Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
98

Red Hat Enterprise Linux 8.6: RHSA-2023-3810-01 Important Python27 Update

An update for the python27:2.7 module is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: python27:2.7 security update Advisory ID: RHSA-2023:3810-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3810 Issue date: 2023-06-27 CVE Names: CVE-2023-24329 ==================================================================== 1. Summary: An update for the python27:2.7 module is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.6) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing. The python27 packages provide a stable release of Python 2.7 with a number of additional utilities and database connectorsfor MySQL and PostgreSQL. Security Fix(es): * python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2173917 - CVE-2023-24329 python: urllib.parse url blocklisting bypass 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.8.6): Source: Cython-0.28.1-7.module+el8.1.0+3111+de3f2d8e.src.rpm PyYAML-3.12-16.module+el8.1.0+3111+de3f2d8e.src.rpm babel-2.5.1-10.module+el8.5.0+11014+88fc0d0b.src.rpm numpy-1.14.2-16.module+el8.4.0+9406+221a4565.src.rpm pytest-3.4.2-13.module+el8.1.0+3111+de3f2d8e.src.rpm python-PyMySQL-0.8.0-10.module+el8.1.0+3111+de3f2d8e.src.rpm python-attrs-17.4.0-10.module+el8.1.0+3111+de3f2d8e.src.rpm python-backports-1.0-16.module+el8.4.0+9193+f3daf6ef.src.rpm python-backports-ssl_match_hostname-3.5.0.1-12.module+el8.4.0+9193+f3daf6ef.src.rpm python-chardet-3.0.4-10.module+el8.1.0+3111+de3f2d8e.src.rpm python-coverage-4.5.1-4.module+el8.1.0+3111+de3f2d8e.src.rpm python-dns-1.15.0-10.module+el8.1.0+3111+de3f2d8e.src.rpm python-docs-2.7.16-2.module+el8.1.0+3111+de3f2d8e.src.rpm python-docutils-0.14-12.module+el8.1.0+3111+de3f2d8e.src.rpm python-funcsigs-1.0.2-13.module+el8.1.0+3111+de3f2d8e.src.rpm python-idna-2.5-7.module+el8.1.0+3111+de3f2d8e.src.rpm python-ipaddress-1.0.18-6.module+el8.1.0+3111+de3f2d8e.src.rpm python-jinja2-2.10-9.module+el8.5.0+10541+706bb066.src.rpm python-lxml-4.2.3-6.module+el8.6.0+13959+8e368262.src.rpm python-markupsafe-0.23-19.module+el8.1.0+3111+de3f2d8e.src.rpm python-mock-2.0.0-13.module+el8.1.0+3111+de3f2d8e.src.rpm python-nose-1.3.7-31.module+el8.5.0+12203+77770ab7.src.rpm python-pluggy-0.6.0-8.module+el8.1.0+3111+de3f2d8e.src.rpm python-psycopg2-2.7.5-7.module+el8.1.0+3111+de3f2d8e.src.rpm python-py-1.5.3-6.module+el8.1.0+3111+de3f2d8e.src.rpm python-pygments-2.2.0-22.module+el8.5.0+10788+a4cea9e0.src.rpm python-pymongo-3.7.0-1.module+el8.5.0+10264+e5753a40.src.rpm python-pysocks-1.6.8-6.module+el8.1.0+3111+de3f2d8e.src.rpm python-pytest-mock-1.9.0-4.module+el8.1.0+3111+de3f2d8e.src.rpm python-requests-2.20.0-3.module+el8.2.0+4577+feefd9b8.src.rpm python-setuptools_scm-1.15.7-6.module+el8.1.0+3111+de3f2d8e.src.rpm python-sqlalchemy-1.3.2-2.module+el8.3.0+6647+8d010749.src.rpm python-urllib3-1.24.2-3.module+el8.4.0+9193+f3daf6ef.src.rpm python-virtualenv-15.1.0-21.module+el8.5.0+12203+77770ab7.src.rpm python-wheel-0.31.1-3.module+el8.5.0+12203+77770ab7.src.rpm python2-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.src.rpm python2-pip-9.0.3-19.module+el8.6.0+13001+ad200bd9.src.rpm python2-rpm-macros-3-38.module+el8.1.0+3111+de3f2d8e.src.rpm python2-setuptools-39.0.1-13.module+el8.4.0+9442+27d0e81c.src.rpm python2-six-1.11.0-6.module+el8.4.0+9287+299307c7.src.rpm pytz-2017.2-12.module+el8.1.0+3111+de3f2d8e.src.rpm scipy-1.0.0-21.module+el8.5.0+10858+05337455.src.rpm aarch64: Cython-debugsource-0.28.1-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm PyYAML-debugsource-3.12-16.module+el8.1.0+3111+de3f2d8e.aarch64.rpm numpy-debugsource-1.14.2-16.module+el8.4.0+9406+221a4565.aarch64.rpm python-coverage-debugsource-4.5.1-4.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python-lxml-debugsource-4.2.3-6.module+el8.6.0+13959+8e368262.aarch64.rpm python-psycopg2-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python-psycopg2-debugsource-2.7.5-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python-psycopg2-doc-2.7.5-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python-pymongo-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.aarch64.rpm python-pymongo-debugsource-3.7.0-1.module+el8.5.0+10264+e5753a40.aarch64.rpm python2-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.aarch64.rpm python2-Cython-0.28.1-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-Cython-debuginfo-0.28.1-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-backports-1.0-16.module+el8.4.0+9193+f3daf6ef.aarch64.rpm python2-bson-3.7.0-1.module+el8.5.0+10264+e5753a40.aarch64.rpm python2-bson-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.aarch64.rpm python2-coverage-4.5.1-4.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-coverage-debuginfo-4.5.1-4.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-debug-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.aarch64.rpm python2-debuginfo-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.aarch64.rpm python2-debugsource-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.aarch64.rpm python2-devel-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.aarch64.rpm python2-libs-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.aarch64.rpm python2-lxml-4.2.3-6.module+el8.6.0+13959+8e368262.aarch64.rpm python2-lxml-debuginfo-4.2.3-6.module+el8.6.0+13959+8e368262.aarch64.rpm python2-markupsafe-0.23-19.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-numpy-1.14.2-16.module+el8.4.0+9406+221a4565.aarch64.rpm python2-numpy-debuginfo-1.14.2-16.module+el8.4.0+9406+221a4565.aarch64.rpm python2-numpy-f2py-1.14.2-16.module+el8.4.0+9406+221a4565.aarch64.rpm python2-psycopg2-2.7.5-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-psycopg2-debug-2.7.5-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-psycopg2-debug-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-psycopg2-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-psycopg2-tests-2.7.5-7.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-pymongo-3.7.0-1.module+el8.5.0+10264+e5753a40.aarch64.rpm python2-pymongo-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.aarch64.rpm python2-pymongo-gridfs-3.7.0-1.module+el8.5.0+10264+e5753a40.aarch64.rpm python2-pyyaml-3.12-16.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-pyyaml-debuginfo-3.12-16.module+el8.1.0+3111+de3f2d8e.aarch64.rpm python2-scipy-1.0.0-21.module+el8.5.0+10858+05337455.aarch64.rpm python2-scipy-debuginfo-1.0.0-21.module+el8.5.0+10858+05337455.aarch64.rpm python2-sqlalchemy-1.3.2-2.module+el8.3.0+6647+8d010749.aarch64.rpm python2-test-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.aarch64.rpm python2-tkinter-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.aarch64.rpm python2-tools-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.aarch64.rpm scipy-debugsource-1.0.0-21.module+el8.5.0+10858+05337455.aarch64.rpm noarch: babel-2.5.1-10.module+el8.5.0+11014+88fc0d0b.noarch.rpm python-nose-docs-1.3.7-31.module+el8.5.0+12203+77770ab7.noarch.rpm python-sqlalchemy-doc-1.3.2-2.module+el8.3.0+6647+8d010749.noarch.rpm python2-PyMySQL-0.8.0-10.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-attrs-17.4.0-10.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-babel-2.5.1-10.module+el8.5.0+11014+88fc0d0b.noarch.rpm python2-backports-ssl_match_hostname-3.5.0.1-12.module+el8.4.0+9193+f3daf6ef.noarch.rpm python2-chardet-3.0.4-10.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-dns-1.15.0-10.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-docs-2.7.16-2.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-docs-info-2.7.16-2.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-docutils-0.14-12.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-funcsigs-1.0.2-13.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-idna-2.5-7.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-ipaddress-1.0.18-6.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-jinja2-2.10-9.module+el8.5.0+10541+706bb066.noarch.rpm python2-mock-2.0.0-13.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-nose-1.3.7-31.module+el8.5.0+12203+77770ab7.noarch.rpm python2-numpy-doc-1.14.2-16.module+el8.4.0+9406+221a4565.noarch.rpm python2-pip-9.0.3-19.module+el8.6.0+13001+ad200bd9.noarch.rpm python2-pip-wheel-9.0.3-19.module+el8.6.0+13001+ad200bd9.noarch.rpm python2-pluggy-0.6.0-8.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-py-1.5.3-6.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-pygments-2.2.0-22.module+el8.5.0+10788+a4cea9e0.noarch.rpm python2-pysocks-1.6.8-6.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-pytest-3.4.2-13.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-pytest-mock-1.9.0-4.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-pytz-2017.2-12.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-requests-2.20.0-3.module+el8.2.0+4577+feefd9b8.noarch.rpm python2-rpm-macros-3-38.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-setuptools-39.0.1-13.module+el8.4.0+9442+27d0e81c.noarch.rpm python2-setuptools-wheel-39.0.1-13.module+el8.4.0+9442+27d0e81c.noarch.rpm python2-setuptools_scm-1.15.7-6.module+el8.1.0+3111+de3f2d8e.noarch.rpm python2-six-1.11.0-6.module+el8.4.0+9287+299307c7.noarch.rpm python2-urllib3-1.24.2-3.module+el8.4.0+9193+f3daf6ef.noarch.rpm python2-virtualenv-15.1.0-21.module+el8.5.0+12203+77770ab7.noarch.rpm python2-wheel-0.31.1-3.module+el8.5.0+12203+77770ab7.noarch.rpm python2-wheel-wheel-0.31.1-3.module+el8.5.0+12203+77770ab7.noarch.rpm ppc64le: Cython-debugsource-0.28.1-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm PyYAML-debugsource-3.12-16.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm numpy-debugsource-1.14.2-16.module+el8.4.0+9406+221a4565.ppc64le.rpm python-coverage-debugsource-4.5.1-4.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python-lxml-debugsource-4.2.3-6.module+el8.6.0+13959+8e368262.ppc64le.rpm python-psycopg2-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python-psycopg2-debugsource-2.7.5-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python-psycopg2-doc-2.7.5-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python-pymongo-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.ppc64le.rpm python-pymongo-debugsource-3.7.0-1.module+el8.5.0+10264+e5753a40.ppc64le.rpm python2-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.ppc64le.rpm python2-Cython-0.28.1-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-Cython-debuginfo-0.28.1-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-backports-1.0-16.module+el8.4.0+9193+f3daf6ef.ppc64le.rpm python2-bson-3.7.0-1.module+el8.5.0+10264+e5753a40.ppc64le.rpm python2-bson-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.ppc64le.rpm python2-coverage-4.5.1-4.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-coverage-debuginfo-4.5.1-4.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-debug-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.ppc64le.rpm python2-debuginfo-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.ppc64le.rpm python2-debugsource-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.ppc64le.rpm python2-devel-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.ppc64le.rpm python2-libs-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.ppc64le.rpm python2-lxml-4.2.3-6.module+el8.6.0+13959+8e368262.ppc64le.rpm python2-lxml-debuginfo-4.2.3-6.module+el8.6.0+13959+8e368262.ppc64le.rpm python2-markupsafe-0.23-19.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-numpy-1.14.2-16.module+el8.4.0+9406+221a4565.ppc64le.rpm python2-numpy-debuginfo-1.14.2-16.module+el8.4.0+9406+221a4565.ppc64le.rpm python2-numpy-f2py-1.14.2-16.module+el8.4.0+9406+221a4565.ppc64le.rpm python2-psycopg2-2.7.5-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-psycopg2-debug-2.7.5-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-psycopg2-debug-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-psycopg2-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-psycopg2-tests-2.7.5-7.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-pymongo-3.7.0-1.module+el8.5.0+10264+e5753a40.ppc64le.rpm python2-pymongo-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.ppc64le.rpm python2-pymongo-gridfs-3.7.0-1.module+el8.5.0+10264+e5753a40.ppc64le.rpm python2-pyyaml-3.12-16.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-pyyaml-debuginfo-3.12-16.module+el8.1.0+3111+de3f2d8e.ppc64le.rpm python2-scipy-1.0.0-21.module+el8.5.0+10858+05337455.ppc64le.rpm python2-scipy-debuginfo-1.0.0-21.module+el8.5.0+10858+05337455.ppc64le.rpm python2-sqlalchemy-1.3.2-2.module+el8.3.0+6647+8d010749.ppc64le.rpm python2-test-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.ppc64le.rpm python2-tkinter-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.ppc64le.rpm python2-tools-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.ppc64le.rpm scipy-debugsource-1.0.0-21.module+el8.5.0+10858+05337455.ppc64le.rpm s390x: Cython-debugsource-0.28.1-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm PyYAML-debugsource-3.12-16.module+el8.1.0+3111+de3f2d8e.s390x.rpm numpy-debugsource-1.14.2-16.module+el8.4.0+9406+221a4565.s390x.rpm python-coverage-debugsource-4.5.1-4.module+el8.1.0+3111+de3f2d8e.s390x.rpm python-lxml-debugsource-4.2.3-6.module+el8.6.0+13959+8e368262.s390x.rpm python-psycopg2-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python-psycopg2-debugsource-2.7.5-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python-psycopg2-doc-2.7.5-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python-pymongo-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.s390x.rpm python-pymongo-debugsource-3.7.0-1.module+el8.5.0+10264+e5753a40.s390x.rpm python2-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.s390x.rpm python2-Cython-0.28.1-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-Cython-debuginfo-0.28.1-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-backports-1.0-16.module+el8.4.0+9193+f3daf6ef.s390x.rpm python2-bson-3.7.0-1.module+el8.5.0+10264+e5753a40.s390x.rpm python2-bson-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.s390x.rpm python2-coverage-4.5.1-4.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-coverage-debuginfo-4.5.1-4.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-debug-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.s390x.rpm python2-debuginfo-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.s390x.rpm python2-debugsource-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.s390x.rpm python2-devel-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.s390x.rpm python2-libs-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.s390x.rpm python2-lxml-4.2.3-6.module+el8.6.0+13959+8e368262.s390x.rpm python2-lxml-debuginfo-4.2.3-6.module+el8.6.0+13959+8e368262.s390x.rpm python2-markupsafe-0.23-19.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-numpy-1.14.2-16.module+el8.4.0+9406+221a4565.s390x.rpm python2-numpy-debuginfo-1.14.2-16.module+el8.4.0+9406+221a4565.s390x.rpm python2-numpy-f2py-1.14.2-16.module+el8.4.0+9406+221a4565.s390x.rpm python2-psycopg2-2.7.5-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-psycopg2-debug-2.7.5-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-psycopg2-debug-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-psycopg2-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-psycopg2-tests-2.7.5-7.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-pymongo-3.7.0-1.module+el8.5.0+10264+e5753a40.s390x.rpm python2-pymongo-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.s390x.rpm python2-pymongo-gridfs-3.7.0-1.module+el8.5.0+10264+e5753a40.s390x.rpm python2-pyyaml-3.12-16.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-pyyaml-debuginfo-3.12-16.module+el8.1.0+3111+de3f2d8e.s390x.rpm python2-scipy-1.0.0-21.module+el8.5.0+10858+05337455.s390x.rpm python2-scipy-debuginfo-1.0.0-21.module+el8.5.0+10858+05337455.s390x.rpm python2-sqlalchemy-1.3.2-2.module+el8.3.0+6647+8d010749.s390x.rpm python2-test-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.s390x.rpm python2-tkinter-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.s390x.rpm python2-tools-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.s390x.rpm scipy-debugsource-1.0.0-21.module+el8.5.0+10858+05337455.s390x.rpm x86_64: Cython-debugsource-0.28.1-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm PyYAML-debugsource-3.12-16.module+el8.1.0+3111+de3f2d8e.x86_64.rpm numpy-debugsource-1.14.2-16.module+el8.4.0+9406+221a4565.x86_64.rpm python-coverage-debugsource-4.5.1-4.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python-lxml-debugsource-4.2.3-6.module+el8.6.0+13959+8e368262.x86_64.rpm python-psycopg2-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python-psycopg2-debugsource-2.7.5-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python-psycopg2-doc-2.7.5-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python-pymongo-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.x86_64.rpm python-pymongo-debugsource-3.7.0-1.module+el8.5.0+10264+e5753a40.x86_64.rpm python2-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.x86_64.rpm python2-Cython-0.28.1-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-Cython-debuginfo-0.28.1-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-backports-1.0-16.module+el8.4.0+9193+f3daf6ef.x86_64.rpm python2-bson-3.7.0-1.module+el8.5.0+10264+e5753a40.x86_64.rpm python2-bson-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.x86_64.rpm python2-coverage-4.5.1-4.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-coverage-debuginfo-4.5.1-4.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-debug-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.x86_64.rpm python2-debuginfo-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.x86_64.rpm python2-debugsource-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.x86_64.rpm python2-devel-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.x86_64.rpm python2-libs-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.x86_64.rpm python2-lxml-4.2.3-6.module+el8.6.0+13959+8e368262.x86_64.rpm python2-lxml-debuginfo-4.2.3-6.module+el8.6.0+13959+8e368262.x86_64.rpm python2-markupsafe-0.23-19.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-numpy-1.14.2-16.module+el8.4.0+9406+221a4565.x86_64.rpm python2-numpy-debuginfo-1.14.2-16.module+el8.4.0+9406+221a4565.x86_64.rpm python2-numpy-f2py-1.14.2-16.module+el8.4.0+9406+221a4565.x86_64.rpm python2-psycopg2-2.7.5-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-psycopg2-debug-2.7.5-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-psycopg2-debug-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-psycopg2-debuginfo-2.7.5-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-psycopg2-tests-2.7.5-7.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-pymongo-3.7.0-1.module+el8.5.0+10264+e5753a40.x86_64.rpm python2-pymongo-debuginfo-3.7.0-1.module+el8.5.0+10264+e5753a40.x86_64.rpm python2-pymongo-gridfs-3.7.0-1.module+el8.5.0+10264+e5753a40.x86_64.rpm python2-pyyaml-3.12-16.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-pyyaml-debuginfo-3.12-16.module+el8.1.0+3111+de3f2d8e.x86_64.rpm python2-scipy-1.0.0-21.module+el8.5.0+10858+05337455.x86_64.rpm python2-scipy-debuginfo-1.0.0-21.module+el8.5.0+10858+05337455.x86_64.rpm python2-sqlalchemy-1.3.2-2.module+el8.3.0+6647+8d010749.x86_64.rpm python2-test-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.x86_64.rpm python2-tkinter-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.x86_64.rpm python2-tools-2.7.18-10.module+el8.6.0+19066+9af6e2d5.1.x86_64.rpm scipy-debugsource-1.0.0-21.module+el8.5.0+10858+05337455.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZJsFmdzjgjWX9erEAQhOixAAkYOkSUNiDAKKUfrX7JgPtZ3xfJHTQbJ/ cpH6R0eiQF7Peohdltd8j/DCPVsErfJJga3/nUTocfNLjMxQuj33P2nNM2iTZ03p tUj7K3kR/STHBaEuvW8EGZWmBAhcM47NtZjmJ84uxuxc3oyXgtL7c316twdc0Q5u Cs0DmWDdl5KtmWkHMn7UszUZQfdwmfXCH+ZsIXGk7vtPbEPo9TOmwNzdPt3YQmiv 9uoOvzTotqJQ4RE9huuJKmJwYB/4joiFta47u37pTIj69JmXCNaq86sV51zI2UEG B1zVXtDldJ1axgljVp5pfGCawzsDjsCYrhT0xtnAoJwEXd+MoW2s0tl9Fr1ppXK1 cGcrNBI3hblcc1bpFD9Qxg+gml06sim5vPdBeC2zOcrmC2/SPvmD2bJC+zhZwG/I N/6rp3SJBtXIqaCQQ6k9pLG/RJD8UDs6g2l3ME9GcPulXXz2a2hPd4STRS0yNIFH p7nt/rjWOx7UDZJRXJ4rgGL14HoxPZzTt160huBmfRGtTuW0aEebjstyTlbTTZ75 Hr1vQtWyc9YafvQ31widKYjIkJDThpQloRHL7mtsECYN6M+O3XT7oqLNv5+CtQyG BZdRdv6ZP5OvSobeAiwvJUe2NApTbdnfEBmhPjikPLAXOxM6ydVw4EcTuKpz6pFV 80Znn7A9Qbg=ROts -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Canonical issues a critical python3:3.8 security patch for Ubuntu 20.04 highlighting CVE-2023-26842 vulnerabilities.. python27 Security Update, Red Hat Enterprise Linux, Python Module Update, Important Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 27, 2023 Important Red Hat
98

Red Hat Enterprise Linux 8: RHSA-2021:1024-1 Important OpenSSL Fix

An update for openssl is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openssl security update Advisory ID: RHSA-2021:1024-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:1024 Issue date: 2021-03-29 CVE Names: CVE-2021-3449 CVE-2021-3450 ==================================================================== 1. Summary: An update for openssl is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): * openssl: NULL pointer dereference in signature_algorithms processing (CVE-2021-3449) * openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT (CVE-2021-3450) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect,all services linked to the OpenSSL library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 1941547 - CVE-2021-3450 openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT 1941554 - CVE-2021-3449 openssl: NULL pointer dereference in signature_algorithms processing 6. Package List: Red Hat Enterprise Linux BaseOS (v. 8): Source: openssl-1.1.1g-15.el8_3.src.rpm aarch64: openssl-1.1.1g-15.el8_3.aarch64.rpm openssl-debuginfo-1.1.1g-15.el8_3.aarch64.rpm openssl-debugsource-1.1.1g-15.el8_3.aarch64.rpm openssl-devel-1.1.1g-15.el8_3.aarch64.rpm openssl-libs-1.1.1g-15.el8_3.aarch64.rpm openssl-libs-debuginfo-1.1.1g-15.el8_3.aarch64.rpm openssl-perl-1.1.1g-15.el8_3.aarch64.rpm ppc64le: openssl-1.1.1g-15.el8_3.ppc64le.rpm openssl-debuginfo-1.1.1g-15.el8_3.ppc64le.rpm openssl-debugsource-1.1.1g-15.el8_3.ppc64le.rpm openssl-devel-1.1.1g-15.el8_3.ppc64le.rpm openssl-libs-1.1.1g-15.el8_3.ppc64le.rpm openssl-libs-debuginfo-1.1.1g-15.el8_3.ppc64le.rpm openssl-perl-1.1.1g-15.el8_3.ppc64le.rpm s390x: openssl-1.1.1g-15.el8_3.s390x.rpm openssl-debuginfo-1.1.1g-15.el8_3.s390x.rpm openssl-debugsource-1.1.1g-15.el8_3.s390x.rpm openssl-devel-1.1.1g-15.el8_3.s390x.rpm openssl-libs-1.1.1g-15.el8_3.s390x.rpm openssl-libs-debuginfo-1.1.1g-15.el8_3.s390x.rpm openssl-perl-1.1.1g-15.el8_3.s390x.rpm x86_64: openssl-1.1.1g-15.el8_3.x86_64.rpm openssl-debuginfo-1.1.1g-15.el8_3.i686.rpm openssl-debuginfo-1.1.1g-15.el8_3.x86_64.rpm openssl-debugsource-1.1.1g-15.el8_3.i686.rpm openssl-debugsource-1.1.1g-15.el8_3.x86_64.rpm openssl-devel-1.1.1g-15.el8_3.i686.rpm openssl-devel-1.1.1g-15.el8_3.x86_64.rpm openssl-libs-1.1.1g-15.el8_3.i686.rpm openssl-libs-1.1.1g-15.el8_3.x86_64.rpm openssl-libs-debuginfo-1.1.1g-15.el8_3.i686.rpm openssl-libs-debuginfo-1.1.1g-15.el8_3.x86_64.rpm openssl-perl-1.1.1g-15.el8_3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2021-3449 https://access.redhat.com/security/cve/CVE-2021-3450 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYGItXtzjgjWX9erEAQi62w//UVi8TgK532M2dUMRHG5p+DYgct/9/Ke2 h0KdFJG0sXRl6GH/vlBUKkuJjjuRzbLslOeBfDy08+iOSjHX17qiOLG5e5H3AazH kAvq4uG5Q6VSXTdxVwgLOKPuQIi/SZFGzFXcZdr8GmyMNsYV2e+N1hIyrVWFX1Ug qrGrBeJw0Ep+IwezQGk+Vb6JXbj0DwaXSw0AdUA0bzlJ2/E0YPqV11hC6IGmFygA zgw8aYM5zG2JePEmhOoMYN3hXChePxb2l+qxHWVkYWAEBXnqh6oji1jFT18o3m2d fVVjLoeRciFPPdKCEnMVkj63TkxYDhVzztw1GZlijoql0cE0sH+mcpWqMc5xcZkc QHWOU3pS6mcQVfasPRe2LwwDlsUiAfAVppl3gdMspWx6z33CtCq/UCJBEXxCBBfy pmYUnwA0jZ9GTJyrJetB9VjKXbqGXsoI1FNFFpFDe7XeOwFi9nPUZAYK2wfuvHH6 5f0PoEeeVBohyE9g3PJmwmhJpO8+YV9BeNhTgaPIoUJG6UWg4LWn03gb2uFr/1PF XQ2I6kUmX5jG5vrD9Chf0aFuntkg9F9xCN203ZiQnrtlpVAM7xT7/czMem4CVMHO qpwc4AfUp+F+7aTk74WsIaHjDGbrbdq/bq1mFZ3bl1wDt7S5ASriICJQpjiR2bNb IOdSK7PLh+U=E1Oe -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Ubuntu announces critical patch for openssl tackling vulnerabilities. Adhere to the recommendations to maintain system integrity.. Red Hat Enterprise Linux, OpenSSL Update, Security Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 29, 2021 Important Red Hat
98

Red Hat JBoss Web Server 5.4: RHSA-2020-5170-01 Moderate: DoS Attack

Updated Red Hat JBoss Web Server 5.4.0 packages are now available for Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat JBoss Web Server 5.4 security release Advisory ID: RHSA-2020:5170-01 Product: Red Hat JBoss Web Server Advisory URL: https://access.redhat.com/errata/RHSA-2020:5170 Issue date: 2020-11-23 CVE Names: CVE-2020-11996 ==================================================================== 1. Summary: Updated Red Hat JBoss Web Server 5.4.0 packages are now available for Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat JBoss Web Server 5.4 for RHEL 6 Server - i386, noarch, x86_64 Red Hat JBoss Web Server 5.4 for RHEL 7 Server - noarch, x86_64 Red Hat JBoss Web Server 5.4 for RHEL 8 - noarch, x86_64 3. Description: Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 5.4 serves as a replacement for Red Hat JBoss Web Server 5.3, and includes bug fixes, enhancements, and component upgrades, which are documented in the Release Notes, linked to in the References. Security Fix(es): * tomcat: specially crafted sequence of HTTP/2 requestscan lead to DoS (CVE-2020-11996) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link for the update. You must be logged in to download the update. 5. Bugs fixed (https://bugzilla.redhat.com/): 1851420 - CVE-2020-11996 tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS 6. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): JWS-1050 - windows text files have linux-like lines ends JWS-1445 - [ASF BZ 63765] NIO2 connector with OpenSSL 1.1.1 hangs with TLSv1.3 7. Package List: Red Hat JBoss Web Server 5.4 for RHEL 6Server: Source: jws5-jboss-logging-3.4.1-1.Final_redhat_00001.1.el6jws.src.rpm jws5-mod_cluster-1.4.2-7.Final_redhat_00002.2.el6jws.src.rpm jws5-tomcat-9.0.36-6.redhat_5.2.el6jws.src.rpm jws5-tomcat-native-1.2.25-2.redhat_2.el6jws.src.rpm i386: jws5-tomcat-native-1.2.25-2.redhat_2.el6jws.i686.rpm jws5-tomcat-native-debuginfo-1.2.25-2.redhat_2.el6jws.i686.rpm noarch: jws5-jboss-logging-3.4.1-1.Final_redhat_00001.1.el6jws.noarch.rpm jws5-mod_cluster-1.4.2-7.Final_redhat_00002.2.el6jws.noarch.rpm jws5-mod_cluster-tomcat-1.4.2-7.Final_redhat_00002.2.el6jws.noarch.rpm jws5-tomcat-9.0.36-6.redhat_5.2.el6jws.noarch.rpm jws5-tomcat-admin-webapps-9.0.36-6.redhat_5.2.el6jws.noarch.rpm jws5-tomcat-docs-webapp-9.0.36-6.redhat_5.2.el6jws.noarch.rpm jws5-tomcat-el-3.0-api-9.0.36-6.redhat_5.2.el6jws.noarch.rpm jws5-tomcat-javadoc-9.0.36-6.redhat_5.2.el6jws.noarch.rpm jws5-tomcat-jsp-2.3-api-9.0.36-6.redhat_5.2.el6jws.noarch.rpm jws5-tomcat-lib-9.0.36-6.redhat_5.2.el6jws.noarch.rpm jws5-tomcat-selinux-9.0.36-6.redhat_5.2.el6jws.noarch.rpm jws5-tomcat-servlet-4.0-api-9.0.36-6.redhat_5.2.el6jws.noarch.rpm jws5-tomcat-webapps-9.0.36-6.redhat_5.2.el6jws.noarch.rpm x86_64: jws5-tomcat-native-1.2.25-2.redhat_2.el6jws.x86_64.rpm jws5-tomcat-native-debuginfo-1.2.25-2.redhat_2.el6jws.x86_64.rpm Red Hat JBoss Web Server 5.4 for RHEL 7Server: Source: jws5-jboss-logging-3.4.1-1.Final_redhat_00001.1.el7jws.src.rpm jws5-mod_cluster-1.4.2-7.Final_redhat_00002.2.el7jws.src.rpm jws5-tomcat-9.0.36-6.redhat_5.2.el7jws.src.rpm jws5-tomcat-native-1.2.25-2.redhat_2.el7jws.src.rpm noarch: jws5-jboss-logging-3.4.1-1.Final_redhat_00001.1.el7jws.noarch.rpm jws5-mod_cluster-1.4.2-7.Final_redhat_00002.2.el7jws.noarch.rpm jws5-mod_cluster-tomcat-1.4.2-7.Final_redhat_00002.2.el7jws.noarch.rpm jws5-tomcat-9.0.36-6.redhat_5.2.el7jws.noarch.rpm jws5-tomcat-admin-webapps-9.0.36-6.redhat_5.2.el7jws.noarch.rpm jws5-tomcat-docs-webapp-9.0.36-6.redhat_5.2.el7jws.noarch.rpm jws5-tomcat-el-3.0-api-9.0.36-6.redhat_5.2.el7jws.noarch.rpm jws5-tomcat-javadoc-9.0.36-6.redhat_5.2.el7jws.noarch.rpm jws5-tomcat-jsp-2.3-api-9.0.36-6.redhat_5.2.el7jws.noarch.rpm jws5-tomcat-lib-9.0.36-6.redhat_5.2.el7jws.noarch.rpm jws5-tomcat-selinux-9.0.36-6.redhat_5.2.el7jws.noarch.rpm jws5-tomcat-servlet-4.0-api-9.0.36-6.redhat_5.2.el7jws.noarch.rpm jws5-tomcat-webapps-9.0.36-6.redhat_5.2.el7jws.noarch.rpm x86_64: jws5-tomcat-native-1.2.25-2.redhat_2.el7jws.x86_64.rpm jws5-tomcat-native-debuginfo-1.2.25-2.redhat_2.el7jws.x86_64.rpm Red Hat JBoss Web Server 5.4 for RHEL8: Source: jws5-jboss-logging-3.4.1-1.Final_redhat_00001.1.el8jws.src.rpm jws5-mod_cluster-1.4.2-7.Final_redhat_00002.2.el8jws.src.rpm jws5-tomcat-9.0.36-6.redhat_5.2.el8jws.src.rpm jws5-tomcat-native-1.2.25-2.redhat_2.el8jws.src.rpm noarch: jws5-jboss-logging-3.4.1-1.Final_redhat_00001.1.el8jws.noarch.rpm jws5-mod_cluster-1.4.2-7.Final_redhat_00002.2.el8jws.noarch.rpm jws5-mod_cluster-tomcat-1.4.2-7.Final_redhat_00002.2.el8jws.noarch.rpm jws5-tomcat-9.0.36-6.redhat_5.2.el8jws.noarch.rpm jws5-tomcat-admin-webapps-9.0.36-6.redhat_5.2.el8jws.noarch.rpm jws5-tomcat-docs-webapp-9.0.36-6.redhat_5.2.el8jws.noarch.rpm jws5-tomcat-el-3.0-api-9.0.36-6.redhat_5.2.el8jws.noarch.rpm jws5-tomcat-javadoc-9.0.36-6.redhat_5.2.el8jws.noarch.rpm jws5-tomcat-jsp-2.3-api-9.0.36-6.redhat_5.2.el8jws.noarch.rpm jws5-tomcat-lib-9.0.36-6.redhat_5.2.el8jws.noarch.rpm jws5-tomcat-selinux-9.0.36-6.redhat_5.2.el8jws.noarch.rpm jws5-tomcat-servlet-4.0-api-9.0.36-6.redhat_5.2.el8jws.noarch.rpm jws5-tomcat-webapps-9.0.36-6.redhat_5.2.el8jws.noarch.rpm x86_64: jws5-tomcat-native-1.2.25-2.redhat_2.el8jws.x86_64.rpm jws5-tomcat-native-debuginfo-1.2.25-2.redhat_2.el8jws.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 8. References: https://access.redhat.com/security/cve/CVE-2020-11996 https://access.redhat.com/security/updates/classification/#moderate 9. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX7unItzjgjWX9erEAQifnw//c08v2mGH9XWHfgCoAqtizfvN/gMJ+NQT zQcz1kQ6wYPFlOT4JKRPtXRRUAvtxLj+UP5ML7fsip7fIPlba1NBOmnfaCqN/05j xvDYlDdIUyL4l0tECXEi5D6eg1io7R9HmFikYxs44V999WWY4ibW8iTM4xCsmgO0 GV6Cr+Ncn9s/8q2hXBzpCPnyj3MkYVTfN59a1zqrfmJxdPIDA/zg5+TQGz3idZsP N3VDfssINHjUll+xmJ9wtOulKuQ0jFke7JyRYsEZ5GTIl/H0aDosmEEFoJEwqTuN QnYKqgkAJaaFQ+4C1k9kxu6JyXzyy5zzLD2tOsK/d0Ls5QksQs4dLGYZ+Kw5aBwO ItrzerF4L+urcMVWfpaY6wAAjknr40yGwBP18jykwbtRZprt4j2sc0P7R1053vNF 0D7tJuV5ebBPIsDr+XsC7VSf9Gio65t4Iyi6JSyeg9Rw4UyAb3Ar1GSbR8mikk58 H7zBdYS5ooSazDHKOxuapRUaZxKG/XCp3C9VK3Zncepa+uhHPZaOJpI65mHxmNtF Mm0pJnwpFj70VIko3hm4CPlAufIxemX5MJMeiyeMQhVEEDeS9d/jcwFq2MozYOiF 11JyFedkJSUCzLCmcynz3JkSGGZuzlq7ysi11ZSpMz7ryK+n7VXCm6CLK3NYalBJ z3gVC++aWLM=cItG -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ====================================================. updated, jboss, server, packages, enterprise, linux. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 23, 2020 Important Red Hat
199

CentOS 7: CESA-2019-2606 Important Kdelibs DoS Advisory

Upstream details at : https://access.redhat.com/errata/RHSA-2019:2606. CentOS Errata and Security Advisory 2019:2606 Important Upstream details at : https://access.redhat.com/errata/RHSA-2019:2606 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 5cb5251df550f50ccb605cf53a6a720f38ac6c7e77ccb34bd7a018a5b8b5ccd0 kdelibs-4.14.8-11.el7_7.i686.rpm 150ca855ef45be0d1f6be00dd7bfed5693743caf8909398ff6e9249c4b33233d kdelibs-4.14.8-11.el7_7.x86_64.rpm eafa49bd4efc99bb5243d022afab94648cca5beb9f05c5d84c2fc4bb0a7b4cc5 kdelibs-apidocs-4.14.8-11.el7_7.noarch.rpm 5624f8c9dd40d43e5c7206c0e4bcebdd893a19cc8f292fe8931e92155a053c6b kdelibs-common-4.14.8-11.el7_7.x86_64.rpm d6d94f7b072472531c76e011a8e80db9eaa1efb39b24c9039fb63f68375436c8 kdelibs-devel-4.14.8-11.el7_7.i686.rpm 317a615c096545286367a35d67d64397d541f4b6f1ef8845653851e7231699db kdelibs-devel-4.14.8-11.el7_7.x86_64.rpm 6bdde73688581724d59d663cc615376555bf5c37f6b76bc82d57b24827e31ce5 kdelibs-ktexteditor-4.14.8-11.el7_7.i686.rpm dc403dcf2ff1ebc81802b80c052bdc166f7f96adf6f5d99ab4a9c9b98e47cffd kdelibs-ktexteditor-4.14.8-11.el7_7.x86_64.rpm Source: bcdec5a8544827b6196f233b122297ced35c93fd166e848a245bcf39e770212d kdelibs-4.14.8-11.el7_7.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent CentOS 7 Kdelibs Security Advisory CESA-2019-2606 highlights significant vulnerabilities within key kdelibs components, which are now rectified.. CentOS 7 Security, Kdelibs Update, CentOS Errata, Security Advisory, Important Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 18, 2019 Important CentOS
98

Red Hat Enterprise 6: RHSA-2016:1547-01 Important: LibTiff Memory Flaws

An update for libtiff is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: libtiff security update Advisory ID: RHSA-2016:1547-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:1547.html Issue date: 2016-08-02 CVE Names: CVE-2014-8127 CVE-2014-8129 CVE-2014-8130 CVE-2014-9330 CVE-2014-9655 CVE-2015-1547 CVE-2015-7554 CVE-2015-8665 CVE-2015-8668 CVE-2015-8683 CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 CVE-2015-8784 CVE-2016-3632 CVE-2016-3945 CVE-2016-3990 CVE-2016-3991 CVE-2016-5320 ==================================================================== 1. Summary: An update for libtiff is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6)- i386, x86_64 3. Description: The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): * Multiple flaws have been discovered in libtiff. A remote attacker could exploit these flaws to cause a crash or memory corruption and, possibly, execute arbitrary code by tricking an application linked against libtiff into processing specially crafted files. (CVE-2014-9655, CVE-2015-1547, CVE-2015-8784, CVE-2015-8683, CVE-2015-8665, CVE-2015-8781, CVE-2015-8782, CVE-2015-8783, CVE-2016-3990, CVE-2016-5320) * Multiple flaws have been discovered in various libtiff tools (bmp2tiff, pal2rgb, thumbnail, tiff2bw, tiff2pdf, tiffcrop, tiffdither, tiffsplit, tiff2rgba). By tricking a user into processing a specially crafted file, a remote attacker could exploit these flaws to cause a crash or memory corruption and, possibly, execute arbitrary code with the privileges of the user running the libtiff tool. (CVE-2014-8127, CVE-2014-8129, CVE-2014-8130, CVE-2014-9330, CVE-2015-7554, CVE-2015-8668, CVE-2016-3632, CVE-2016-3945, CVE-2016-3991) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running applications linked against libtiff must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1177893 - CVE-2014-9330 libtiff: Out-of-bounds reads followed by a crash in bmp2tiff 1185805 - CVE-2014-8127 libtiff: out-of-bounds read with malformed TIFF image in multiple tools 1185815 - CVE-2014-8129 libtiff: out-of-bounds read/write with malformed TIFF image in tiff2pdf 1185817 - CVE-2014-8130 libtiff: divide by zero in the tiffdither tool 1190703 - CVE-2014-9655 libtiff: use of uninitialized memory in putcontig8bitYCbCr21tile and NeXTDecode 1190709 - CVE-2015-1547 libtiff: use of uninitialized memory in NeXTDecode 1294417 - CVE-2015-7554 libtiff: Invalid-write in _TIFFVGetField() when parsing some extensiontags 1294425 - CVE-2015-8668 libtiff: OOB read in bmp2tiff 1294427 - CVE-2015-8683 libtiff: Out-of-bounds when reading CIE Lab image format files 1294444 - CVE-2015-8665 libtiff: Out-of-bounds read in tif_getimage.c 1301649 - CVE-2015-8781 CVE-2015-8782 CVE-2015-8783 libtiff: invalid assertion 1301652 - CVE-2015-8784 libtiff: out-of-bound write in NeXTDecode() 1325093 - CVE-2016-3945 libtiff: out-of-bounds write in the tiff2rgba tool 1325095 - CVE-2016-3632 libtiff: out-of-bounds write in _TIFFVGetField function 1326246 - CVE-2016-3990 libtiff: out-of-bounds write in horizontalDifference8() 1326249 - CVE-2016-3991 libtiff: out-of-bounds write in loadImage() function 1346687 - CVE-2016-5320 libtiff: Out-of-bounds write in PixarLogDecode() function in tif_pixarlog.c 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: libtiff-3.9.4-18.el6_8.src.rpm i386: libtiff-3.9.4-18.el6_8.i686.rpm libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm x86_64: libtiff-3.9.4-18.el6_8.i686.rpm libtiff-3.9.4-18.el6_8.x86_64.rpm libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-debuginfo-3.9.4-18.el6_8.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): i386: libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-devel-3.9.4-18.el6_8.i686.rpm libtiff-static-3.9.4-18.el6_8.i686.rpm x86_64: libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-debuginfo-3.9.4-18.el6_8.x86_64.rpm libtiff-devel-3.9.4-18.el6_8.i686.rpm libtiff-devel-3.9.4-18.el6_8.x86_64.rpm libtiff-static-3.9.4-18.el6_8.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: libtiff-3.9.4-18.el6_8.src.rpm x86_64: libtiff-3.9.4-18.el6_8.i686.rpm libtiff-3.9.4-18.el6_8.x86_64.rpm libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-debuginfo-3.9.4-18.el6_8.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): x86_64: libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-debuginfo-3.9.4-18.el6_8.x86_64.rpm libtiff-devel-3.9.4-18.el6_8.i686.rpm libtiff-devel-3.9.4-18.el6_8.x86_64.rpm libtiff-static-3.9.4-18.el6_8.x86_64.rpm Red Hat Enterprise LinuxServer (v. 6): Source: libtiff-3.9.4-18.el6_8.src.rpm i386: libtiff-3.9.4-18.el6_8.i686.rpm libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-devel-3.9.4-18.el6_8.i686.rpm ppc64: libtiff-3.9.4-18.el6_8.ppc.rpm libtiff-3.9.4-18.el6_8.ppc64.rpm libtiff-debuginfo-3.9.4-18.el6_8.ppc.rpm libtiff-debuginfo-3.9.4-18.el6_8.ppc64.rpm libtiff-devel-3.9.4-18.el6_8.ppc.rpm libtiff-devel-3.9.4-18.el6_8.ppc64.rpm s390x: libtiff-3.9.4-18.el6_8.s390.rpm libtiff-3.9.4-18.el6_8.s390x.rpm libtiff-debuginfo-3.9.4-18.el6_8.s390.rpm libtiff-debuginfo-3.9.4-18.el6_8.s390x.rpm libtiff-devel-3.9.4-18.el6_8.s390.rpm libtiff-devel-3.9.4-18.el6_8.s390x.rpm x86_64: libtiff-3.9.4-18.el6_8.i686.rpm libtiff-3.9.4-18.el6_8.x86_64.rpm libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-debuginfo-3.9.4-18.el6_8.x86_64.rpm libtiff-devel-3.9.4-18.el6_8.i686.rpm libtiff-devel-3.9.4-18.el6_8.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): i386: libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-static-3.9.4-18.el6_8.i686.rpm ppc64: libtiff-debuginfo-3.9.4-18.el6_8.ppc64.rpm libtiff-static-3.9.4-18.el6_8.ppc64.rpm s390x: libtiff-debuginfo-3.9.4-18.el6_8.s390x.rpm libtiff-static-3.9.4-18.el6_8.s390x.rpm x86_64: libtiff-debuginfo-3.9.4-18.el6_8.x86_64.rpm libtiff-static-3.9.4-18.el6_8.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: libtiff-3.9.4-18.el6_8.src.rpm i386: libtiff-3.9.4-18.el6_8.i686.rpm libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-devel-3.9.4-18.el6_8.i686.rpm x86_64: libtiff-3.9.4-18.el6_8.i686.rpm libtiff-3.9.4-18.el6_8.x86_64.rpm libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-debuginfo-3.9.4-18.el6_8.x86_64.rpm libtiff-devel-3.9.4-18.el6_8.i686.rpm libtiff-devel-3.9.4-18.el6_8.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): i386: libtiff-debuginfo-3.9.4-18.el6_8.i686.rpm libtiff-static-3.9.4-18.el6_8.i686.rpm x86_64: libtiff-debuginfo-3.9.4-18.el6_8.x86_64.rpm libtiff-static-3.9.4-18.el6_8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our keyand details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2014-8127 https://access.redhat.com/security/cve/CVE-2014-8129 https://access.redhat.com/security/cve/CVE-2014-8130 https://access.redhat.com/security/cve/CVE-2014-9330 https://access.redhat.com/security/cve/CVE-2014-9655 https://access.redhat.com/security/cve/CVE-2015-1547 https://access.redhat.com/security/cve/CVE-2015-7554 https://access.redhat.com/security/cve/CVE-2015-8665 https://access.redhat.com/security/cve/CVE-2015-8668 https://access.redhat.com/security/cve/CVE-2015-8683 https://access.redhat.com/security/cve/CVE-2015-8781 https://access.redhat.com/security/cve/CVE-2015-8782 https://access.redhat.com/security/cve/CVE-2015-8783 https://access.redhat.com/security/cve/CVE-2015-8784 https://access.redhat.com/security/cve/CVE-2016-3632 https://access.redhat.com/security/cve/CVE-2016-3945 https://access.redhat.com/security/cve/CVE-2016-3990 https://access.redhat.com/security/cve/CVE-2016-3991 https://access.redhat.com/security/cve/CVE-2016-5320 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFXoNKeXlSAg2UNWIIRAsVZAJ940rmw6jTuzv+WQ7T1G+tfn9S1GQCgnVTY Fsfa3CmoWEoMPE+ZNQBpeTQ=vyQ/ -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat has issued a significant security patch for libtiff, correcting several vulnerabilities. Discover further details.. LibTiff Update, Red Hat Advisory, Memory Exploit. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 02, 2016 Important Red Hat
98

Important GnuTLS Security Advisory for Red Hat Enterprise Linux 5 & 6

Updated gnutls packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS). -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: gnutls security update Advisory ID: RHSA-2013:0883-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2013:0883.html Issue date: 2013-05-30 CVE Names: CVE-2013-2116 ==================================================================== 1. Summary: Updated gnutls packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: The GnuTLS library provides support for cryptographic algorithms and for protocols such as Transport Layer Security (TLS). It was discovered that the fix for the CVE-2013-1619 issuereleased via RHSA-2013:0588 introduced a regression in the way GnuTLS decrypted TLS/SSL encrypted records when CBC-mode cipher suites were used. A remote attacker could possibly use this flaw to crash a server or client application that uses GnuTLS. (CVE-2013-2116) Users of GnuTLS are advised to upgrade to these updated packages, which correct this issue. For the update to take effect, all applications linked to the GnuTLS library must be restarted. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 966754 - CVE-2013-2116 gnutls: out of bounds read in _gnutls_ciphertext2compressed (GNUTLS-SA-2013-2) 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: gnutls-1.4.1-10.el5_9.2.i386.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.i386.rpm gnutls-utils-1.4.1-10.el5_9.2.i386.rpm x86_64: gnutls-1.4.1-10.el5_9.2.i386.rpm gnutls-1.4.1-10.el5_9.2.x86_64.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.i386.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.x86_64.rpm gnutls-utils-1.4.1-10.el5_9.2.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: gnutls-debuginfo-1.4.1-10.el5_9.2.i386.rpm gnutls-devel-1.4.1-10.el5_9.2.i386.rpm x86_64: gnutls-debuginfo-1.4.1-10.el5_9.2.i386.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.x86_64.rpm gnutls-devel-1.4.1-10.el5_9.2.i386.rpm gnutls-devel-1.4.1-10.el5_9.2.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: gnutls-1.4.1-10.el5_9.2.i386.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.i386.rpm gnutls-devel-1.4.1-10.el5_9.2.i386.rpm gnutls-utils-1.4.1-10.el5_9.2.i386.rpm ia64: gnutls-1.4.1-10.el5_9.2.i386.rpm gnutls-1.4.1-10.el5_9.2.ia64.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.i386.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.ia64.rpm gnutls-devel-1.4.1-10.el5_9.2.ia64.rpm gnutls-utils-1.4.1-10.el5_9.2.ia64.rpm ppc: gnutls-1.4.1-10.el5_9.2.ppc.rpm gnutls-1.4.1-10.el5_9.2.ppc64.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.ppc.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.ppc64.rpm gnutls-devel-1.4.1-10.el5_9.2.ppc.rpm gnutls-devel-1.4.1-10.el5_9.2.ppc64.rpm gnutls-utils-1.4.1-10.el5_9.2.ppc.rpm s390x: gnutls-1.4.1-10.el5_9.2.s390.rpm gnutls-1.4.1-10.el5_9.2.s390x.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.s390.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.s390x.rpm gnutls-devel-1.4.1-10.el5_9.2.s390.rpm gnutls-devel-1.4.1-10.el5_9.2.s390x.rpm gnutls-utils-1.4.1-10.el5_9.2.s390x.rpm x86_64: gnutls-1.4.1-10.el5_9.2.i386.rpm gnutls-1.4.1-10.el5_9.2.x86_64.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.i386.rpm gnutls-debuginfo-1.4.1-10.el5_9.2.x86_64.rpm gnutls-devel-1.4.1-10.el5_9.2.i386.rpm gnutls-devel-1.4.1-10.el5_9.2.x86_64.rpm gnutls-utils-1.4.1-10.el5_9.2.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 6): Source: i386: gnutls-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-utils-2.8.5-10.el6_4.2.i686.rpm x86_64: gnutls-2.8.5-10.el6_4.2.i686.rpm gnutls-2.8.5-10.el6_4.2.x86_64.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.x86_64.rpm gnutls-utils-2.8.5-10.el6_4.2.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v.6): Source: i386: gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-devel-2.8.5-10.el6_4.2.i686.rpm gnutls-guile-2.8.5-10.el6_4.2.i686.rpm x86_64: gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.x86_64.rpm gnutls-devel-2.8.5-10.el6_4.2.i686.rpm gnutls-devel-2.8.5-10.el6_4.2.x86_64.rpm gnutls-guile-2.8.5-10.el6_4.2.i686.rpm gnutls-guile-2.8.5-10.el6_4.2.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: gnutls-2.8.5-10.el6_4.2.i686.rpm gnutls-2.8.5-10.el6_4.2.x86_64.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.x86_64.rpm gnutls-utils-2.8.5-10.el6_4.2.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.x86_64.rpm gnutls-devel-2.8.5-10.el6_4.2.i686.rpm gnutls-devel-2.8.5-10.el6_4.2.x86_64.rpm gnutls-guile-2.8.5-10.el6_4.2.i686.rpm gnutls-guile-2.8.5-10.el6_4.2.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: i386: gnutls-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-devel-2.8.5-10.el6_4.2.i686.rpm gnutls-utils-2.8.5-10.el6_4.2.i686.rpm ppc64: gnutls-2.8.5-10.el6_4.2.ppc.rpm gnutls-2.8.5-10.el6_4.2.ppc64.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.ppc.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.ppc64.rpm gnutls-devel-2.8.5-10.el6_4.2.ppc.rpm gnutls-devel-2.8.5-10.el6_4.2.ppc64.rpm gnutls-utils-2.8.5-10.el6_4.2.ppc64.rpm s390x: gnutls-2.8.5-10.el6_4.2.s390.rpm gnutls-2.8.5-10.el6_4.2.s390x.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.s390.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.s390x.rpm gnutls-devel-2.8.5-10.el6_4.2.s390.rpm gnutls-devel-2.8.5-10.el6_4.2.s390x.rpm gnutls-utils-2.8.5-10.el6_4.2.s390x.rpm x86_64: gnutls-2.8.5-10.el6_4.2.i686.rpm gnutls-2.8.5-10.el6_4.2.x86_64.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.x86_64.rpm gnutls-devel-2.8.5-10.el6_4.2.i686.rpm gnutls-devel-2.8.5-10.el6_4.2.x86_64.rpm gnutls-utils-2.8.5-10.el6_4.2.x86_64.rpm Red HatEnterprise Linux Server Optional (v. 6): Source: i386: gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-guile-2.8.5-10.el6_4.2.i686.rpm ppc64: gnutls-debuginfo-2.8.5-10.el6_4.2.ppc.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.ppc64.rpm gnutls-guile-2.8.5-10.el6_4.2.ppc.rpm gnutls-guile-2.8.5-10.el6_4.2.ppc64.rpm s390x: gnutls-debuginfo-2.8.5-10.el6_4.2.s390.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.s390x.rpm gnutls-guile-2.8.5-10.el6_4.2.s390.rpm gnutls-guile-2.8.5-10.el6_4.2.s390x.rpm x86_64: gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.x86_64.rpm gnutls-guile-2.8.5-10.el6_4.2.i686.rpm gnutls-guile-2.8.5-10.el6_4.2.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: gnutls-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-devel-2.8.5-10.el6_4.2.i686.rpm gnutls-utils-2.8.5-10.el6_4.2.i686.rpm x86_64: gnutls-2.8.5-10.el6_4.2.i686.rpm gnutls-2.8.5-10.el6_4.2.x86_64.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.x86_64.rpm gnutls-devel-2.8.5-10.el6_4.2.i686.rpm gnutls-devel-2.8.5-10.el6_4.2.x86_64.rpm gnutls-utils-2.8.5-10.el6_4.2.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-guile-2.8.5-10.el6_4.2.i686.rpm x86_64: gnutls-debuginfo-2.8.5-10.el6_4.2.i686.rpm gnutls-debuginfo-2.8.5-10.el6_4.2.x86_64.rpm gnutls-guile-2.8.5-10.el6_4.2.i686.rpm gnutls-guile-2.8.5-10.el6_4.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2013-2116 https://access.redhat.com/security/updates/classification#important https://access.redhat.com/errata/RHSA-2013:0588.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2013 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFRp5x7XlSAg2UNWIIRAs++AJ0ZoAHUqcqY+Zqz3CAG5obsL/WdJgCeNhtD w3Y9Mu8rjL4WWKPKc9ZAv6U=rTdV -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Key gnutls patch resolves serious vulnerabilities impacting Red Hat Enterprise Linux versions 5 and 6. Immediate upgrade advised.. GnuTLS Security Update, RHEL 5, RHEL 6 Update, Critical Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 30, 2013 Important Red Hat
98

Red Hat: RHSA-2012:0127-01 Moderate: MySQL Remote Access Threat

Updated mysql packages that fix several security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: mysql security update Advisory ID: RHSA-2012:0127-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2012:0127.html Issue date: 2012-02-13 CVE Names: CVE-2012-0075 CVE-2012-0087 CVE-2012-0101 CVE-2012-0102 CVE-2012-0114 CVE-2012-0484 CVE-2012-0490 ==================================================================== 1. Summary: Updated mysql packages that fix several security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries. This update fixes several vulnerabilities in the MySQL database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section. (CVE-2012-0075, CVE-2012-0087, CVE-2012-0101, CVE-2012-0102, CVE-2012-0114, CVE-2012-0484, CVE-2012-0490) These updated packages upgrade MySQL to version 5.0.95. Refer to the MySQL release notes for a full list of changes: http://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html All MySQLusers should upgrade to these updated packages, which correct these issues. After installing this update, the MySQL server daemon (mysqld) will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 783794 - CVE-2012-0075 mysql: Unspecified vulnerability allows remote authenticated users to affect integrity 783795 - CVE-2012-0087 mysql: Unspecified vulnerability allows remote authenticated users to affect availability 783797 - CVE-2012-0101 mysql: Unspecified vulnerability allows remote authenticated users to affect availability 783798 - CVE-2012-0102 mysql: Unspecified vulnerability allows remote authenticated users to affect availability 783801 - CVE-2012-0114 mysql: Unspecified vulnerability allows local users to affect confidentiality and integrity 783808 - CVE-2012-0484 mysql: Unspecified vulnerability allows remote authenticated users to affect confidentiality 783815 - CVE-2012-0490 mysql: Unspecified vulnerability allows remote authenticated users to affect availability 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm x86_64: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-5.0.95-1.el5_7.1.x86_64.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: mysql-bench-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-devel-5.0.95-1.el5_7.1.i386.rpm mysql-server-5.0.95-1.el5_7.1.i386.rpm mysql-test-5.0.95-1.el5_7.1.i386.rpm x86_64: mysql-bench-5.0.95-1.el5_7.1.x86_64.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.x86_64.rpm mysql-devel-5.0.95-1.el5_7.1.i386.rpm mysql-devel-5.0.95-1.el5_7.1.x86_64.rpm mysql-server-5.0.95-1.el5_7.1.x86_64.rpm mysql-test-5.0.95-1.el5_7.1.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-bench-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-devel-5.0.95-1.el5_7.1.i386.rpm mysql-server-5.0.95-1.el5_7.1.i386.rpm mysql-test-5.0.95-1.el5_7.1.i386.rpm ia64: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-5.0.95-1.el5_7.1.ia64.rpm mysql-bench-5.0.95-1.el5_7.1.ia64.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.ia64.rpm mysql-devel-5.0.95-1.el5_7.1.ia64.rpm mysql-server-5.0.95-1.el5_7.1.ia64.rpm mysql-test-5.0.95-1.el5_7.1.ia64.rpm ppc: mysql-5.0.95-1.el5_7.1.ppc.rpm mysql-5.0.95-1.el5_7.1.ppc64.rpm mysql-bench-5.0.95-1.el5_7.1.ppc.rpm mysql-debuginfo-5.0.95-1.el5_7.1.ppc.rpm mysql-debuginfo-5.0.95-1.el5_7.1.ppc64.rpm mysql-devel-5.0.95-1.el5_7.1.ppc.rpm mysql-devel-5.0.95-1.el5_7.1.ppc64.rpm mysql-server-5.0.95-1.el5_7.1.ppc.rpm mysql-server-5.0.95-1.el5_7.1.ppc64.rpm mysql-test-5.0.95-1.el5_7.1.ppc.rpm s390x: mysql-5.0.95-1.el5_7.1.s390.rpm mysql-5.0.95-1.el5_7.1.s390x.rpm mysql-bench-5.0.95-1.el5_7.1.s390x.rpm mysql-debuginfo-5.0.95-1.el5_7.1.s390.rpm mysql-debuginfo-5.0.95-1.el5_7.1.s390x.rpm mysql-devel-5.0.95-1.el5_7.1.s390.rpm mysql-devel-5.0.95-1.el5_7.1.s390x.rpm mysql-server-5.0.95-1.el5_7.1.s390x.rpm mysql-test-5.0.95-1.el5_7.1.s390x.rpm x86_64: mysql-5.0.95-1.el5_7.1.i386.rpm mysql-5.0.95-1.el5_7.1.x86_64.rpm mysql-bench-5.0.95-1.el5_7.1.x86_64.rpm mysql-debuginfo-5.0.95-1.el5_7.1.i386.rpm mysql-debuginfo-5.0.95-1.el5_7.1.x86_64.rpm mysql-devel-5.0.95-1.el5_7.1.i386.rpm mysql-devel-5.0.95-1.el5_7.1.x86_64.rpm mysql-server-5.0.95-1.el5_7.1.x86_64.rpm mysql-test-5.0.95-1.el5_7.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7.References: https://access.redhat.com/security/cve/CVE-2012-0075 https://access.redhat.com/security/cve/CVE-2012-0087 https://access.redhat.com/security/cve/CVE-2012-0101 https://access.redhat.com/security/cve/CVE-2012-0102 https://access.redhat.com/security/cve/CVE-2012-0114 https://access.redhat.com/security/cve/CVE-2012-0484 https://access.redhat.com/security/cve/CVE-2012-0490 https://access.redhat.com/security/updates/classification#moderate http://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html https://www.oracle.com/security-alerts/cpujan2012.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2012 Red Hat, Inc. . New MySQL updates address various important security vulnerabilities in Red Hat 5; it is essential to implement this urgent fix immediately.. MySQL Security Update, Red Hat Enterprise Linux, Remote Access Issues. . LinuxSecurity.com Team

Calendar%202 Feb 13, 2012 Red Hat
98

Red Hat: RHSA-2002:035-18 Moderate: PHP Remote Access Risk

Updated PHP packages are available to fix vulnerabilities in the functionsthat parse multipart MIME data, which are used when uploading filesthrough forms.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated PHP packages are available [updated 2002-Mar-11] Advisory ID: RHSA-2002:035-18 Issue date: 2002-02-27 Updated on: 2002-03-21 Product: Red Hat Linux Keywords: PHP remote exploit mulitpart MIME Cross references: Obsoletes: RHSA-2000:088 RHSA-2000:136 --------------------------------------------------------------------- 1. Topic: Updated PHP packages are available to fix vulnerabilities in the functions that parse multipart MIME data, which are used when uploading files through forms. This revised advisory contains updated packages for Red Hat Linux 7, 7.1, and 7.2. 2. Relevant releases/architectures: Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386, ia64 Red Hat Linux 7.2 - i386, ia64, s390 3. Problem description: PHP is an HTML-embeddable scripting language. A number of flaws have been found in the way PHP handles multipart/form-data POST requests. Each of these flaws could allow an attacker to execute arbitrary code on the remote system. PHP 3.10-3.18 contains a broken boundary check (hard to exploit) and an arbitrary heap overflow (easy to exploit). These versions of PHP were shipped with Red Hat Linux 6.2. PHP 4.0.1-4.0.3pl1 contains a broken boundary check (hard to exploit) and a heap-off-by-one (easy to exploit). These versions of PHP were shipped with Red Hat Linux 7.0. PHP 4.0.2-4.0.5 contains two broken boundary checks (one very easy and one hard to exploit). These versions of PHP were shipped with Red Hat Linux 7.1 and as erratas to 7.0. PHP 4.0.6-4.0.7RC2 contains a broken boundary check (very easy to exploit). These versions of PHP were shipped with Red Hat Linux7.2 The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2002-0081 to this issue. If you are running PHP 4.0.3 or above, one way to work around these bugs is to disable the fileupload support within your php.ini file (by setting file_uploads = Off). All users of PHP are advised to immediately upgrade to these errata packages which close these vulnerabilities. A previous version of this erratum included a version of the MySQL extension which was compiled with an incorrect default pathname for the socket used to connect to database servers residing on the local host. This setting corresponds to the mysql.default_socket setting in the /etc/php.ini file, and can also be corrected there. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. After applying these updates you will need to restart your web server if it was running before the update was applied. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: Red Hat Linux 7.2: SRPMS: i386: ia64: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- f07b6317aee9ade09625a8166641edc7 6.2/en/os/SRPMS/php-3.0.18-8.src.rpm c56a2c896756ce982e14b329ee122c97 6.2/en/os/alpha/php-3.0.18-8.alpha.rpm 1a14f54cf642e41b6474f7bd8d89b4b7 6.2/en/os/alpha/php-imap-3.0.18-8.alpha.rpm 90244d18f76ce2f254e946edcb28e4b9 6.2/en/os/alpha/php-ldap-3.0.18-8.alpha.rpm 7b05bacc07896a17866cbe73b9c37eba 6.2/en/os/alpha/php-manual-3.0.18-8.alpha.rpm 1266ab137b0fb24e7447683e9100c501 6.2/en/os/alpha/php-pgsql-3.0.18-8.alpha.rpm f4219464571e14737e1e5e3d414ae5d2 6.2/en/os/i386/php-3.0.18-8.i386.rpm 9e4250f304c8832a0d0e99d98109f59c 6.2/en/os/i386/php-imap-3.0.18-8.i386.rpm 31630b40f901d1617cfe0fce4a2e14df 6.2/en/os/i386/php-ldap-3.0.18-8.i386.rpm 78ade58fa6517548264f21996bf799a3 6.2/en/os/i386/php-manual-3.0.18-8.i386.rpm c4985d7263824fd4c837f997605afff2 6.2/en/os/i386/php-pgsql-3.0.18-8.i386.rpm 08e4722c97645d8bde860ff0b9dbb48c 6.2/en/os/sparc/php-3.0.18-8.sparc.rpm 17d9aaac1927e3dd631dfd26fd75e25e 6.2/en/os/sparc/php-imap-3.0.18-8.sparc.rpm 4f9a316f188315dddc6d2d7b3f643abc 6.2/en/os/sparc/php-ldap-3.0.18-8.sparc.rpm f7783e877972c2cd4a8c91574fef4655 6.2/en/os/sparc/php-manual-3.0.18-8.sparc.rpm b2ac8533b51b8a63db12cee2e334bc70 6.2/en/os/sparc/php-pgsql-3.0.18-8.sparc.rpm bb29d69be271e9392ac5d7927bb5898b 7.0/en/os/SRPMS/php-4.0.6-13.src.rpm 0b712264f703cbeb1ec8bfd4aef472fc 7.0/en/os/alpha/php-4.0.6-13.alpha.rpm 6ad1e3760f43c0bc6565aeb0e3e893c4 7.0/en/os/alpha/php-devel-4.0.6-13.alpha.rpm a591f97833ef17101dcdf4d3a83afca8 7.0/en/os/alpha/php-imap-4.0.6-13.alpha.rpm 71c2a9c5ac2110886a40fc95531bbc9b 7.0/en/os/alpha/php-ldap-4.0.6-13.alpha.rpm 0340411a93de40a1adf9399cf4250f98 7.0/en/os/alpha/php-manual-4.0.6-13.alpha.rpm a867a755350bdb973ca9bb6715d8ee027.0/en/os/alpha/php-mysql-4.0.6-13.alpha.rpm 85f509ab6df2eeff3598ee83a00a4894 7.0/en/os/alpha/php-odbc-4.0.6-13.alpha.rpm 00181ed29d93b2b58b0b80898c15b4db 7.0/en/os/alpha/php-pgsql-4.0.6-13.alpha.rpm af89043ea355c15f56b956851d0aa4d5 7.0/en/os/i386/php-4.0.6-13.i386.rpm df120a36632bfefed5e8214c103153c8 7.0/en/os/i386/php-devel-4.0.6-13.i386.rpm 954c496e71a391754431e604fea27d3a 7.0/en/os/i386/php-imap-4.0.6-13.i386.rpm fe6a47d82357ff4b2f2ecb3c4b5b9263 7.0/en/os/i386/php-ldap-4.0.6-13.i386.rpm 6494c2fe238beb90e8f5d374bef78b82 7.0/en/os/i386/php-manual-4.0.6-13.i386.rpm c9756317b0164b5a9eb4e598233f6603 7.0/en/os/i386/php-mysql-4.0.6-13.i386.rpm 0d219a74f9a603faa6bec0d6cae404ff 7.0/en/os/i386/php-odbc-4.0.6-13.i386.rpm b31f9833aa9de5fb146bd7b0d83d3447 7.0/en/os/i386/php-pgsql-4.0.6-13.i386.rpm 744b77f8a3cc55a27d4d60ab7981c535 7.1/en/os/SRPMS/php-4.0.6-14.src.rpm c050178fb44e084ff22c5df45313e4c5 7.1/en/os/alpha/php-4.0.6-14.alpha.rpm 20aec96fa6f11d258e7341364c7267fe 7.1/en/os/alpha/php-devel-4.0.6-14.alpha.rpm 0efbcddd0fece2113f11b4d73ed8fe7d 7.1/en/os/alpha/php-imap-4.0.6-14.alpha.rpm 4c312b08af6779ec7d232f6d5ee48110 7.1/en/os/alpha/php-ldap-4.0.6-14.alpha.rpm 46847ebec323ce1eee75f94a5e211ff9 7.1/en/os/alpha/php-manual-4.0.6-14.alpha.rpm 59ef323131bed33623b9e1fba289ed2f 7.1/en/os/alpha/php-mysql-4.0.6-14.alpha.rpm 9fbcb899edc3541018ec122c40576ff5 7.1/en/os/alpha/php-odbc-4.0.6-14.alpha.rpm e278989038dc0f87936569846aa293fc 7.1/en/os/alpha/php-pgsql-4.0.6-14.alpha.rpm dc1140d7f7b18781d672e309dd7ca04b 7.1/en/os/i386/php-4.0.6-14.i386.rpm fa4b579888995b6573e7a73804158f96 7.1/en/os/i386/php-devel-4.0.6-14.i386.rpm 1263d98ba75ec5ca1e65d48bd368379d 7.1/en/os/i386/php-imap-4.0.6-14.i386.rpm 74efc20c094b707be855dabaf2add1f4 7.1/en/os/i386/php-ldap-4.0.6-14.i386.rpm cbc44ab6b2fc44a02494bf2471919961 7.1/en/os/i386/php-manual-4.0.6-14.i386.rpm 5d495b80a74f66322a47fd944966f279 7.1/en/os/i386/php-mysql-4.0.6-14.i386.rpm b354335acc5b940d2f0e738fc4787be6 7.1/en/os/i386/php-odbc-4.0.6-14.i386.rpm d077d9fa21dadb3c057678230b3074c07.1/en/os/i386/php-pgsql-4.0.6-14.i386.rpm 3228e983d9ddc1d489a842530b89d243 7.1/en/os/ia64/php-4.0.6-14.ia64.rpm 4833f11cffa29e2ddb875363e5b3f251 7.1/en/os/ia64/php-devel-4.0.6-14.ia64.rpm 47b48d59b575a9b575d611e0f172b7aa 7.1/en/os/ia64/php-imap-4.0.6-14.ia64.rpm e4332a1b20a06ed9fb8f81fde2cc804b 7.1/en/os/ia64/php-ldap-4.0.6-14.ia64.rpm 6f7f723ee3f53ffca3f3d5ff45019b79 7.1/en/os/ia64/php-manual-4.0.6-14.ia64.rpm 3724f9d8d8f4d220346863a88de13d76 7.1/en/os/ia64/php-mysql-4.0.6-14.ia64.rpm 4b8f83a823e31ed823a3140a760483ff 7.1/en/os/ia64/php-odbc-4.0.6-14.ia64.rpm 3f3331675054fddb9da31bf86b0c5547 7.1/en/os/ia64/php-pgsql-4.0.6-14.ia64.rpm 66ecdcea3196a94160ce6cdbc2ddc4d6 7.2/en/os/SRPMS/php-4.0.6-15.src.rpm 39ba1ae47d084733ed62d13bdc2c94c7 7.2/en/os/i386/php-4.0.6-15.i386.rpm 78b159fdd343e51f94999702535b0ea7 7.2/en/os/i386/php-devel-4.0.6-15.i386.rpm ee99d2eef98e265a3bbf8f8a7560aae2 7.2/en/os/i386/php-imap-4.0.6-15.i386.rpm 71e442a419d01253b28e153bb8c0e14d 7.2/en/os/i386/php-ldap-4.0.6-15.i386.rpm dfe7acedf564e7870ec6ae2a5ba35cea 7.2/en/os/i386/php-manual-4.0.6-15.i386.rpm 79c7dd197bd32308cd6fde471ab6ecf9 7.2/en/os/i386/php-mysql-4.0.6-15.i386.rpm 6f361675b3abdf2a0217e1060102b4d3 7.2/en/os/i386/php-odbc-4.0.6-15.i386.rpm d4fed68c16d30a4bc8a810ffa1e38f47 7.2/en/os/i386/php-pgsql-4.0.6-15.i386.rpm f4576c3f1337e53762cb5faa3f6c1d50 7.2/en/os/ia64/php-4.0.6-15.ia64.rpm 206f11bcc8a84d18b742f3e1200bf284 7.2/en/os/ia64/php-devel-4.0.6-15.ia64.rpm 68320556a17082261578fca3b7b8cb83 7.2/en/os/ia64/php-imap-4.0.6-15.ia64.rpm dfe2bf8b9ed61589e43acf87d4d37c22 7.2/en/os/ia64/php-ldap-4.0.6-15.ia64.rpm bf8af9aa9891e0491bd5e4e3d22ae821 7.2/en/os/ia64/php-manual-4.0.6-15.ia64.rpm 971ba2e0d2fdec91d80bb7337a7f7b9f 7.2/en/os/ia64/php-mysql-4.0.6-15.ia64.rpm d6f5e5077ba72d94a21479923382cfe4 7.2/en/os/ia64/php-odbc-4.0.6-15.ia64.rpm 9141daf011bb0bd53543214cb438bbc8 7.2/en/os/ia64/php-pgsql-4.0.6-15.ia64.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each packagewith the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: cert CVE -CVE-2002-0081 Copyright(c) 2000, 2001, 2002 Red Hat, Inc. `. Stay protected by upgrading PHP to fix critical remote access risks via file uploads in Red Hat Linux. Act now!. Red Hat PHP Update, Remote Access Fix, MIME Data Issue. . LinuxSecurity.com Team

Calendar%202 Mar 22, 2002 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200