Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
219

Rocky Linux 9 RLEA-2024:1140 Node.js Enhancement Update

nodejs:18 enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2024:1140","synopsis":"nodejs:18 enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for nodejs-nodemon, nodejs-packaging, module.nodejs-packaging, module.nodejs-nodemon.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Node.js is a software development platform for building fast and scalable\nnetwork applications in the JavaScript programming language.\n\nEnhancement(s):\n\n* nodejs:18\/nodejs: Rebase to latest upstream version (JIRA:Rocky Linux-21438)","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[],"cves":[],"references":[],"publishedAt":"2025-05-07T19:13:09.903227Z","rpms":{"Rocky Linux 9":{"nvras":["nodejs-nodemon-0:3.0.1-1.module+el9.5.0+31785+5534beb0.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el9.5.0+31770+0da7192d.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el9.5.0+31770+0da7192d.src.rpm","nodejs-nodemon-0:3.0.1-1.module+el9.5.0+31785+5534beb0.src.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31786+d18c719d.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31770+0da7192d.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31785+5534beb0.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31785+5534beb0.src.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31786+d18c719d.src.rpm","nodejs-packaging-0:2021.06-4.module+el9.5.0+31770+0da7192d.src.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el9.5.0+31785+5534beb0.noarch.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el9.5.0+31770+0da7192d.noarch.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el9.5.0+31786+d18c719d.noarch.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. An important Node.js update for Rocky Linux 9 has been released, boosting performance and unveiling innovative functionalities.. Rocky Linux, Node.js, enhancementupdate, software development. . LinuxSecurity.com Team

Calendar%202 May 07, 2025 Rocky Linux
219

Rocky Linux 8 RLEA-2024:0890 critical: Node.js Bug Fix and Enhancement

nodejs:18 bug fix and enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2024:0890","synopsis":"nodejs:18 bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for nodejs-nodemon, module.nodejs, nodejs, module.nodejs-nodemon, module.nodejs-packaging, nodejs-packaging.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Node.js is a software development platform for building fast and scalable\nnetwork applications in the JavaScript programming language.\n\nBug Fix(es) and Enhancement(s):\n\n* nodejs:18\/nodejs: Rebase to latest upstream version (JIRA:Rocky Linux-21439)","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[],"cves":[],"references":[],"publishedAt":"2024-03-12T15:42:26.241001Z","rpms":{"Rocky Linux 8":{"nvras":["nodejs-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.src.rpm","nodejs-debuginfo-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-debugsource-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-devel-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-docs-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.noarch.rpm","nodejs-full-i18n-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.8.0+1459+02651ab6.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.8.0+1459+02651ab6.src.rpm","nodejs-packaging-0:2021.06-4.module+el8.7.0+1072+5b168780.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el8.7.0+1072+5b168780.src.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el8.7.0+1072+5b168780.noarch.rpm","npm-1:10.2.3-1.18.19.0.1.module+el8.9.0+1727+17e65eb5.aarch64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Elevate your Rocky Linux 8 environment by incorporating the updated nodejs:18, featuring essential bug resolutions and enhancements to maximizeefficiency.. Rocky Linux Update, Node.js Enhancements, Software Development Platform. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 12, 2024 Critical Rocky Linux
100

SUSE: 2024:0542-1 Important: PostgreSQL12 DoS Security Update

* bsc#1219679 Cross-References: * CVE-2024-0985 . # Security update for postgresql12 Announcement ID: SUSE-SU-2024:0542-1 Rating: important References: * bsc#1219679 Cross-References: * CVE-2024-0985 CVSS scores: * CVE-2024-0985 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2024-0985 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for postgresql12 fixes the following issues: Upgrade to 12.18: * CVE-2024-0985: Tighten security restrictions within REFRESH MATERIALIZED VIEW CONCURRENTLY (bsc#1219679). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-542=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-542=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-542=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-542=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * postgresql12-devel-12.18-3.52.1 * postgresql12-debugsource-12.18-3.52.1 * postgresql12-devel-debuginfo-12.18-3.52.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (ppc64le s390x x86_64) * postgresql12-server-devel-12.18-3.52.1 * postgresql12-server-devel-debuginfo-12.18-3.52.1 * SUSE Linux Enterprise High PerformanceComputing 12 SP5 (aarch64 x86_64) * postgresql12-plpython-12.18-3.52.1 * postgresql12-contrib-12.18-3.52.1 * postgresql12-contrib-debuginfo-12.18-3.52.1 * postgresql12-debugsource-12.18-3.52.1 * postgresql12-server-12.18-3.52.1 * postgresql12-plperl-12.18-3.52.1 * postgresql12-server-debuginfo-12.18-3.52.1 * postgresql12-plperl-debuginfo-12.18-3.52.1 * postgresql12-plpython-debuginfo-12.18-3.52.1 * postgresql12-debuginfo-12.18-3.52.1 * postgresql12-pltcl-debuginfo-12.18-3.52.1 * postgresql12-12.18-3.52.1 * postgresql12-pltcl-12.18-3.52.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * postgresql12-docs-12.18-3.52.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * postgresql12-plpython-12.18-3.52.1 * postgresql12-contrib-12.18-3.52.1 * postgresql12-contrib-debuginfo-12.18-3.52.1 * postgresql12-debugsource-12.18-3.52.1 * postgresql12-server-12.18-3.52.1 * postgresql12-plperl-12.18-3.52.1 * postgresql12-server-debuginfo-12.18-3.52.1 * postgresql12-plperl-debuginfo-12.18-3.52.1 * postgresql12-plpython-debuginfo-12.18-3.52.1 * postgresql12-debuginfo-12.18-3.52.1 * postgresql12-pltcl-debuginfo-12.18-3.52.1 * postgresql12-12.18-3.52.1 * postgresql12-pltcl-12.18-3.52.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * postgresql12-docs-12.18-3.52.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * postgresql12-plpython-12.18-3.52.1 * postgresql12-contrib-12.18-3.52.1 * postgresql12-contrib-debuginfo-12.18-3.52.1 * postgresql12-debugsource-12.18-3.52.1 * postgresql12-server-12.18-3.52.1 * postgresql12-plperl-12.18-3.52.1 * postgresql12-server-debuginfo-12.18-3.52.1 * postgresql12-plperl-debuginfo-12.18-3.52.1 * postgresql12-plpython-debuginfo-12.18-3.52.1 * postgresql12-debuginfo-12.18-3.52.1 * postgresql12-pltcl-debuginfo-12.18-3.52.1 * postgresql12-12.18-3.52.1 *postgresql12-pltcl-12.18-3.52.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * postgresql12-docs-12.18-3.52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0985.html * https://bugzilla.suse.com/show_bug.cgi?id=1219679 . Ensure you obtain the critical security patch for postgresql12 to remediate CVE-2024-0985, incorporating significant improvements for multiple SUSE distributions.. SUSE Security Patch, PostgreSQL Update, DoS Mitigation Tutorial, Server Management Tips. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 20, 2024 Important SuSE
89

Fedora 36: FEDORA-2022-f3fc52428e High: PHP 8.1.7 Critical Update

**PHP version 8.1.7** (09 Jun 2022) **CLI:** * Fixed bug [GH-8575](https://github.com/php/php-src/issues/8575) (CLI closes standard streams too early). (Levi Morrison) **Date:** * Fixed bug php#51934 (strtotime plurals / incorrect time). (Derick) * Fixed bug php#51987 (Datetime fails to parse an ISO 8601 ordinal date (extended format)). (Derick) * Fixed bug. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-f3fc52428e 2022-06-17 01:12:46.340889 --------------------------------------------------------------------------------Name : php Product : Fedora 36 Version : 8.1.7 Release : 1.fc36 URL : https://www.php.net/ Summary : PHP scripting language for creating dynamic web sites Description : PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. --------------------------------------------------------------------------------Update Information: **PHP version 8.1.7** (09 Jun 2022) **CLI:** * Fixed bug [GH-8575](https://github.com/php/php-src/issues/8575) (CLI closes standard streams too early). (Levi Morrison) **Date:** * Fixed bug php#51934 (strtotime plurals / incorrect time). (Derick) * Fixed bug php#51987 (Datetime fails to parse an ISO 8601 ordinal date (extended format)). (Derick) * Fixed bug php#66019 (DateTime object does not support short ISO 8601 time format - YYYY-MM-DDTHH) (cmb, Derick) * Fixed bug php#68549 (Timezones and offsets are not properly used when working with dates) (Derick, Roel Harbers) * Fixed bug php#81565 (date parsing fails when provided with timezones including seconds). (Derick) * Fixed bug[GH-7758](https://github.com/php/php-src/issues/7758) (Problems with negative timestamps and fractions). (Derick, Ilija) **FPM:** * Fixed ACL build check on MacOS. (David Carlier) * Fixed bug php#72185: php-fpm writes empty fcgi record causing nginx 502. (Jakub Zelenka, loveharmful) **mysqlnd:** * Fixed bug php#81719: mysqlnd/pdo password buffer overflow. (**CVE-2022-31626**) (c dot fol at ambionics dot io) **OPcache:** * Fixed bug [GH-8461](https://github.com/php/php-src/issues/8461) (tracing JIT crash after function/method change). (Arnaud, Dmitry) **OpenSSL:** * Fixed bug php#79589 (error:14095126:SSL routines:ssl3_read_n:unexpected eof while reading). (Jakub Zelenka) **Pcntl:** * Fixed Haiku build. (David Carlier) **pgsql** * Fixed bug php#81720: Uninitialized array in pg_query_params(). (**CVE-2022-31625**) (cmb) **Soap:** * Fixed bug [GH-8578](https://github.com/php/php-src/issues/8578) (Error on wrong parameter on SoapHeader constructor). (robertnisipeanu) * Fixed bug [GH-8538](https://github.com/php/php-src/issues/8538) (SoapClient may strip parts of nmtokens). (cmb) **SPL:** * Fixed bug [GH-8235](https://github.com/php/php-src/issues/8235) (iterator_count() may run indefinitely). (cmb) **Standard:** * Fixed bug [GH-8185](https://github.com/php/php-src/issues/8185) (Crash during unloading of extension after dl() in ZTS). (Arnaud) --------------------------------------------------------------------------------ChangeLog: * Wed Jun 8 2022 Remi Collet - 8.1.7-1 - Update to 8.1.7 - https://www.php.net/releases/8_1_7.php - add upstream patch to initialize pcre before mbstring --------------------------------------------------------------------------------References: [ 1 ] Bug #2091404 - Process 41581 (php-fpm) crashed in zend_accel_inheritance_cache_get() https://bugzilla.redhat.com/show_bug.cgi?id=2091404 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2022-f3fc52428e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Explore the latest updates in PHP version 8.1.7, detailing crucial bug fixes that enhance Fedora 36's performance and stability for developers and users alike. PHP Updates, Fedora Issues, Bug Fixes, Open Source Solutions. . LinuxSecurity.com Team

Calendar%202 Jun 16, 2022 Fedora
98

Red Hat: RHSA-2021-3280-01 Important Update for Node.js Security

An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon security update Advisory ID: RHSA-2021:3280-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2021:3280 Issue date: 2021-08-26 CVE Names: CVE-2020-7788 CVE-2020-28469 CVE-2021-3672 CVE-2021-22930 CVE-2021-22931 CVE-2021-22939 CVE-2021-22940 CVE-2021-23343 CVE-2021-32803 CVE-2021-32804 ==================================================================== 1. Summary: An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The following packages have been upgraded to a later upstream version: rh-nodejs14-nodejs (14.17.5). Security Fix(es): * nodejs:Use-after-free on close http2 on stream canceling (CVE-2021-22930) * nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22940) * nodejs-ini: Prototype pollution via malicious INI file (CVE-2020-7788) * nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469) * c-ares: Missing input validation of host names may lead to domain hijacking (CVE-2021-3672) * nodejs: Improper handling of untypical characters in domain names (CVE-2021-22931) * nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite (CVE-2021-32803) * nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite (CVE-2021-32804) * nodejs: Incomplete validation of tls rejectUnauthorized parameter (CVE-2021-22939) * nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe (CVE-2021-23343) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1907444 - CVE-2020-7788 nodejs-ini: Prototype pollution via malicious INI file 1945459 - CVE-2020-28469 nodejs-glob-parent: Regular expression denial of service 1956818 - CVE-2021-23343 nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe 1988342 - CVE-2021-3672 c-ares: Missing input validation of host names may lead to domain hijacking 1988394 - CVE-2021-22930 nodejs: Use-after-free on close http2 on stream canceling 1990409 - CVE-2021-32804 nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite 1990415 - CVE-2021-32803 nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite 1993019 - CVE-2021-22931 nodejs: Improper handling of untypical characters indomain names 1993029 - CVE-2021-22940 nodejs: Use-after-free on close http2 on stream canceling 1993039 - CVE-2021-22939 nodejs: Incomplete validation of tls rejectUnauthorized parameter 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-nodejs14-nodejs-14.17.5-1.el7.src.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.17.5-1.el7.noarch.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.17.5-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.s390x.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7): Source: rh-nodejs14-nodejs-14.17.5-1.el7.src.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.17.5-1.el7.noarch.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.ppc64le.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.17.5-1.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.s390x.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.x86_64.rpm Red Hat Software Collections for Red HatEnterprise Linux Workstation (v. 7): Source: rh-nodejs14-nodejs-14.17.5-1.el7.src.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.17.5-1.el7.noarch.rpm rh-nodejs14-nodejs-nodemon-2.0.3-5.el7.noarch.rpm x86_64: rh-nodejs14-nodejs-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.17.5-1.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.17.5-1.el7.x86_64.rpm rh-nodejs14-npm-6.14.14-14.17.5.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-7788 https://access.redhat.com/security/cve/CVE-2020-28469 https://access.redhat.com/security/cve/CVE-2021-3672 https://access.redhat.com/security/cve/CVE-2021-22930 https://access.redhat.com/security/cve/CVE-2021-22931 https://access.redhat.com/security/cve/CVE-2021-22939 https://access.redhat.com/security/cve/CVE-2021-22940 https://access.redhat.com/security/cve/CVE-2021-23343 https://access.redhat.com/security/cve/CVE-2021-32803 https://access.redhat.com/security/cve/CVE-2021-32804 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYSe+ZdzjgjWX9erEAQhYcg/7B3abtCo+3cNCafs6xxdE/gTXji7SK5EY 1HRy0aXRd5bXCuRKnfNAPkkmhGKOfa0J+0TuZotF/Sh/20VtkGYIrwMIH9X/OYcl kDsv8KkGtFgTKg0rRRCXG3FV+hPDh4r0F0WWxssmXjunAYnOzyxlntafSTnW2FGO igl7caJv6zh3YJsUB/ITn4JCUDCClWR6KEF7gasKnaNpoap52HfHa7qYSUpxaz1K /z3atfAOYJkj1aSSj4327iE1i8SbyYnuPD5m2RZUdHxZrMnVbsd+lVkrrd66KV0q Z58mal5whSgZ6U7jt1oiQBafYvm3mLoyFm3URC9xqPhDbapvL0++mDov5OQNUoyk zRqs1vaV7f27DiQuGtCxCcy+34jIP5PpmazpkWG0oTYYkgt6hpda3+/A4GEvymNF 8xKTpekyasjYpWZ8sX4FOAo5vnqedwFtQoFJ7Q0YoO+DUje2oaw9I9Cm1BGyjTeq /VMJkslLT17lRSrJwNvWBxrUg849nFAd1xMEcAyMhJrlhG6zqe2zGoUCJokaPaxr Cx0pezZ8ERabp8kTBS5Jm7vN9yBymwVsEw32QRV/2Mp2Zdi1cY6Y9UJJQ7N+YjjJ 5nsPiho66PlZ3E0CIU+Ntr03ROW3X8E2u15ACUsGnZdSsqt36QWKmoKCP4d+8fNI z53onxTqYlM=JjAl -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical announcement regarding rh-nodejs14-nodejs focusing on significant security vulnerabilities within Red Hat Software Collections.. rh-nodejs14-nodemon, important security update, software development, Red Hat advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 26, 2021 Important Red Hat
100

SUSE 12-SP5: 2021:2564-1 Moderate Vulnerability: Php72 SSRF Bypass Risk

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2564-1 Rating: moderate References: #1188037 Cross-References: CVE-2021-21705 CVSS scores: CVE-2021-21705 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php72 fixes the following issues: - CVE-2021-21705 [bsc#1188037]: SSRF bypass in FILTER_VALIDATE_URL Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-2564=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-2564=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.63.2 php72-debugsource-7.2.5-1.63.2 php72-devel-7.2.5-1.63.2 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.63.2 apache2-mod_php72-debuginfo-7.2.5-1.63.2 php72-7.2.5-1.63.2 php72-bcmath-7.2.5-1.63.2 php72-bcmath-debuginfo-7.2.5-1.63.2 php72-bz2-7.2.5-1.63.2 php72-bz2-debuginfo-7.2.5-1.63.2 php72-calendar-7.2.5-1.63.2 php72-calendar-debuginfo-7.2.5-1.63.2 php72-ctype-7.2.5-1.63.2 php72-ctype-debuginfo-7.2.5-1.63.2 php72-curl-7.2.5-1.63.2 php72-curl-debuginfo-7.2.5-1.63.2 php72-dba-7.2.5-1.63.2 php72-dba-debuginfo-7.2.5-1.63.2 php72-debuginfo-7.2.5-1.63.2 php72-debugsource-7.2.5-1.63.2 php72-dom-7.2.5-1.63.2 php72-dom-debuginfo-7.2.5-1.63.2 php72-enchant-7.2.5-1.63.2 php72-enchant-debuginfo-7.2.5-1.63.2 php72-exif-7.2.5-1.63.2 php72-exif-debuginfo-7.2.5-1.63.2 php72-fastcgi-7.2.5-1.63.2 php72-fastcgi-debuginfo-7.2.5-1.63.2 php72-fileinfo-7.2.5-1.63.2 php72-fileinfo-debuginfo-7.2.5-1.63.2 php72-fpm-7.2.5-1.63.2 php72-fpm-debuginfo-7.2.5-1.63.2 php72-ftp-7.2.5-1.63.2 php72-ftp-debuginfo-7.2.5-1.63.2 php72-gd-7.2.5-1.63.2 php72-gd-debuginfo-7.2.5-1.63.2 php72-gettext-7.2.5-1.63.2 php72-gettext-debuginfo-7.2.5-1.63.2 php72-gmp-7.2.5-1.63.2 php72-gmp-debuginfo-7.2.5-1.63.2 php72-iconv-7.2.5-1.63.2 php72-iconv-debuginfo-7.2.5-1.63.2 php72-imap-7.2.5-1.63.2 php72-imap-debuginfo-7.2.5-1.63.2 php72-intl-7.2.5-1.63.2 php72-intl-debuginfo-7.2.5-1.63.2 php72-json-7.2.5-1.63.2 php72-json-debuginfo-7.2.5-1.63.2 php72-ldap-7.2.5-1.63.2 php72-ldap-debuginfo-7.2.5-1.63.2 php72-mbstring-7.2.5-1.63.2 php72-mbstring-debuginfo-7.2.5-1.63.2 php72-mysql-7.2.5-1.63.2 php72-mysql-debuginfo-7.2.5-1.63.2 php72-odbc-7.2.5-1.63.2 php72-odbc-debuginfo-7.2.5-1.63.2 php72-opcache-7.2.5-1.63.2 php72-opcache-debuginfo-7.2.5-1.63.2 php72-openssl-7.2.5-1.63.2 php72-openssl-debuginfo-7.2.5-1.63.2 php72-pcntl-7.2.5-1.63.2 php72-pcntl-debuginfo-7.2.5-1.63.2 php72-pdo-7.2.5-1.63.2 php72-pdo-debuginfo-7.2.5-1.63.2 php72-pgsql-7.2.5-1.63.2 php72-pgsql-debuginfo-7.2.5-1.63.2 php72-phar-7.2.5-1.63.2 php72-phar-debuginfo-7.2.5-1.63.2 php72-posix-7.2.5-1.63.2 php72-posix-debuginfo-7.2.5-1.63.2 php72-pspell-7.2.5-1.63.2 php72-pspell-debuginfo-7.2.5-1.63.2 php72-readline-7.2.5-1.63.2 php72-readline-debuginfo-7.2.5-1.63.2 php72-shmop-7.2.5-1.63.2 php72-shmop-debuginfo-7.2.5-1.63.2 php72-snmp-7.2.5-1.63.2 php72-snmp-debuginfo-7.2.5-1.63.2 php72-soap-7.2.5-1.63.2 php72-soap-debuginfo-7.2.5-1.63.2 php72-sockets-7.2.5-1.63.2 php72-sockets-debuginfo-7.2.5-1.63.2 php72-sodium-7.2.5-1.63.2 php72-sodium-debuginfo-7.2.5-1.63.2 php72-sqlite-7.2.5-1.63.2 php72-sqlite-debuginfo-7.2.5-1.63.2 php72-sysvmsg-7.2.5-1.63.2 php72-sysvmsg-debuginfo-7.2.5-1.63.2 php72-sysvsem-7.2.5-1.63.2 php72-sysvsem-debuginfo-7.2.5-1.63.2 php72-sysvshm-7.2.5-1.63.2 php72-sysvshm-debuginfo-7.2.5-1.63.2 php72-tidy-7.2.5-1.63.2 php72-tidy-debuginfo-7.2.5-1.63.2 php72-tokenizer-7.2.5-1.63.2 php72-tokenizer-debuginfo-7.2.5-1.63.2 php72-wddx-7.2.5-1.63.2 php72-wddx-debuginfo-7.2.5-1.63.2 php72-xmlreader-7.2.5-1.63.2 php72-xmlreader-debuginfo-7.2.5-1.63.2 php72-xmlrpc-7.2.5-1.63.2 php72-xmlrpc-debuginfo-7.2.5-1.63.2 php72-xmlwriter-7.2.5-1.63.2 php72-xmlwriter-debuginfo-7.2.5-1.63.2 php72-xsl-7.2.5-1.63.2 php72-xsl-debuginfo-7.2.5-1.63.2 php72-zip-7.2.5-1.63.2 php72-zip-debuginfo-7.2.5-1.63.2 php72-zlib-7.2.5-1.63.2 php72-zlib-debuginfo-7.2.5-1.63.2 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.63.2 php72-pear-Archive_Tar-7.2.5-1.63.2 References: https://www.suse.com/security/cve/CVE-2021-21705.html https://bugzilla.suse.com/1188037 . Ubuntu Security Alert for php7.4 resolves a moderate risk SSRF tampering flaw to protect system stability.. php72 Update,SUSE Linux Security,SUSE Patch Instructions. . LinuxSecurity.com Team

Calendar%202 Jul 29, 2021 SuSE
100

SUSE: 2021:0125-1 Moderate: php72 Insufficient Filter Update

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for php72 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0125-1 Rating: moderate References: #1180706 Cross-References: CVE-2020-7071 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Module for Web Scripting 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for php72 fixes the following issue: - CVE-2020-7071: Fixed an insufficient filter in parse_url() that accepted URLs with invalid userinfo (bsc#1180706). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-125=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2021-125=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): php72-debuginfo-7.2.5-1.57.1 php72-debugsource-7.2.5-1.57.1 php72-devel-7.2.5-1.57.1 - SUSE Linux Enterprise Module for Web Scripting 12 (aarch64 ppc64le s390x x86_64): apache2-mod_php72-7.2.5-1.57.1 apache2-mod_php72-debuginfo-7.2.5-1.57.1 php72-7.2.5-1.57.1 php72-bcmath-7.2.5-1.57.1 php72-bcmath-debuginfo-7.2.5-1.57.1 php72-bz2-7.2.5-1.57.1 php72-bz2-debuginfo-7.2.5-1.57.1 php72-calendar-7.2.5-1.57.1 php72-calendar-debuginfo-7.2.5-1.57.1 php72-ctype-7.2.5-1.57.1 php72-ctype-debuginfo-7.2.5-1.57.1 php72-curl-7.2.5-1.57.1 php72-curl-debuginfo-7.2.5-1.57.1 php72-dba-7.2.5-1.57.1 php72-dba-debuginfo-7.2.5-1.57.1 php72-debuginfo-7.2.5-1.57.1 php72-debugsource-7.2.5-1.57.1 php72-dom-7.2.5-1.57.1 php72-dom-debuginfo-7.2.5-1.57.1 php72-enchant-7.2.5-1.57.1 php72-enchant-debuginfo-7.2.5-1.57.1 php72-exif-7.2.5-1.57.1 php72-exif-debuginfo-7.2.5-1.57.1 php72-fastcgi-7.2.5-1.57.1 php72-fastcgi-debuginfo-7.2.5-1.57.1 php72-fileinfo-7.2.5-1.57.1 php72-fileinfo-debuginfo-7.2.5-1.57.1 php72-fpm-7.2.5-1.57.1 php72-fpm-debuginfo-7.2.5-1.57.1 php72-ftp-7.2.5-1.57.1 php72-ftp-debuginfo-7.2.5-1.57.1 php72-gd-7.2.5-1.57.1 php72-gd-debuginfo-7.2.5-1.57.1 php72-gettext-7.2.5-1.57.1 php72-gettext-debuginfo-7.2.5-1.57.1 php72-gmp-7.2.5-1.57.1 php72-gmp-debuginfo-7.2.5-1.57.1 php72-iconv-7.2.5-1.57.1 php72-iconv-debuginfo-7.2.5-1.57.1 php72-imap-7.2.5-1.57.1 php72-imap-debuginfo-7.2.5-1.57.1 php72-intl-7.2.5-1.57.1 php72-intl-debuginfo-7.2.5-1.57.1 php72-json-7.2.5-1.57.1 php72-json-debuginfo-7.2.5-1.57.1 php72-ldap-7.2.5-1.57.1 php72-ldap-debuginfo-7.2.5-1.57.1 php72-mbstring-7.2.5-1.57.1 php72-mbstring-debuginfo-7.2.5-1.57.1 php72-mysql-7.2.5-1.57.1 php72-mysql-debuginfo-7.2.5-1.57.1 php72-odbc-7.2.5-1.57.1 php72-odbc-debuginfo-7.2.5-1.57.1 php72-opcache-7.2.5-1.57.1 php72-opcache-debuginfo-7.2.5-1.57.1 php72-openssl-7.2.5-1.57.1 php72-openssl-debuginfo-7.2.5-1.57.1 php72-pcntl-7.2.5-1.57.1 php72-pcntl-debuginfo-7.2.5-1.57.1 php72-pdo-7.2.5-1.57.1 php72-pdo-debuginfo-7.2.5-1.57.1 php72-pgsql-7.2.5-1.57.1 php72-pgsql-debuginfo-7.2.5-1.57.1 php72-phar-7.2.5-1.57.1 php72-phar-debuginfo-7.2.5-1.57.1 php72-posix-7.2.5-1.57.1 php72-posix-debuginfo-7.2.5-1.57.1 php72-pspell-7.2.5-1.57.1 php72-pspell-debuginfo-7.2.5-1.57.1 php72-readline-7.2.5-1.57.1 php72-readline-debuginfo-7.2.5-1.57.1 php72-shmop-7.2.5-1.57.1 php72-shmop-debuginfo-7.2.5-1.57.1 php72-snmp-7.2.5-1.57.1 php72-snmp-debuginfo-7.2.5-1.57.1 php72-soap-7.2.5-1.57.1 php72-soap-debuginfo-7.2.5-1.57.1 php72-sockets-7.2.5-1.57.1 php72-sockets-debuginfo-7.2.5-1.57.1 php72-sodium-7.2.5-1.57.1 php72-sodium-debuginfo-7.2.5-1.57.1 php72-sqlite-7.2.5-1.57.1 php72-sqlite-debuginfo-7.2.5-1.57.1 php72-sysvmsg-7.2.5-1.57.1 php72-sysvmsg-debuginfo-7.2.5-1.57.1 php72-sysvsem-7.2.5-1.57.1 php72-sysvsem-debuginfo-7.2.5-1.57.1 php72-sysvshm-7.2.5-1.57.1 php72-sysvshm-debuginfo-7.2.5-1.57.1 php72-tidy-7.2.5-1.57.1 php72-tidy-debuginfo-7.2.5-1.57.1 php72-tokenizer-7.2.5-1.57.1 php72-tokenizer-debuginfo-7.2.5-1.57.1 php72-wddx-7.2.5-1.57.1 php72-wddx-debuginfo-7.2.5-1.57.1 php72-xmlreader-7.2.5-1.57.1 php72-xmlreader-debuginfo-7.2.5-1.57.1 php72-xmlrpc-7.2.5-1.57.1 php72-xmlrpc-debuginfo-7.2.5-1.57.1 php72-xmlwriter-7.2.5-1.57.1 php72-xmlwriter-debuginfo-7.2.5-1.57.1 php72-xsl-7.2.5-1.57.1 php72-xsl-debuginfo-7.2.5-1.57.1 php72-zip-7.2.5-1.57.1 php72-zip-debuginfo-7.2.5-1.57.1 php72-zlib-7.2.5-1.57.1 php72-zlib-debuginfo-7.2.5-1.57.1 - SUSE Linux Enterprise Module for Web Scripting 12 (noarch): php72-pear-7.2.5-1.57.1 php72-pear-Archive_Tar-7.2.5-1.57.1 References: https://www.suse.com/security/cve/CVE-2020-7071.html https://bugzilla.suse.com/1180706 . SUSE publishes a security patch for php72 addressing a vulnerability related to inadequate filtering. Check the advisory for installation details.. php72 Security Patch,SUSE Update,Moderate Vulnerability Fix,Web Scripting Security,Software Development Kit Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 14, 2021 Important SuSE
100

SUSE: 2018:3921-1 Important: Java 1.7.1 IBM Security Patch

An update that fixes 7 vulnerabilities is now available. . SUSE Security Update: Security update for java-1_7_1-ibm ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3921-1 Rating: important References: #1116574 Cross-References: CVE-2018-13785 CVE-2018-3136 CVE-2018-3139 CVE-2018-3149 CVE-2018-3169 CVE-2018-3180 CVE-2018-3214 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 ______________________________________________________________________________ An update that fixes 7 vulnerabilities is now available. Description: java-1_7_1-ibm was updated to Java 7.1 Service Refresh 4 Fix Pack 35 (bsc#1116574): * Consumability - IJ10515 AIX JAVA 7.1.3.10 GENERAL PROTECTION FAULT WHEN ATTEMPTING TO USE HEALTH CENTER API * Class Libraries - IJ10934 CVE-2018-13785 - IJ10935 CVE-2018-3136 - IJ10895 CVE-2018-3139 - IJ10932 CVE-2018-3149 - IJ10894 CVE-2018-3180 - IJ10933 CVE-2018-3214 - IJ09315 FLOATING POINT EXCEPTION FROM JAVA.TEXT.DECIMALFORMAT. FORMAT - IJ09088 INTRODUCING A NEW PROPERTY FOR TURKEY TIMEZONE FOR PRODUCTS NOT IDENTIFYING TRT - IJ08569 JAVA.IO.IOEXCEPTION OCCURS WHEN A FILECHANNEL IS BIGGER THAN 2GB ON AIX PLATFORM - IJ10800 REMOVE EXPIRING ROOT CERTIFICATES IN IBM JDK’S CACERTS. * Java Virtual Machine - IJ10931 CVE-2018-3169 - IV91132 SOME CORE PATTERN SPECIFIERS ARE NOT HANDLED BY THE JVM ON LINUX * JIT Compiler - IJ08205 CRASH WHILE COMPILING - IJ07886 INCORRECT CALUCATIONS WHEN USING NUMBERFORMAT.FORMAT() AND BIGDECIMAL.{FLOAT/DOUBLE }VALUE() * ORB - IX90187 CLIENTREQUESTIMPL.REINVO KE FAILS WITH JAVA.LANG.INDEXOUTOFBOUN DSEXCEPTION * Security - IJ10492 'EC KEYSIZE < 384' IS NOT HONORED USING THE 'JDK.TLS.DISABLEDALGORIT HMS' SECURITY PROPERTY - IJ10491 AES/GCM CIPHER – AAD NOT RESET TO UN-INIT STATE AFTER DOFINAL( ) AND INIT( ) - IJ08442 HTTP PUBLIC KEY PINNING FINGERPRINT,PROBLEM WITH CONVERTING TO JKS KEYSTORE - IJ09107 IBMPKCS11IMPL CRYPTO PROVIDER – INTERMITTENT ERROR WITH SECP521R1 SIGNATURE ON Z/OS - IJ10136 IBMPKCS11IMPL – INTERMITTENT ERROR WITH SECP521R1 SIG ON Z/OS AND Z/LINUX - IJ08530 IBMPKCS11IMPL PROVIDER USES THE WRONG RSA CIPHER MECHANISM FOR THE RSA/ECB/PKCS1PADDING CIPHER - IJ08723 JAAS THROWS A ‘ARRAY INDEX OUT OF RANGE’ EXCEPTION - IJ08704 THE SECURITY PROPERTY ‘JDK.CERTPATH.DISABLEDAL GORITHMS’ IS MISTAKENLY BEING USED TO FILTER JAR SIGNING ALGORITHMS * z/OS Extentions - PH01244 OUTPUT BUFFER TOO SHORT FOR GCM MODE ENCRYPTION USING IBMJCEHYBRID Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-java-1_7_1-ibm-13883=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-java-1_7_1-ibm-13883=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ppc64 s390x x86_64): java-1_7_1-ibm-devel-1.7.1_sr4.35-26.32.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ppc64 s390x x86_64): java-1_7_1-ibm-1.7.1_sr4.35-26.32.1 java-1_7_1-ibm-jdbc-1.7.1_sr4.35-26.32.1 - SUSE Linux Enterprise Server 11-SP4 (i586 x86_64): java-1_7_1-ibm-alsa-1.7.1_sr4.35-26.32.1 java-1_7_1-ibm-plugin-1.7.1_sr4.35-26.32.1 References: https://www.suse.com/security/cve/CVE-2018-13785.html https://www.suse.com/security/cve/CVE-2018-3136.html https://www.suse.com/security/cve/CVE-2018-3139.html https://www.suse.com/security/cve/CVE-2018-3149.html https://www.suse.com/security/cve/CVE-2018-3169.html https://www.suse.com/security/cve/CVE-2018-3180.html https://www.suse.com/security/cve/CVE-2018-3214.html https://bugzilla.suse.com/1116574 . SUSE Security Bulletin: Critical updates for python-3_8_7 addressing various vulnerabilities swiftly.. SUSE Security Update, java-1_7_1-ibm, JDK security, software patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 27, 2018 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200