Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 11 articles for you...
89

Fedora 39: 2024-6d1d9f70d2 critical: fonttools XML Injection

Security fix for CVE-2023-45139. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-6d1d9f70d2 2024-01-25 00:38:48.210927 -------------------------------------------------------------------------------- Name : fonttools Product : Fedora 39 Version : 4.43.1 Release : 1.fc39 URL : https://github.com/fonttools/fonttools/ Summary : Tools to manipulate font files Description : fontTools is a library for manipulating fonts, written in Python. The project includes the TTX tool, that can convert TrueType and OpenType fonts to and from an XML text format, which is also called TTX. It supports TrueType, OpenType, AFM and to an extent Type 1 and some Mac-specific formats. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-45139 -------------------------------------------------------------------------------- ChangeLog: * Sun Oct 8 2023 Parag Nemade - 4.43.1-1 - Update to 4.43.1 version (#2241574) * Tue Aug 22 2023 Parag Nemade - 4.42.1-1 - Update to 4.42.1 version (#2232931) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257808 - CVE-2023-45139 fonttools: XML External Entity Injection (XXE) Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2257808 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-6d1d9f70d2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Keep updated on CVE-2023-45139 impacting fonttools in Fedora 39; ensure you upgrade for safeguarding against security risks.. Fonttools Security Fix, XXE Vulnerability Advisory, Fedora Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 25, 2024 Critical Fedora
100

SUSE: 2023:4378-2 Critical: Nginx Path Traversal Vulnerability

* bsc#1214422 Cross-References: * CVE-2022-46751 . # Security update for apache-ivy Announcement ID: SUSE-SU-2023:4367-1 Rating: important References: * bsc#1214422 Cross-References: * CVE-2022-46751 CVSS scores: * CVE-2022-46751 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2022-46751 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L Affected Products: * Development Tools Module 15-SP4 * Development Tools Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for apache-ivy fixes the following issues: * Upgrade to version 2.5.2 (bsc#1214422) * CVE-2022-46751: Fixed an XML External Entity Injections that could be exploited to exfiltrate data, access resources only the machine running Ivy has access to or disturb the execution of Ivy in different ways. (bsc#1214422) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4367=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4367=1 * Development Tools Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-4367=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-4367=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4367=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4367=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4367=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4367=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4367=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4367=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4367=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-4367=1 ## Package List: * openSUSE Leap 15.4 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * apache-ivy-javadoc-2.5.2-150200.3.9.1 * openSUSE Leap 15.5 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * apache-ivy-javadoc-2.5.2-150200.3.9.1 * Development Tools Module15-SP4 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * Development Tools Module 15-SP5 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * apache-ivy-2.5.2-150200.3.9.1 * SUSE Enterprise Storage 7.1 (noarch) * apache-ivy-2.5.2-150200.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2022-46751.html * https://bugzilla.suse.com/show_bug.cgi?id=1214422 . Security patch for apache-ivy addressing XML vulnerability problems with SUSE critical evaluation. Upgrade guidelines provided.. Apache Ivy Security, SUSE Patch Update, XML Injection Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 06, 2023 Important SuSE
197

Debian LTS DLA-3149-1 Critical: Nokogiri Command Injection & XXE Issues

Multiple vulnerabilities were discovered in Nokogiri, an HTML/XML/SAX/Reader parser for the Ruby programming language, leading to command injection, XML external entity injection (XXE), and denial-of-service (DoS). . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3149-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler October 12, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ruby-nokogiri Version : 1.10.0+dfsg1-2+deb10u1 CVE ID : CVE-2019-5477 CVE-2020-26247 CVE-2022-24836 Debian Bug : 934802 978967 1009787 Multiple vulnerabilities were discovered in Nokogiri, an HTML/XML/SAX/Reader parser for the Ruby programming language, leading to command injection, XML external entity injection (XXE), and denial-of-service (DoS). CVE-2019-5477 A command injection vulnerability allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename. This vulnerability appears in code generated by the Rexical gem versions v1.0.6 and earlier. Rexical is used by Nokogiri to generate lexical scanner code for parsing CSS queries. CVE-2020-26247 XXE vulnerability: XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. CVE-2022-24836 Nokogiri contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. ForDebian 10 buster, these problems have been fixed in version 1.10.0+dfsg1-2+deb10u1. We recommend that you upgrade your ruby-nokogiri packages. For the detailed security status of ruby-nokogiri please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ruby-nokogiri Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Nokogiri experienced multiple security flaws leading to potential command execution, XML parameter injection, and service disruption issues within Debian.. ruby-nokogiri,vulnerability management,debian security updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 12, 2022 Critical Debian LTS
100

SUSE Linux Enterprise 4.1: SUSE-SU-2021:0323-1 Moderate: XML Injection

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for nutch-core ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0323-1 Rating: moderate References: #1181356 Cross-References: CVE-2021-23901 Affected Products: SUSE Linux Enterprise Module for SUSE Manager Server 4.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nutch-core fixes the following issue: - CVE-2021-23901: fixed an XML external entity (XXE) injection in `DmozParser` (bsc#1181356) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.1-2021-323=1 Package List: - SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (noarch): nutch-core-1.0.1-4.3.1 References: https://www.suse.com/security/cve/CVE-2021-23901.html https://bugzilla.suse.com/1181356 . Security patch for nutch-core launched, tackling XML injection vulnerability. Implement the update immediately for enhanced security.. SUSE Update,nutch-core Patch,XML Injection Fix,Security Advisory,Moderate Vulnerability. . LinuxSecurity.com Team

Calendar%202 Feb 08, 2021 SuSE
98

Red Hat JBoss: RHSA-2019-1162-01 Moderate: XSS and Injection Issues

An update is now available for Red Hat JBoss Enterprise Application Platform 6.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat JBoss Enterprise Application Platform 6.4.22 security update Advisory ID: RHSA-2019:1162-01 Product: Red Hat JBoss Enterprise Application Platform Advisory URL: https://access.redhat.com/errata/RHSA-2019:1162 Issue date: 2019-05-13 CVE Names: CVE-2018-8034 CVE-2018-10934 CVE-2018-1000632 ==================================================================== 1. Summary: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server. This release of Red Hat JBoss Enterprise Application Platform 6.4.22 serves as a replacement for Red Hat JBoss Enterprise Application Platform 6.4.21, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * admin-cli: wildfly-core: Cross-site scripting (XSS) in JBoss Management Console (CVE-2018-10934) * dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents (CVE-2018-1000632) * jbossweb: tomcat: host name verification missing in WebSocket client (CVE-2018-8034) For more details about the security issue(s), including the impact, a CVSS score, andother related information, refer to the CVE page(s) listed in the References section. All users of Red Hat JBoss Enterprise Application Platform 6.4 are advised to upgrade to these updated packages. The JBoss server process must be restarted for the update to take effect. 3. Solution: Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 1607580 - CVE-2018-8034 tomcat: host name verification missing in WebSocket client 1613428 - [GSS](6.4.z) Upgrade Ironjacamar from 1.0.42 to 1.0.43 1615673 - CVE-2018-10934 wildfly-core: Cross-site scripting (XSS) in JBoss Management Console 1620529 - CVE-2018-1000632 dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents 1630924 - [GSS](6.4.z) Upgrade Apache CXF from 2.7.18.SP6 to 2.7.18.SP7 1630928 - [GSS](6.4.z) Upgrade JBoss Web from 7.5.29 to 7.5.30 1631773 - [GSS](6.4.z) Upgrade HornetQ from 2.3.25.SP28 to 2.3.25.SP29 1643557 - [GSS](6.4.z) Upgrade HAL from 2.5.17 to 2.5.19 1675264 - [GSS](6.4.z) Upgrade RESTEasy from 2.3.22 to 2.3.23 1691431 - [GSS](6.4.z) Upgrade JBoss Remote Naming from 1.0.13 to 1.0.15 5. References: https://access.redhat.com/security/cve/CVE-2018-8034 https://access.redhat.com/security/cve/CVE-2018-10934 https://access.redhat.com/security/cve/CVE-2018-1000632 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/6.4 https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=6.4 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIUAwUBXNmodNzjgjWX9erEAQghcA/4w/76DtpL5247P+KOeYX7Z4qZXHTC5Cxw aTzBasOcZueXvmhCUMIAXOwCJq9lBi+LkB7NvbiYCnymjjF6zzx+w7HXz5OThYAs Op+a427WblPdmjgj4lu2waU16Hlt17RCfWi4F7s5gUgPO598ECsfVLDAOvXLogM4 RoZT34aEYN31xLbej0xXOKMY22JoJ9FWKIVLqNF+WmKD/dqeBn2i8H7oTeY0pZNV 8NaBuHs4zl6yA9YH9GIZBuMitT1pVlvjzvoRWxINSub0ZkN29O695+uQC4F1DOhA nDlHetCqznTl1zZL+lpTIGkVncBUYFjDRwiA1RTprFS5VVHivqhKh+eGfuZXKROr xdcDh7nZ86HjtO4immYIhfGKPcompOg8gHXfSg7LwwJYqeueRrbF8uP3tD3RNA2E YPj9NGBwEgb0emcgqkk60rXdhi+CMS/X+ic+BTztEKT7Dnt253RNzoVflgo7Hd0t 4TwPAVGpWf7TGRm+/vi3j47vhWSHd0R6kMkljSdnGHS29aUHquu7rpBxEI+0+5FZ llAPRt1VCmaOifM7sdY+Fv1lkaYKxJLD1gQqQ8hKni+HwJkUu0SsyvLIDI5XF3e3 lZtZ2DmMLhxcgMcQ1ZHn8jRiy5y1xkxkR3YwV9DIBbGz8JUbwHHbO1KKlz53piIp lfyVGrwz9g==PZaR -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial security patch for Red Hat JBoss Enterprise Application Platform tackling multiple vulnerabilities. Please proceed with the upgrade.. Red Hat JBoss, enterprise application, security advisory, application platform. . LinuxSecurity.com Team

Calendar%202 May 13, 2019 Red Hat
98

Red Hat 6.4: RHSA-2019-1160-01 Moderate: JBoss Security Fix

An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat JBoss Enterprise Application Platform 6.4.22 security update Advisory ID: RHSA-2019:1160-01 Product: Red Hat JBoss Enterprise Application Platform Advisory URL: https://access.redhat.com/errata/RHSA-2019:1160 Issue date: 2019-05-13 CVE Names: CVE-2018-8034 CVE-2018-10934 CVE-2018-1000632 ==================================================================== 1. Summary: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 Server - noarch 3. Description: Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server. This release of Red Hat JBoss Enterprise Application Platform 6.4.22 serves as a replacement for Red Hat JBoss Enterprise Application Platform 6.4.21, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * admin-cli: wildfly-core: Cross-site scripting (XSS) in JBoss Management Console (CVE-2018-10934) * dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents(CVE-2018-1000632) * jbossweb: tomcat: host name verification missing in WebSocket client (CVE-2018-8034) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. All users of Red Hat JBoss Enterprise Application Platform 6.4 on Red Hat Enterprise Linux 6 are advised to upgrade to these updated packages. The JBoss server process must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1607580 - CVE-2018-8034 tomcat: host name verification missing in WebSocket client 1613428 - [GSS](6.4.z) Upgrade Ironjacamar from 1.0.42 to 1.0.43 1615673 - CVE-2018-10934 wildfly-core: Cross-site scripting (XSS) in JBoss Management Console 1620529 - CVE-2018-1000632 dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents 1630924 - [GSS](6.4.z) Upgrade Apache CXF from 2.7.18.SP6 to 2.7.18.SP7 1630928 - [GSS](6.4.z) Upgrade JBoss Web from 7.5.29 to 7.5.30 1631773 - [GSS](6.4.z) Upgrade HornetQ from 2.3.25.SP28 to 2.3.25.SP29 1643557 - [GSS](6.4.z) Upgrade HAL from 2.5.17 to 2.5.19 1675264 - [GSS](6.4.z) Upgrade RESTEasy from 2.3.22 to 2.3.23 1691431 - [GSS](6.4.z) Upgrade JBoss Remote Naming from 1.0.13 to 1.0.15 6. Package List: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6Server: Source: apache-cxf-2.7.18-8.SP7_redhat_1.1.ep6.el6.src.rpm dom4j-eap6-1.6.1-22.redhat_9.1.ep6.el6.src.rpm hornetq-2.3.25-28.SP29_redhat_1.1.ep6.el6.src.rpm ironjacamar-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-appclient-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-cli-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-client-all-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-clustering-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-cmp-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-configadmin-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-connector-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-console-2.5.19-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-controller-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-controller-client-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-core-security-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-deployment-repository-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-deployment-scanner-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-domain-http-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-domain-management-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-ee-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-ee-deployment-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-ejb3-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-embedded-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-host-controller-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-jacorb-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-jaxr-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-jaxrs-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-jdr-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-jmx-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-jpa-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-jsf-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-jsr77-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-logging-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-mail-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-management-client-content-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-messaging-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-modcluster-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-naming-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-network-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-osgi-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-osgi-configadmin-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-osgi-service-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-picketlink-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-platform-mbean-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-pojo-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-process-controller-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-protocol-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-remoting-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-sar-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-security-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-server-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-system-jmx-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-threads-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-transactions-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-version-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-web-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-webservices-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-weld-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-as-xts-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-hal-2.5.19-1.Final_redhat_1.1.ep6.el6.src.rpm jboss-remote-naming-1.0.15-1.Final_redhat_1.1.ep6.el6.src.rpm jbossas-appclient-7.5.22-2.Final_redhat_1.1.ep6.el6.src.rpm jbossas-bundles-7.5.22-2.Final_redhat_1.1.ep6.el6.src.rpm jbossas-core-7.5.22-2.Final_redhat_1.1.ep6.el6.src.rpm jbossas-domain-7.5.22-2.Final_redhat_1.1.ep6.el6.src.rpm jbossas-javadocs-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jbossas-modules-eap-7.5.22-1.Final_redhat_1.1.ep6.el6.src.rpm jbossas-product-eap-7.5.22-2.Final_redhat_1.1.ep6.el6.src.rpm jbossas-standalone-7.5.22-2.Final_redhat_1.1.ep6.el6.src.rpm jbossas-welcome-content-eap-7.5.22-2.Final_redhat_1.1.ep6.el6.src.rpm jbossweb-7.5.30-1.Final_redhat_1.1.ep6.el6.src.rpm resteasy-2.3.23-1.Final_redhat_1.1.ep6.el6.src.rpm noarch: apache-cxf-2.7.18-8.SP7_redhat_1.1.ep6.el6.noarch.rpm dom4j-eap6-1.6.1-22.redhat_9.1.ep6.el6.noarch.rpm hornetq-2.3.25-28.SP29_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-common-api-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-common-impl-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-common-spi-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-core-api-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-core-impl-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-deployers-common-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-jdbc-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-spec-api-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm ironjacamar-validator-eap6-1.0.43-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-appclient-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-cli-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-client-all-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-clustering-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-cmp-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-configadmin-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-connector-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-console-2.5.19-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-controller-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-controller-client-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-core-security-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-deployment-repository-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-deployment-scanner-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-domain-http-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-domain-management-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-ee-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-ee-deployment-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-ejb3-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-embedded-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-host-controller-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-jacorb-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-jaxr-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-jaxrs-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-jdr-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-jmx-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-jpa-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-jsf-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-jsr77-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-logging-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-mail-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-management-client-content-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-messaging-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-modcluster-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-naming-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-network-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-osgi-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-osgi-configadmin-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-osgi-service-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-picketlink-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-platform-mbean-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-pojo-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-process-controller-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-protocol-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-remoting-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-sar-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-security-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-server-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-system-jmx-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-threads-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-transactions-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-version-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-web-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-webservices-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-weld-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-as-xts-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-hal-2.5.19-1.Final_redhat_1.1.ep6.el6.noarch.rpm jboss-remote-naming-1.0.15-1.Final_redhat_1.1.ep6.el6.noarch.rpm jbossas-appclient-7.5.22-2.Final_redhat_1.1.ep6.el6.noarch.rpm jbossas-bundles-7.5.22-2.Final_redhat_1.1.ep6.el6.noarch.rpm jbossas-core-7.5.22-2.Final_redhat_1.1.ep6.el6.noarch.rpm jbossas-domain-7.5.22-2.Final_redhat_1.1.ep6.el6.noarch.rpm jbossas-javadocs-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jbossas-modules-eap-7.5.22-1.Final_redhat_1.1.ep6.el6.noarch.rpm jbossas-product-eap-7.5.22-2.Final_redhat_1.1.ep6.el6.noarch.rpm jbossas-standalone-7.5.22-2.Final_redhat_1.1.ep6.el6.noarch.rpm jbossas-welcome-content-eap-7.5.22-2.Final_redhat_1.1.ep6.el6.noarch.rpm jbossweb-7.5.30-1.Final_redhat_1.1.ep6.el6.noarch.rpm resteasy-2.3.23-1.Final_redhat_1.1.ep6.el6.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-8034 https://access.redhat.com/security/cve/CVE-2018-10934 https://access.redhat.com/security/cve/CVE-2018-1000632 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXNmlE9zjgjWX9erEAQh2hA//WufFPgxlJy2hW535Vz9SOpiF+C5ixMvB Q6I9qDmhBLIRWTswo/HGIT+584YO1Oxm5fVNAVVfpeblVSpYNb8eglc/f41pRk6w 1oYpRgkUEPS0p0xe4q7PxKBdMEim3EnNzyBFiBhdS2M3h9/bjeKdssui3OWYAGv3 b2UrSziOlHQD2n6BQXE6DeTYFVWMl+S/TPouvtdUSwp+tNGzOfRwza7p5ZxNjoyh ckB7devVS+vZ4JT8FNjYJXQtgiy3JQKCCZ//HhqLICkIkeceqIGUnfc2aUL5heoI q31kT2pku9oJmzkzvXBit5oS83oiztvwQxGYp0DKafxUBxeF9X1UqMJD/9MlgQrR 1imEHVXJDqwe8AJZYm/+ywC2LynkaPt3WEQtKjUhFh5VS2c8tcS8bVywJvf+WUwA NIOaKTcQefNF9XHLy3jsozjzv0rzyfbqCua1azIa62MnCxWxL4f0HG/OxfZvZB4B 5hD/xDn/VEbNyLYjcACdmK7criIzHmW4FJqg6qoRu4xSK+zTIx0ZBHmi1cctW1KR 3ZlTg8PiAaQPixYVIibCSiMPQ1EhpvAEIUc5nNgXThKVPa8I+FKTWnilvebwIKw5 PhFXw8PH/n+R5wwgaxsc9TEB+y4sCdA6f0LtYU20Wvosf+OcqGUfcklO0TPY9mUk nfB/tw0VmEk=4Z+T -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Elevate your platform to Red Hat JBoss Enterprise Application 6.4.22 to mitigate moderate vulnerabilities such as XSS and XML injection threats.. Red Hat JBoss, Enterprise Application, Security Advisory, Application Updates, Web Application Security. . LinuxSecurity.com Team

Calendar%202 May 13, 2019 Red Hat
98

RedHat: RHSA-2019-0362-01 Moderate: JBoss App Platform Security Update

An update is now available for Red Hat JBoss Enterprise Application Platform 7.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat JBoss Enterprise Application Platform 7.1.6 security update Advisory ID: RHSA-2019:0362-01 Product: Red Hat JBoss Enterprise Application Platform Advisory URL: https://access.redhat.com/errata/RHSA-2019:0362 Issue date: 2019-02-18 CVE Names: CVE-2018-10934 CVE-2018-14642 CVE-2018-1000632 ==================================================================== 1. Summary: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat JBoss Enterprise Application Platform is a platform for Java applications based on the JBoss Application Server. This release of Red Hat JBoss Enterprise Application Platform 7.1.6 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.1.5, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * wildfly-core: Cross-site scripting (XSS) in JBoss Management Console (CVE-2018-10934) * undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer (CVE-2018-14642) * dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents (CVE-2018-1000632) For more details about the security issue(s), including the impact, aCVSS score, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. The References section of this erratum contains a download link (you must log in to download the update). The JBoss server process must be restarted for the update to take effect. 4. Bugs fixed (https://bugzilla.redhat.com/): 1615673 - CVE-2018-10934 wildfly-core: Cross-site scripting (XSS) in JBoss Management Console 1620529 - CVE-2018-1000632 dom4j: XML Injection in Class: Element. Methods: addElement, addAttribute which can impact the integrity of XML documents 1628702 - CVE-2018-14642 undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer 5. JIRA issues fixed (https://issues.redhat.com/): JBEAP-15311 - (7.1.z) Upgrade Hibernate ORM from 5.1.16 to 5.1.17 JBEAP-15370 - (7.1.z) Upgrade undertow from 1.4.18.SP9 to 1.4.18.SP11 JBEAP-15373 - [GSS](7.1.z) Upgrade ActiveMQ Artemis from 1.5.5.jbossorg-014 to 1.5.5.jbossorg-015 JBEAP-15391 - (7.1.z) Upgrade apache-cxf from 3.1.16.redhat-1 to 3.1.16.redhat-2 JBEAP-15440 - [GSS](7.1.z) Upgrade JBoss Modules from 1.6.5.Final-redhat-00001 to 1.6.7.Final JBEAP-15443 - [GSS](7.1.z) Upgrade PicketLink bindings from 2.5.5.SP12-redhat-2 to 2.5.5.SP12-redhat-3 JBEAP-15444 - [GSS](7.1.z) Upgrade PicketLink from 2.5.5.SP12-redhat-2 to 2.5.5.SP12-redhat-3 JBEAP-15463 - Tracker bug for the EAP 7.1.6 text only release JBEAP-15482 - (7.1.z) Upgrade Elytron from 1.1.11.Final to 1.1.12.Final JBEAP-15483 - (7.1.z) Upgrade Elytron-Tool from 1.0.8 to 1.0.9.Final JBEAP-15525 - [GSS](7.1.z) Upgrade to ironjacamar from 1.4.11.Final to 1.4.12.Final JBEAP-15528 - (7.1.z) Upgrade logmanager from 2.0.10.Final-redhat-1 to 2.0.11.Final JBEAP-15545 - (7.1.z) Upgrade WildFly Core to 3.0.21.Final-redhat-00001 JBEAP-15619 - [GSS](7.1.z) Upgrade jboss-ejb-client from 4.0.11 to 4.0.12 JBEAP-15627 - [GSS](7.1.z)Upgrade jboss-el-api_spec from 1.0.9.Final to 1.0.13.Final JBEAP-15747 - [GSS](7.1.z) Upgrade jastow from 2.0.6.Final-redhat-00001 to 2.0.7.Final JBEAP-15842 - [GSS](7.1.z) Upgrade jberet from 1.2.6 to 1.2.7 JBEAP-15852 - [GSS](7.1.z) Upgrade WildFly Common from 1.2.0.Final-redhat-1 to 1.2.1.Final JBEAP-15891 - [GSS](7.1.z) Upgrade Narayana from 5.5.32 to 5.5.33 JBEAP-16015 - [GSS](7.1.z) Upgrade Narayana from 5.5.32 to 5.5.34 JBEAP-9658 - (7.1.z) Upgrade jboss-negotiation to 3.0.5 6. References: https://access.redhat.com/security/cve/CVE-2018-10934 https://access.redhat.com/security/cve/CVE-2018-14642 https://access.redhat.com/security/cve/CVE-2018-1000632 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=appplatform&version=7.1 https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/?version=7.1 https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/ 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXGrSldzjgjWX9erEAQhfxRAAjFDmSGcgQwqcVAFVeL4MuQaF+Ay1zXh1 QHxWomeMJqyxZVYZQK1+5l3ANSDRvmAH3wgpxyFz/q6JP2KdBK4Vx8Smgx3zcOLY X7sOLMOGSPXP5NBKHE/wEom1GBPLS3G32iXKmjhUqP7gKbFdbht0kkksnsABwTP9 tuI4OLzF3xtnv0SMAUXoZ7T0FEvdCeLkm72oMvIzkEECbjVvdzJ5VvR+GQQxZakR g2tQRKcywfbXoiDYITkXpgoQSwRJavRnX3f5QZgQ5vz9socD4TgEAcwkWN7r/PJN hITIvNeix0Ip5KPhaVeI3ruWI+AxSC1vxj7r9S3j8x7fOWS4JIQZMKlhty/EiLiR xHzfM2S14TnaElnZ3xU+6Mt8QcCDPIJmH+NDM7Tmw0gsoTZCM4BGqm0n3cE5Yyt5 QHBDuMI37boTNgnZjjE46VJOhGRQAVVLOOgmrtlASD6En/54UF1JsbpXdhh4KWow 2N88k0nfAcpmCngqAFP6JFo6Vq0h9tSle1RLtAl3LEaNfAZ03zkkiXma4YbGDt8Y e9cSFHK9Qva+9Sevo+bjmq22sL3HwXznhrcJI1zoJiwp3T/iHv1wXIgvXJ40rfq8 ax0SZ5AnKrv5LWR9uleaQ7ioFUe75Tv9CbD1opm/Af0DQSqKI2LPOAFjoAT7PZwC y8aLL5A+5Eg=8Qq+ -----END PGPSIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest release of Red Hat JBoss Enterprise Application Platform includes a crucial security patch that tackles vulnerabilities related to cross-site scripting (XSS) and data exposure.. RedHat JBoss, Security Advisory, Application Platform, Update, Info Leak. . LinuxSecurity.com Team

Calendar%202 Feb 18, 2019 Red Hat
100

SUSE: 2018:3908-1 Moderate: dom4j XML Injection Threat Update

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for dom4j ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3908-1 Rating: moderate References: #1105443 Cross-References: CVE-2018-1000632 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for dom4j fixes the following issues: - CVE-2018-1000632: Prevent XML injection that could have resulted in an attacker tampering with XML documents (bsc#1105443). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2018-8795=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (noarch): dom4j-1.6.1-4.3.2 dom4j-demo-1.6.1-4.3.2 dom4j-javadoc-1.6.1-4.3.2 dom4j-manual-1.6.1-4.3.2 References: https://www.suse.com/security/cve/CVE-2018-1000632.html https://bugzilla.suse.com/1105443 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update: dom4j patch prevents XML injection threats. Advisory ID: SUSE-SU-2018:3908-1.. SUSE Security Update, dom4j Security Fix, XML Injection Prevention, SUSE Development Tools Patch. . LinuxSecurity.com Team

Calendar%202 Nov 26, 2018 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200