.5.0+31785+5534beb0.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el9.5.0+31770+0da7192d.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el9.5.0+31770+0da7192d.src.rpm","nodejs-nodemon-0:3.0.1-1.module+el9.5.0+31785+5534beb0.src.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31786+d18c719d.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31770+0da7192d.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31785+5534beb0.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31785+5534beb0.src.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31786+d18c719d.src.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31770+0da7192d.src.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el9.5.0+31785+5534beb0.noarch.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el9.5.0+31770+0da7192d.noarch.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el9.5.0+31786+d18c719d.noarch.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. An important Node.js update for Rocky Linux 9 has been released, boosting performance and unveiling innovative functionalities.. Rocky Linux, Node.js, enhancementupdate, software development. . LinuxSecurity.com Team
nodejs:18 bug fix and enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2024:0890","synopsis":"nodejs:18 bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for nodejs-nodemon, module.nodejs, nodejs, module.nodejs-nodemon, module.nodejs-packaging, nodejs-packaging.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Node.js is a software development platform for building fast and scalable\nnetwork applications in the JavaScript programming language.\n\nBug Fix(es) and Enhancement(s):\n\n* nodejs:18\/nodejs: Rebase to latest upstream version (JIRA:Rocky Linux-21439)","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[],"cves":[],"references":[],"publishedAt":"2024-03-12T15:42:26.241001Z","rpms":{"Rocky Linux 8":{"nvras":["nodejs-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.src.rpm","nodejs-debuginfo-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-debugsource-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-devel-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-docs-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.noarch.rpm","nodejs-full-i18n-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.8.0+1459+02651ab6.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.8.0+1459+02651ab6.src.rpm","nodejs-packaging-0:2021.06-4.module+el8.7.0+1072+5b168780.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el8.7.0+1072+5b168780.src.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el8.7.0+1072+5b168780.noarch.rpm","npm-1:10.2.3-1.18.19.0.1.module+el8.9.0+1727+17e65eb5.aarch64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Elevate your Rocky Linux 8 environment by incorporating the updated nodejs:18, featuring essential bug resolutions and enhancements to maximizeefficiency.. Rocky Linux Update, Node.js Enhancements, Software Development Platform. . Severity: Critical. LinuxSecurity.com Team
* bsc#1219679 Cross-References: * CVE-2024-0985 . # Security update for postgresql12 Announcement ID: SUSE-SU-2024:0542-1 Rating: important References: * bsc#1219679 Cross-References: * CVE-2024-0985 CVSS scores: * CVE-2024-0985 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2024-0985 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for postgresql12 fixes the following issues: Upgrade to 12.18: * CVE-2024-0985: Tighten security restrictions within REFRESH MATERIALIZED VIEW CONCURRENTLY (bsc#1219679). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-542=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-542=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-542=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-542=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * postgresql12-devel-12.18-3.52.1 * postgresql12-debugsource-12.18-3.52.1 * postgresql12-devel-debuginfo-12.18-3.52.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (ppc64le s390x x86_64) * postgresql12-server-devel-12.18-3.52.1 * postgresql12-server-devel-debuginfo-12.18-3.52.1 * SUSE Linux Enterprise High PerformanceComputing 12 SP5 (aarch64 x86_64) * postgresql12-plpython-12.18-3.52.1 * postgresql12-contrib-12.18-3.52.1 * postgresql12-contrib-debuginfo-12.18-3.52.1 * postgresql12-debugsource-12.18-3.52.1 * postgresql12-server-12.18-3.52.1 * postgresql12-plperl-12.18-3.52.1 * postgresql12-server-debuginfo-12.18-3.52.1 * postgresql12-plperl-debuginfo-12.18-3.52.1 * postgresql12-plpython-debuginfo-12.18-3.52.1 * postgresql12-debuginfo-12.18-3.52.1 * postgresql12-pltcl-debuginfo-12.18-3.52.1 * postgresql12-12.18-3.52.1 * postgresql12-pltcl-12.18-3.52.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * postgresql12-docs-12.18-3.52.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * postgresql12-plpython-12.18-3.52.1 * postgresql12-contrib-12.18-3.52.1 * postgresql12-contrib-debuginfo-12.18-3.52.1 * postgresql12-debugsource-12.18-3.52.1 * postgresql12-server-12.18-3.52.1 * postgresql12-plperl-12.18-3.52.1 * postgresql12-server-debuginfo-12.18-3.52.1 * postgresql12-plperl-debuginfo-12.18-3.52.1 * postgresql12-plpython-debuginfo-12.18-3.52.1 * postgresql12-debuginfo-12.18-3.52.1 * postgresql12-pltcl-debuginfo-12.18-3.52.1 * postgresql12-12.18-3.52.1 * postgresql12-pltcl-12.18-3.52.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * postgresql12-docs-12.18-3.52.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * postgresql12-plpython-12.18-3.52.1 * postgresql12-contrib-12.18-3.52.1 * postgresql12-contrib-debuginfo-12.18-3.52.1 * postgresql12-debugsource-12.18-3.52.1 * postgresql12-server-12.18-3.52.1 * postgresql12-plperl-12.18-3.52.1 * postgresql12-server-debuginfo-12.18-3.52.1 * postgresql12-plperl-debuginfo-12.18-3.52.1 * postgresql12-plpython-debuginfo-12.18-3.52.1 * postgresql12-debuginfo-12.18-3.52.1 * postgresql12-pltcl-debuginfo-12.18-3.52.1 * postgresql12-12.18-3.52.1 *postgresql12-pltcl-12.18-3.52.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * postgresql12-docs-12.18-3.52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0985.html * https://bugzilla.suse.com/show_bug.cgi?id=1219679 . Ensure you obtain the critical security patch for postgresql12 to remediate CVE-2024-0985, incorporating significant improvements for multiple SUSE distributions.. SUSE Security Patch, PostgreSQL Update, DoS Mitigation Tutorial, Server Management Tips. . Severity: Important. LinuxSecurity.com Team
**PHP version 8.1.7** (09 Jun 2022) **CLI:** * Fixed bug [GH-8575](https://github.com/php/php-src/issues/8575) (CLI closes standard streams too early). (Levi Morrison) **Date:** * Fixed bug php#51934 (strtotime plurals / incorrect time). (Derick) * Fixed bug php#51987 (Datetime fails to parse an ISO 8601 ordinal date (extended format)). (Derick) * Fixed bug. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-f3fc52428e 2022-06-17 01:12:46.340889 --------------------------------------------------------------------------------Name : php Product : Fedora 36 Version : 8.1.7 Release : 1.fc36 URL : https://www.php.net/ Summary : PHP scripting language for creating dynamic web sites Description : PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. --------------------------------------------------------------------------------Update Information: **PHP version 8.1.7** (09 Jun 2022) **CLI:** * Fixed bug [GH-8575](https://github.com/php/php-src/issues/8575) (CLI closes standard streams too early). (Levi Morrison) **Date:** * Fixed bug php#51934 (strtotime plurals / incorrect time). (Derick) * Fixed bug php#51987 (Datetime fails to parse an ISO 8601 ordinal date (extended format)). (Derick) * Fixed bug php#66019 (DateTime object does not support short ISO 8601 time format - YYYY-MM-DDTHH) (cmb, Derick) * Fixed bug php#68549 (Timezones and offsets are not properly used when working with dates) (Derick, Roel Harbers) * Fixed bug php#81565 (date parsing fails when provided with timezones including seconds). (Derick) * Fixed bug[GH-7758](https://github.com/php/php-src/issues/7758) (Problems with negative timestamps and fractions). (Derick, Ilija) **FPM:** * Fixed ACL build check on MacOS. (David Carlier) * Fixed bug php#72185: php-fpm writes empty fcgi record causing nginx 502. (Jakub Zelenka, loveharmful) **mysqlnd:** * Fixed bug php#81719: mysqlnd/pdo password buffer overflow. (**CVE-2022-31626**) (c dot fol at ambionics dot io) **OPcache:** * Fixed bug [GH-8461](https://github.com/php/php-src/issues/8461) (tracing JIT crash after function/method change). (Arnaud, Dmitry) **OpenSSL:** * Fixed bug php#79589 (error:14095126:SSL routines:ssl3_read_n:unexpected eof while reading). (Jakub Zelenka) **Pcntl:** * Fixed Haiku build. (David Carlier) **pgsql** * Fixed bug php#81720: Uninitialized array in pg_query_params(). (**CVE-2022-31625**) (cmb) **Soap:** * Fixed bug [GH-8578](https://github.com/php/php-src/issues/8578) (Error on wrong parameter on SoapHeader constructor). (robertnisipeanu) * Fixed bug [GH-8538](https://github.com/php/php-src/issues/8538) (SoapClient may strip parts of nmtokens). (cmb) **SPL:** * Fixed bug [GH-8235](https://github.com/php/php-src/issues/8235) (iterator_count() may run indefinitely). (cmb) **Standard:** * Fixed bug [GH-8185](https://github.com/php/php-src/issues/8185) (Crash during unloading of extension after dl() in ZTS). (Arnaud) --------------------------------------------------------------------------------ChangeLog: * Wed Jun 8 2022 Remi Collet - 8.1.7-1 - Update to 8.1.7 - https://www.php.net/releases/8_1_7.php - add upstream patch to initialize pcre before mbstring --------------------------------------------------------------------------------References: [ 1 ] Bug #2091404 - Process 41581 (php-fpm) crashed in zend_accel_inheritance_cache_get() https://bugzilla.redhat.com/show_bug.cgi?id=2091404 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2022-f3fc52428e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon security update Advisory ID: RHSA-2021:3280-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2021:3280 Issue date: 2021-08-26 CVE Names: CVE-2020-7788 CVE-2020-28469 CVE-2021-3672 CVE-2021-22930 CVE-2021-22931 CVE-2021-22939 CVE-2021-22940 CVE-2021-23343 CVE-2021-32803 CVE-2021-32804 ==================================================================== 1. Summary: An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: rh-nodejs14-nodejs (14.17.5). Security Fix(es): * nodejs:Use-after-free on close http2 on stream canceling (CVE-2021-22930) * nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22940) * nodejs-ini: Prototype pollution via malicious INI file (CVE-2020-7788) * nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469) * c-ares: Missing input validation of host names may lead to domain hijacking (CVE-2021-3672) * nodejs: Improper handling of untypical characters in domain names (CVE-2021-22931) * nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite (CVE-2021-32803) * nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite (CVE-2021-32804) * nodejs: Incomplete validation of tls rejectUnauthorized parameter (CVE-2021-22939) * nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe (CVE-2021-23343) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1907444 - CVE-2020-7788 nodejs-ini: Prototype pollution via malicious INI file 1945459 - CVE-2020-28469 nodejs-glob-parent: Regular expression denial of service 1956818 - CVE-2021-23343 nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe 1988342 - CVE-2021-3672 c-ares: Missing input validation of host names may lead to domain hijacking 1988394 - CVE-2021-22930 nodejs: Use-after-free on close http2 on stream canceling 1990409 - CVE-2021-32804 nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite 1990415 - CVE-2021-32803 nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite 1993019 - CVE-2021-22931 nodejs: Improper handling of untypical characters indomain names 1993029 - CVE-2021-22940 nodejs: Use-after-free on close http2 on stream canceling 1993039 - CVE-2021-22939 nodejs: Incomplete validation of tls rejectUnauthorized parameter 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-nodejs14-nodejs-14.17.5-1.el7.src.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.17.5-1.el7.noarch.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.17.5-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.s390x.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7): Source: rh-nodejs14-nodejs-14.17.5-1.el7.src.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.17.5-1.el7.noarch.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.17.5-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.s390x.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.x86_64.rpm Red Hat Software Collections for Red HatEnterprise Linux Workstation (v. 7): Source: rh-nodejs14-nodejs-14.17.5-1.el7.src.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.17.5-1.el7.noarch.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.noarch.rpm x86_64: rh-nodejs14-nodejs-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-7788 https://access.redhat.com/security/cve/CVE-2020-28469 https://access.redhat.com/security/cve/CVE-2021-3672 https://access.redhat.com/security/cve/CVE-2021-22930 https://access.redhat.com/security/cve/CVE-2021-22931 https://access.redhat.com/security/cve/CVE-2021-22939 https://access.redhat.com/security/cve/CVE-2021-22940 https://access.redhat.com/security/cve/CVE-2021-23343 https://access.redhat.com/security/cve/CVE-2021-32803 https://access.redhat.com/security/cve/CVE-2021-32804 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYSe+ZdzjgjWX9erEAQhYcg/7B3abtCo+3cNCafs6xxdE/gTXji7SK5EY 1HRy0aXRd5bXCuRKnfNAPkkmhGKOfa0J+0TuZotF/Sh/20VtkGYIrwMIH9X/OYcl kDsv8KkGtFgTKg0rRRCXG3FV+hPDh4r0F0WWxssmXjunAYnOzyxlntafSTnW2FGO igl7caJv6zh3YJsUB/ITn4JCUDCClWR6KEF7gasKnaNpoap52HfHa7qYSUpxaz1K /z3atfAOYJkj1aSSj4327iE1i8SbyYnuPD5m2RZUdHxZrMnVbsd+lVkrrd66KV0q Z58mal5whSgZ6U7jt1oiQBafYvm3mLoyFm3URC9xqPhDbapvL0++mDov5OQNUoyk zRqs1vaV7f27DiQuGtCxCcy+34jIP5PpmazpkWG0oTYYkgt6hpda3+/A4GEvymNF 8xKTpekyasjYpWZ8sX4FOAo5vnqedwFtQoFJ7Q0YoO+DUje2oaw9I9Cm1BGyjTeq /VMJkslLT17lRSrJwNvWBxrUg849nFAd1xMEcAyMhJrlhG6zqe2zGoUCJokaPaxr Cx0pezZ8ERabp8kTBS5Jm7vN9yBymwVsEw32QRV/2Mp2Zdi1cY6Y9UJJQ7N+YjjJ 5nsPiho66PlZ3E0CIU+Ntr03ROW3X8E2u15ACUsGnZdSsqt36QWKmoKCP4d+8fNI z53onxTqYlM=JjAl -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2564-1 Rating: moderate References: #1188037 Cross-References: CVE-2021-21705 CVSS scores: CVE-2021-21705 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php72 fixes the following issues: - CVE-2021-21705 [bsc#1188037]: SSRF bypass in FILTER_VALIDATE_URL Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-2564=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-2564=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.63.2 php72-debugsource-7.2.5-1.63.2 php72-devel-7.2.5-1.63.2 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.63.2 apache2-mod_php72-debuginfo-7.2.5-1.63.2 php72-7.2.5-1.63.2 php72-bcmath-7.2.5-1.63.2 php72-bcmath-debuginfo-7.2.5-1.63.2 php72-bz2-7.2.5-1.63.2 php72-bz2-debuginfo-7.2.5-1.63.2 php72-calendar-7.2.5-1.63.2 php72-calendar-debuginfo-7.2.5-1.63.2 php72-ctype-7.2.5-1.63.2 php72-ctype-debuginfo-7.2.5-1.63.2 php72-curl-7.2.5-1.63.2 php72-curl-debuginfo-7.2.5-1.63.2 php72-dba-7.2.5-1.63.2 php72-dba-debuginfo-7.2.5-1.63.2 php72-debuginfo-7.2.5-1.63.2 php72-debugsource-7.2.5-1.63.2 php72-dom-7.2.5-1.63.2 php72-dom-debuginfo-7.2.5-1.63.2 php72-enchant-7.2.5-1.63.2 php72-enchant-debuginfo-7.2.5-1.63.2 php72-exif-7.2.5-1.63.2 php72-exif-debuginfo-7.2.5-1.63.2 php72-fastcgi-7.2.5-1.63.2 php72-fastcgi-debuginfo-7.2.5-1.63.2 php72-fileinfo-7.2.5-1.63.2 php72-fileinfo-debuginfo-7.2.5-1.63.2 php72-fpm-7.2.5-1.63.2 php72-fpm-debuginfo-7.2.5-1.63.2 php72-ftp-7.2.5-1.63.2 php72-ftp-debuginfo-7.2.5-1.63.2 php72-gd-7.2.5-1.63.2 php72-gd-debuginfo-7.2.5-1.63.2 php72-gettext-7.2.5-1.63.2 php72-gettext-debuginfo-7.2.5-1.63.2 php72-gmp-7.2.5-1.63.2 php72-gmp-debuginfo-7.2.5-1.63.2 php72-iconv-7.2.5-1.63.2 php72-iconv-debuginfo-7.2.5-1.63.2 php72-imap-7.2.5-1.63.2 php72-imap-debuginfo-7.2.5-1.63.2 php72-intl-7.2.5-1.63.2 php72-intl-debuginfo-7.2.5-1.63.2 php72-json-7.2.5-1.63.2 php72-json-debuginfo-7.2.5-1.63.2 php72-ldap-7.2.5-1.63.2 php72-ldap-debuginfo-7.2.5-1.63.2 php72-mbstring-7.2.5-1.63.2 php72-mbstring-debuginfo-7.2.5-1.63.2 php72-mysql-7.2.5-1.63.2 php72-mysql-debuginfo-7.2.5-1.63.2 php72-odbc-7.2.5-1.63.2 php72-odbc-debuginfo-7.2.5-1.63.2 php72-opcache-7.2.5-1.63.2 php72-opcache-debuginfo-7.2.5-1.63.2 php72-openssl-7.2.5-1.63.2 php72-openssl-debuginfo-7.2.5-1.63.2 php72-pcntl-7.2.5-1.63.2 php72-pcntl-debuginfo-7.2.5-1.63.2 php72-pdo-7.2.5-1.63.2 php72-pdo-debuginfo-7.2.5-1.63.2 php72-pgsql-7.2.5-1.63.2 php72-pgsql-debuginfo-7.2.5-1.63.2 php72-phar-7.2.5-1.63.2 php72-phar-debuginfo-7.2.5-1.63.2 php72-posix-7.2.5-1.63.2 php72-posix-debuginfo-7.2.5-1.63.2 php72-pspell-7.2.5-1.63.2 php72-pspell-debuginfo-7.2.5-1.63.2 php72-readline-7.2.5-1.63.2 php72-readline-debuginfo-7.2.5-1.63.2 php72-shmop-7.2.5-1.63.2 php72-shmop-debuginfo-7.2.5-1.63.2 php72-snmp-7.2.5-1.63.2 php72-snmp-debuginfo-7.2.5-1.63.2 php72-soap-7.2.5-1.63.2 php72-soap-debuginfo-7.2.5-1.63.2 php72-sockets-7.2.5-1.63.2 php72-sockets-debuginfo-7.2.5-1.63.2 php72-sodium-7.2.5-1.63.2 php72-sodium-debuginfo-7.2.5-1.63.2 php72-sqlite-7.2.5-1.63.2 php72-sqlite-debuginfo-7.2.5-1.63.2 php72-sysvmsg-7.2.5-1.63.2 php72-sysvmsg-debuginfo-7.2.5-1.63.2 php72-sysvsem-7.2.5-1.63.2 php72-sysvsem-debuginfo-7.2.5-1.63.2 php72-sysvshm-7.2.5-1.63.2 php72-sysvshm-debuginfo-7.2.5-1.63.2 php72-tidy-7.2.5-1.63.2 php72-tidy-debuginfo-7.2.5-1.63.2 php72-tokenizer-7.2.5-1.63.2 php72-tokenizer-debuginfo-7.2.5-1.63.2 php72-wddx-7.2.5-1.63.2 php72-wddx-debuginfo-7.2.5-1.63.2 php72-xmlreader-7.2.5-1.63.2 php72-xmlreader-debuginfo-7.2.5-1.63.2 php72-xmlrpc-7.2.5-1.63.2 php72-xmlrpc-debuginfo-7.2.5-1.63.2 php72-xmlwriter-7.2.5-1.63.2 php72-xmlwriter-debuginfo-7.2.5-1.63.2 php72-xsl-7.2.5-1.63.2 php72-xsl-debuginfo-7.2.5-1.63.2 php72-zip-7.2.5-1.63.2 php72-zip-debuginfo-7.2.5-1.63.2 php72-zlib-7.2.5-1.63.2 php72-zlib-debuginfo-7.2.5-1.63.2 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.63.2 php72-pear-Archive_Tar-7.2.5-1.63.2 References: https://www.suse.com/security/cve/CVE-2021-21705.html https://bugzilla.suse.com/1188037 . Ubuntu Security Alert for php7.4 resolves a moderate risk SSRF tampering flaw to protect system stability.. php72 Update,SUSE Linux Security,SUSE Patch Instructions. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0125-1 Rating: moderate References: #1180706 Cross-References: CVE-2020-7071 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php72 fixes the following issue: - CVE-2020-7071: Fixed an insufficient filter in parse_url() that accepted URLs with invalid userinfo (bsc#1180706). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-125=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-125=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.57.1 php72-debugsource-7.2.5-1.57.1 php72-devel-7.2.5-1.57.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.57.1 apache2-mod_php72-debuginfo-7.2.5-1.57.1 php72-7.2.5-1.57.1 php72-bcmath-7.2.5-1.57.1 php72-bcmath-debuginfo-7.2.5-1.57.1 php72-bz2-7.2.5-1.57.1 php72-bz2-debuginfo-7.2.5-1.57.1 php72-calendar-7.2.5-1.57.1 php72-calendar-debuginfo-7.2.5-1.57.1 php72-ctype-7.2.5-1.57.1 php72-ctype-debuginfo-7.2.5-1.57.1 php72-curl-7.2.5-1.57.1 php72-curl-debuginfo-7.2.5-1.57.1 php72-dba-7.2.5-1.57.1 php72-dba-debuginfo-7.2.5-1.57.1 php72-debuginfo-7.2.5-1.57.1 php72-debugsource-7.2.5-1.57.1 php72-dom-7.2.5-1.57.1 php72-dom-debuginfo-7.2.5-1.57.1 php72-enchant-7.2.5-1.57.1 php72-enchant-debuginfo-7.2.5-1.57.1 php72-exif-7.2.5-1.57.1 php72-exif-debuginfo-7.2.5-1.57.1 php72-fastcgi-7.2.5-1.57.1 php72-fastcgi-debuginfo-7.2.5-1.57.1 php72-fileinfo-7.2.5-1.57.1 php72-fileinfo-debuginfo-7.2.5-1.57.1 php72-fpm-7.2.5-1.57.1 php72-fpm-debuginfo-7.2.5-1.57.1 php72-ftp-7.2.5-1.57.1 php72-ftp-debuginfo-7.2.5-1.57.1 php72-gd-7.2.5-1.57.1 php72-gd-debuginfo-7.2.5-1.57.1 php72-gettext-7.2.5-1.57.1 php72-gettext-debuginfo-7.2.5-1.57.1 php72-gmp-7.2.5-1.57.1 php72-gmp-debuginfo-7.2.5-1.57.1 php72-iconv-7.2.5-1.57.1 php72-iconv-debuginfo-7.2.5-1.57.1 php72-imap-7.2.5-1.57.1 php72-imap-debuginfo-7.2.5-1.57.1 php72-intl-7.2.5-1.57.1 php72-intl-debuginfo-7.2.5-1.57.1 php72-json-7.2.5-1.57.1 php72-json-debuginfo-7.2.5-1.57.1 php72-ldap-7.2.5-1.57.1 php72-ldap-debuginfo-7.2.5-1.57.1 php72-mbstring-7.2.5-1.57.1 php72-mbstring-debuginfo-7.2.5-1.57.1 php72-mysql-7.2.5-1.57.1 php72-mysql-debuginfo-7.2.5-1.57.1 php72-odbc-7.2.5-1.57.1 php72-odbc-debuginfo-7.2.5-1.57.1 php72-opcache-7.2.5-1.57.1 php72-opcache-debuginfo-7.2.5-1.57.1 php72-openssl-7.2.5-1.57.1 php72-openssl-debuginfo-7.2.5-1.57.1 php72-pcntl-7.2.5-1.57.1 php72-pcntl-debuginfo-7.2.5-1.57.1 php72-pdo-7.2.5-1.57.1 php72-pdo-debuginfo-7.2.5-1.57.1 php72-pgsql-7.2.5-1.57.1 php72-pgsql-debuginfo-7.2.5-1.57.1 php72-phar-7.2.5-1.57.1 php72-phar-debuginfo-7.2.5-1.57.1 php72-posix-7.2.5-1.57.1 php72-posix-debuginfo-7.2.5-1.57.1 php72-pspell-7.2.5-1.57.1 php72-pspell-debuginfo-7.2.5-1.57.1 php72-readline-7.2.5-1.57.1 php72-readline-debuginfo-7.2.5-1.57.1 php72-shmop-7.2.5-1.57.1 php72-shmop-debuginfo-7.2.5-1.57.1 php72-snmp-7.2.5-1.57.1 php72-snmp-debuginfo-7.2.5-1.57.1 php72-soap-7.2.5-1.57.1 php72-soap-debuginfo-7.2.5-1.57.1 php72-sockets-7.2.5-1.57.1 php72-sockets-debuginfo-7.2.5-1.57.1 php72-sodium-7.2.5-1.57.1 php72-sodium-debuginfo-7.2.5-1.57.1 php72-sqlite-7.2.5-1.57.1 php72-sqlite-debuginfo-7.2.5-1.57.1 php72-sysvmsg-7.2.5-1.57.1 php72-sysvmsg-debuginfo-7.2.5-1.57.1 php72-sysvsem-7.2.5-1.57.1 php72-sysvsem-debuginfo-7.2.5-1.57.1 php72-sysvshm-7.2.5-1.57.1 php72-sysvshm-debuginfo-7.2.5-1.57.1 php72-tidy-7.2.5-1.57.1 php72-tidy-debuginfo-7.2.5-1.57.1 php72-tokenizer-7.2.5-1.57.1 php72-tokenizer-debuginfo-7.2.5-1.57.1 php72-wddx-7.2.5-1.57.1 php72-wddx-debuginfo-7.2.5-1.57.1 php72-xmlreader-7.2.5-1.57.1 php72-xmlreader-debuginfo-7.2.5-1.57.1 php72-xmlrpc-7.2.5-1.57.1 php72-xmlrpc-debuginfo-7.2.5-1.57.1 php72-xmlwriter-7.2.5-1.57.1 php72-xmlwriter-debuginfo-7.2.5-1.57.1 php72-xsl-7.2.5-1.57.1 php72-xsl-debuginfo-7.2.5-1.57.1 php72-zip-7.2.5-1.57.1 php72-zip-debuginfo-7.2.5-1.57.1 php72-zlib-7.2.5-1.57.1 php72-zlib-debuginfo-7.2.5-1.57.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.57.1 php72-pear-Archive_Tar-7.2.5-1.57.1 References: https://www.suse.com/security/cve/CVE-2020-7071.html https://bugzilla.suse.com/1180706 . SUSE publishes a security patch for php72 addressing a vulnerability related to inadequate filtering. Check the advisory for installation details.. php72 Security Patch,SUSE Update,Moderate Vulnerability Fix,Web Scripting Security,Software Development Kit Update. . Severity: Important. LinuxSecurity.com Team
An update that fixes 7 vulnerabilities is now available. . SUSE Security Update: Security update for java-1_7_1-ibm ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3921-1 Rating: important References: #1116574 Cross-References: CVE-2018-13785 CVE-2018-3136 CVE-2018-3139 CVE-2018-3149 CVE-2018-3169 CVE-2018-3180 CVE-2018-3214 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: java-1_7_1-ibm was updated to Java 7.1 Service Refresh 4 Fix Pack 35 (bsc#1116574): * Consumability - IJ10515 AIX JAVA 7.1.3.10 GENERAL PROTECTION FAULT WHEN ATTEMPTING TO USE HEALTH CENTER API * Class Libraries - IJ10934 CVE-2018-13785 - IJ10935 CVE-2018-3136 - IJ10895 CVE-2018-3139 - IJ10932 CVE-2018-3149 - IJ10894 CVE-2018-3180 - IJ10933 CVE-2018-3214 - IJ09315 FLOATING POINT EXCEPTION FROM JAVA.TEXT.DECIMALFORMAT. FORMAT - IJ09088 INTRODUCING A NEW PROPERTY FOR TURKEY TIMEZONE FOR PRODUCTS NOT IDENTIFYING TRT - IJ08569 JAVA.IO.IOEXCEPTION OCCURS WHEN A FILECHANNEL IS BIGGER THAN 2GB ON AIX PLATFORM - IJ10800 REMOVE EXPIRING ROOT CERTIFICATES IN IBM JDK’S CACERTS. * Java Virtual Machine - IJ10931 CVE-2018-3169 - IV91132 SOME CORE PATTERN SPECIFIERS ARE NOT HANDLED BY THE JVM ON LINUX * JIT Compiler - IJ08205 CRASH WHILE COMPILING - IJ07886 INCORRECT CALUCATIONS WHEN USING NUMBERFORMAT.FORMAT() AND BIGDECIMAL.{FLOAT/DOUBLE }VALUE() * ORB - IX90187 CLIENTREQUESTIMPL.REINVO KE FAILS WITH JAVA.LANG.INDEXOUTOFBOUN DSEXCEPTION * Security - IJ10492 'EC KEYSIZE < 384' IS NOT HONORED USING THE 'JDK.TLS.DISABLEDALGORIT HMS' SECURITY PROPERTY - IJ10491 AES/GCM CIPHER – AAD NOT RESET TO UN-INIT STATE AFTER DOFINAL( ) AND INIT( ) - IJ08442 HTTP PUBLIC KEY PINNING FINGERPRINT,PROBLEM WITH CONVERTING TO JKS KEYSTORE - IJ09107 IBMPKCS11IMPL CRYPTO PROVIDER – INTERMITTENT ERROR WITH SECP521R1 SIGNATURE ON Z/OS - IJ10136 IBMPKCS11IMPL – INTERMITTENT ERROR WITH SECP521R1 SIG ON Z/OS AND Z/LINUX - IJ08530 IBMPKCS11IMPL PROVIDER USES THE WRONG RSA CIPHER MECHANISM FOR THE RSA/ECB/PKCS1PADDING CIPHER - IJ08723 JAAS THROWS A ‘ARRAY INDEX OUT OF RANGE’ EXCEPTION - IJ08704 THE SECURITY PROPERTY ‘JDK.CERTPATH.DISABLEDAL GORITHMS’ IS MISTAKENLY BEING USED TO FILTER JAR SIGNING ALGORITHMS * z/OS Extentions - PH01244 OUTPUT BUFFER TOO SHORT FOR GCM MODE ENCRYPTION USING IBMJCEHYBRID Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-java-1_7_1-ibm-13883=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-java-1_7_1-ibm-13883=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ppc64 s390x x86_64): java-1_7_1-ibm-devel-1.7.1_sr4.35-26.32.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ppc64 s390x x86_64): java-1_7_1-ibm-1.7.1_sr4.35-26.32.1 java-1_7_1-ibm-jdbc-1.7.1_sr4.35-26.32.1 - SUSE Linux Enterprise Server 11-SP4 (i586 x86_64): java-1_7_1-ibm-alsa-1.7.1_sr4.35-26.32.1 java-1_7_1-ibm-plugin-1.7.1_sr4.35-26.32.1 References: https://www.suse.com/security/cve/CVE-2018-13785.html https://www.suse.com/security/cve/CVE-2018-3136.html https://www.suse.com/security/cve/CVE-2018-3139.html https://www.suse.com/security/cve/CVE-2018-3149.html https://www.suse.com/security/cve/CVE-2018-3169.html https://www.suse.com/security/cve/CVE-2018-3180.html https://www.suse.com/security/cve/CVE-2018-3214.html https://bugzilla.suse.com/1116574 . SUSE Security Bulletin: Critical updates for python-3_8_7 addressing various vulnerabilities swiftly.. SUSE Security Update, java-1_7_1-ibm, JDK security, software patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.