Upgrade to Ruby 2.7.3.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-6385a09efc 2021-04-17 14:06:11.337489 --------------------------------------------------------------------------------Name : ruby Product : Fedora 33 Version : 2.7.3 Release : 136.fc33 URL : https://www.ruby-lang.org/ Summary : An interpreter of object-oriented scripting language Description : Ruby is the interpreted scripting language for quick and easy object-oriented programming. It has many features to process text files and to do system management tasks (as in Perl). It is simple, straight-forward, and extensible. --------------------------------------------------------------------------------Update Information: Upgrade to Ruby 2.7.3. --------------------------------------------------------------------------------ChangeLog: * Wed Apr 7 2021 Pavel Valena - 2.7.3-136 - Upgrade to Ruby 2.7.3. --------------------------------------------------------------------------------References: [ 1 ] Bug #1947526 - CVE-2021-28965 ruby: XML round-trip vulnerability in REXML https://bugzilla.redhat.com/show_bug.cgi?id=1947526 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-6385a09efc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Data Grid 7.3.8 security update Advisory ID: RHSA-2020:5410-01 Product: Red Hat JBoss Data Grid Advisory URL: https://access.redhat.com/errata/RHSA-2020:5410 Issue date: 2020-12-14 CVE Names: CVE-2020-25644 CVE-2020-25649 ==================================================================== 1. Summary: An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Data Grid is a distributed, in-memory, NoSQL datastore based on the Infinispan project. This release of Red Hat Data Grid 7.3.8 serves as a replacement for Red Hat Data Grid 7.3.7 and includes bug fixes and enhancements, which are described in the Release Notes, linked to in the References section of this erratum. Security Fix(es): * wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL (CVE-2020-25644) * jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) (CVE-2020-25649) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: To install this update, do the following: 1. Download the Data Grid 7.3.8 server patch from the customer portal.See the download link in the References section. 2. Back up your existing Data Grid installation. You should back up databases, configuration files, and so on. 3. Install the Data Grid 7.3.8 server patch. Refer to the 7.3 Release Notes for patching instructions. 4. Restart Data Grid to ensure the changes take effect. 4. Bugs fixed (https://bugzilla.redhat.com/): 1885485 - CVE-2020-25644 wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL 1887664 - CVE-2020-25649 jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) 5. References: https://access.redhat.com/security/cve/CVE-2020-25644 https://access.redhat.com/security/cve/CVE-2020-25649 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=data.grid&downloadType=securityPatches&version=7.3 https://access.redhat.com/documentation/en-us/red_hat_data_grid/7.3/ 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX9emjtzjgjWX9erEAQiNVxAAi0ep0/wcoyArgPwQSXS3a2JePbmC2VKe /29gx/nj70agJX62B9b5iA+UbbLsYuowH4UKcYII/cD4KWgPjk+G8TdGov2kWy9P OFtQvhP8f9reSlSWfEjzoMlTGfaUIg6xRsP6ClWpBr76xTxb/w07tGX8j1Mn9qjC s29Nfz8lYxWyDNhnUsnPNacDB7qIrHrv38eRqTn+jimZLrXtR8ktJWOmN96XRyIZ iuCkvpGOimVXugkqgITY6f0HYHFYOq6c05Q0M8sShz526l/ewnUpv0PtZzTwyCU6 OzyV5tcF/4VAHF7l/WoLV8R+jdXnq3Zqd1gx509Bwkg4VMNSXB0qBT7ldKmuYrBg BUvErN/LQ27g9kkKnQrLWWlxHTs687KxmNhGn9uKMzO0iBFq4/pt/aVh/RoAkO3H NnZ2SD6t3UAsyVZ/xeVENhzn5+0JT7qhtjwmtKy7PI04B/ikO37lJ4x9lNhhdevt DAuK/qiTTu7467v9V2g3dA8ke+2LVmITNNKrGxXcEvxdhA+m1dnzmzD1h3r8Rm2h NFF0zQlORj+DVQN7rbhx2bN62/C2z5R2J2OjOWZxlME9qste6cwGan3Z/r1xQUmp TXbH4S9aJsggZ6nfdRuWxvvLujiy7hniBPWVKGRx2Po1GawHflK2bA61zDeTesg4 QPDe2x7xQHE=DiHA -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Several vulnerabilities were fixed in libjackson-json-java, a Java JSON processor. CVE-2017-7525 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2342-1
An update for Debezium PostgreSQL connector is now available for Red Hat Integration. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Integration Debezium 1.1.3 security update Advisory ID: RHSA-2020:3005-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2020:3005 Issue date: 2020-07-20 CVE Names: CVE-2020-13692 ==================================================================== 1. Summary: An update for Debezium PostgreSQL connector is now available for Red Hat Integration. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: PostgreSQL is an advanced object-relational database management system. The Debezium PostgreSQL connector includes JDBC driver to access a PostgreSQL database. Security Fix(es): * postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML (CVE-2020-13692) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: To apply this update just follow standard installation procedure tml/installing_debezium_on_openshift/installing_debezium_connectors 4. Bugs fixed (https://bugzilla.redhat.com/): 1852985 - CVE-2020-13692 postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML 5.References: https://access.redhat.com/security/cve/CVE-2020-13692 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2020-Q2 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXxYDxdzjgjWX9erEAQiYog/7B/Df8p8sIa7tdtA4psly1niYKiCPPs1q FPxPn2n7VMXOb8okSlu1iwHN8HyJAcv52DXug0ez1nbcOSkMEshkrHDhh1iTBMJe xkQxHaL+JwFBhI/S/CDP/b42soHA1aYTZSRaKBSk5Kk3JE1J8f8dyDspLgDwd9P2 E3op1LMySUnI8cFXOeKbmP/O1qnGdpyc6UvqYOxxJRCq0Ft1nFgJQMkMFMwt02Iv IllTgvJxix0+70Dh+VNPFVe8Yu+V1+SGtY6INrbs0rvuhqemr4LNYBXjSDoUdTZN wtZXD97rB/dfUWpTkY4JcgeMAnQ/tT/e0x3TLePNJaPuXLNASZpvT+C2bnc960YK 1UvdPvPIsJ9WEkvYirHTF2Ydw3o0adZd+PJs5HTgz+qhV+6BeaLJodkG+IjPyBI8 49oMYvsnEQHJAmzaO8EV+j45PevP+U4H3sM55t69lAtQ1PgLfiIwV4hqxas7NjMk Kfzj/Xfonz56Y4ib8CBS8bMfG5NgUhK/Eth4sIGS+e/H4TJyMh6JXqZkLD9WfwqH HnjXMl75n0WSf+1xjvkhgT2XVp9njwidz9LgoAvqg8GfeqPfck/f1wvaRKgoHQBC 3iCwS+9ABDbc7jzqp9R2XFb5h3svjlTs1sWFOVF7AqhxeVBVPTbn02puDu6sIUAi dVioDVBtf54=7cOd -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.