Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.


LinuxSecurity.com Feature Extras:

What we Can Learn from the Recent VLC Security Vulnerability Fiasco: A Conversation with VideoLAN President Jean-Baptiste Kempf - About a week ago, the LinuxSecurity staff started tracking a security issue related to VLC , the popular open source media player. Security vulnerabilities are a regular part of the software development lifecycle. These vulnerabilities are identified, then a solution is created and distributed to its users. In this case, it wasnt completely clear whether thats what happened, though. We decided to find out.

LinuxSecurity.com Launches New site, Celebrates 20 Years of Following Open Source Security News and Resources - July 29, 2019 - Midland Park, NJ -- LinuxSecurity.com, the open-source communitys go-to source for security news and information, has revealed a completely new site design and a renewed focus on providing timely, authoritative industry content. 


  Debian: DSA-4493-1: postgresql-11 security update (Aug 8)
 

Two security issues have been discovered in the PostgreSQL database system, which could result in privilege escalation, denial of service or memory disclosure.

  Debian: DSA-4492-1: postgresql-9.6 security update (Aug 8)
 

A issue has been discovered in the PostgreSQL database system, which could result in privilege escalation. For additional information please refer to the upstream announcement at

  Debian: DSA-4491-1: proftpd-dfsg security update (Aug 4)
 

Tobias Maedel discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands.

 
  Fedora 30: exiv2 FEDORA-2019-60553d5a18 (Aug 8)
 

New upstream bugfix and security release.

  Fedora 29: php FEDORA-2019-f07db8f031 (Aug 7)
 

**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows

  Fedora 29: sqlite FEDORA-2019-3377813d18 (Aug 7)
 

Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting.

  Fedora 30: php FEDORA-2019-ec40d89812 (Aug 7)
 

**PHP version 7.2.21** (01 Aug 2019) **Date:** * Fixed bug php#69044 (discrepency between time and microtime). (krakjoe) **EXIF:** * Fixed bug php#78256 (heap-buffer-overflow on exif_process_user_comment). (CVE-2019-11042) (Stas) * Fixed bug php#78222 (heap-buffer-overflow on exif_scan_thumbnail). (CVE-2019-11041) (Stas) **Fileinfo:** * Fixed bug php#78183 (finfo_file shows

  Fedora 29: hostapd FEDORA-2019-d6bc3771a4 (Aug 6)
 

Security fix for CVE-2019-11555 Update to version 2.8 from upstream Drop obsoleted patches

  Fedora 29: gvfs FEDORA-2019-e6b02af8b8 (Aug 5)
 

Update to 1.38.3

  Fedora 30: kernel-headers FEDORA-2019-7aecfe1c4b (Aug 5)
 

The 5.2.5 stable kernel update contains a number of important fixes across the tree. This should also fix the black screen issue that several i915 users were hitting with 5.2.4. ---- The 5.2.4 kernel rebase contains new features and hardware support, and a number of important fixes across the tree.

  Fedora 30: kernel-tools FEDORA-2019-7aecfe1c4b (Aug 5)
 

The 5.2.5 stable kernel update contains a number of important fixes across the tree. This should also fix the black screen issue that several i915 users were hitting with 5.2.4. ---- The 5.2.4 kernel rebase contains new features and hardware support, and a number of important fixes across the tree.

  Fedora 30: kernel FEDORA-2019-7aecfe1c4b (Aug 5)
 

The 5.2.5 stable kernel update contains a number of important fixes across the tree. This should also fix the black screen issue that several i915 users were hitting with 5.2.4. ---- The 5.2.4 kernel rebase contains new features and hardware support, and a number of important fixes across the tree.

  Fedora 30: subversion FEDORA-2019-f6bc68e455 (Aug 5)
 

This update includes the latest stable release of _Apache Subversion_, version **1.12.2**. This update addresses two security vulnerabilities in **svnserve**, `CVE-2018-11782` and `CVE-2019-0203`. For more information, see: http://subversion.apache.org/security/CVE-2018-11782-advisory.txt https://subversion.apache.org/security/CVE-2019-0203-advisory.txt ## User-

  Fedora 29: java-11-openjdk FEDORA-2019-56a658c60c (Aug 3)
 

July CPU update. See: http://openjdk.java.net/groups/vulnerability/advisories/2019-07-16 and https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-July/001423.html

  Fedora 30: matrix-synapse FEDORA-2019-80f1943143 (Aug 3)
 

This release includes four security fixes: - Prevent an attack where a federated server could send redactions for arbitrary events in v1 and v2 rooms. - Prevent a denial-of-service attack where cycles of redaction events would make Synapse spin infinitely. - Prevent an attack where users could be joined or parted from public rooms without their consent. - Fix a vulnerability where a

  Fedora 30: java-11-openjdk FEDORA-2019-a9825cfb3d (Aug 2)
 

July CPU update. See: http://openjdk.java.net/groups/vulnerability/advisories/2019-07-16 and https://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-July/001423.html

 
  Gentoo: GLSA-201908-02: libpng: Multiple vulnerabilities (Aug 3)
 

Multiple vulnerabilities have been found in libpng, the worst of which could result in a Denial of Service condition.

  Gentoo: GLSA-201908-01: Binutils: Multiple vulnerabilities (Aug 3)
 

Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More...]

 
  RedHat: RHSA-2019-2425:01 Important: qemu-kvm-rhev security and bug fix (Aug 8)
 

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 13.0 (Queens), and Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact

  RedHat: RHSA-2019-2413:01 Important: Red Hat Fuse 7.4.0 security update (Aug 8)
 

A minor version update (from 7.3 to 7.4) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

  RedHat: RHSA-2019-2411:01 Important: kernel security update (Aug 7)
 

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-2405:01 Important: kernel-rt security update (Aug 7)
 

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-2399:01 Important: libssh2 security update (Aug 7)
 

An update for libssh2 is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

  RedHat: RHSA-2019-2403:01 Important: augeas security update (Aug 7)
 

An update for augeas is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

  RedHat: RHSA-2019-2402:01 Important: systemd security update (Aug 7)
 

An update for systemd is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

  RedHat: RHSA-2019-2400:01 Important: perl security update (Aug 7)
 

An update for perl is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

  RedHat: RHSA-2019-2401:01 Important: procps-ng security update (Aug 7)
 

An update for procps-ng is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

  RedHat: RHSA-2019-2002:01 Important: redis:5 security update (Aug 7)
 

An update for the redis:5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-2097:01 Moderate: perl-Archive-Tar security update (Aug 6)
 

An update for perl-Archive-Tar is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2060:01 Moderate: dhcp security and bug fix update (Aug 6)
 

An update for dhcp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2169:01 Important: linux-firmware security, bug fix, (Aug 6)
 

An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-2053:01 Moderate: libtiff security update (Aug 6)
 

An update for libtiff is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2035:01 Low: python-requests security update (Aug 6)
 

An update for python-requests is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2110:01 Moderate: rsyslog security and bug fix update (Aug 6)
 

An update for rsyslog is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2229:01 Moderate: spice-gtk security and bug fix update (Aug 6)
 

An update for spice-gtk, libgovirt, spice-vdagent, and virt-viewer is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2101:01 Low: exiv2 security, bug fix, (Aug 6)
 

An update for exiv2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2078:01 Low: qemu-kvm security, bug fix, (Aug 6)
 

An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2281:01 Low: ghostscript security, bug fix, (Aug 6)
 

An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2029:01 Important: kernel security, bug fix, (Aug 6)
 

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-2136:01 Moderate: libssh2 security, bug fix, (Aug 6)
 

An update for libssh2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2112:01 Moderate: mod_auth_openidc security update (Aug 6)
 

An update for mod_auth_openidc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2046:01 Moderate: polkit security and bug fix update (Aug 6)
 

An update for polkit is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2166:01 Moderate: qemu-kvm-ma security and bug fix update (Aug 6)
 

An update for qemu-kvm-ma is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2130:01 Low: libreoffice security and bug fix update (Aug 6)
 

An update for libreoffice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2177:01 Moderate: sssd security, bug fix, (Aug 6)
 

An update for sssd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2308:01 Low: libguestfs-winsupport security update (Aug 6)
 

An update for libguestfs-winsupport is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2290:01 Low: libsolv security and bug fix update (Aug 6)
 

An update for libsolv is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2043:01 Important: kernel-rt security and bug fix update (Aug 6)
 

An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-2033:01 Low: patch security and bug fix update (Aug 6)
 

An update for patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2057:01 Moderate: bind security, bug fix, (Aug 6)
 

An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2332:01 Low: advancecomp security update (Aug 6)
 

An update for advancecomp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2022:01 Moderate: poppler security, bug fix, (Aug 6)
 

An update for poppler, evince, and okular is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2205:01 Moderate: tomcat security, bug fix, (Aug 6)
 

An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2126:01 Low: libwpd security update (Aug 6)
 

An update for libwpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2197:01 Low: elfutils security, bug fix, (Aug 6)
 

An update for elfutils is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2304:01 Moderate: openssl security and bug fix update (Aug 6)
 

An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2047:01 Moderate: libcgroup security update (Aug 6)
 

An update for libcgroup is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2181:01 Low: curl security and bug fix update (Aug 6)
 

An update for curl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2091:01 Moderate: systemd security, bug fix, (Aug 6)
 

An update for systemd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2280:01 Moderate: uriparser security update (Aug 6)
 

An update for uriparser is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2162:01 Low: blktrace security update (Aug 6)
 

An update for blktrace is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2154:01 Moderate: opensc security, bug fix, (Aug 6)
 

An update for opensc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2135:01 Moderate: qt5 security, bug fix, (Aug 6)
 

An update is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2343:01 Moderate: httpd security and bug fix update (Aug 6)
 

An update for httpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2327:01 Moderate: mariadb security and bug fix update (Aug 6)
 

An update for mariadb is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2118:01 Moderate: glibc security and bug fix update (Aug 6)
 

An update for glibc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2037:01 Moderate: fence-agents security, bug fix, (Aug 6)
 

An update for fence-agents is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2159:01 Low: unzip security update (Aug 6)
 

An update for unzip is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2189:01 Moderate: procps-ng security and bug fix update (Aug 6)
 

An update for procps-ng is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2196:01 Low: zziplib security update (Aug 6)
 

An update for zziplib is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2294:01 Moderate: libvirt security, bug fix, (Aug 6)
 

An update for libvirt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2276:01 Moderate: mercurial security update (Aug 6)
 

An update for mercurial is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2143:01 Low: openssh security, bug fix, (Aug 6)
 

An update for openssh is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2079:01 Moderate: Xorg security and bug fix update (Aug 6)
 

An update for Xorg is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2028:01 Moderate: ruby security update (Aug 6)
 

An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2048:01 Low: exempi security update (Aug 6)
 

An update for exempi is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2017:01 Moderate: zsh security and bug fix update (Aug 6)
 

An update for zsh is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2051:01 Low: compat-libtiff3 security update (Aug 6)
 

An update for compat-libtiff3 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2030:01 Moderate: python security and bug fix update (Aug 6)
 

An update for python is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2137:01 Low: keycloak-httpd-client-install security, (Aug 6)
 

An update for keycloak-httpd-client-install is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2099:01 Moderate: samba security, bug fix, (Aug 6)
 

An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2157:01 Low: freerdp and vinagre security, bug fix, (Aug 6)
 

An update for freerdp and vinagre is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2141:01 Low: kde-workspace security and bug fix update (Aug 6)
 

An update for kde-workspace, kde-settings, kdelibs, kmag, and virtuoso-opensource is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2283:01 Low: sox security update (Aug 6)
 

An update for sox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2237:01 Moderate: nss, nss-softokn, nss-util, (Aug 6)
 

An update for nss, nss-softokn, nss-util, and nspr is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2285:01 Moderate: keepalived security and bug fix update (Aug 6)
 

An update for keepalived is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2052:01 Moderate: libjpeg-turbo security update (Aug 6)
 

An update for libjpeg-turbo is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2049:01 Moderate: libmspack security update (Aug 6)
 

An update for libmspack is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2125:01 Moderate: ovmf security and enhancement update (Aug 6)
 

An update for ovmf is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2178:01 Moderate: udisks2 security, bug fix, (Aug 6)
 

An update for udisks2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2272:01 Moderate: python-urllib3 security update (Aug 6)
 

An update for python-urllib3 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-2258:01 Moderate: http-parser security update (Aug 6)
 

An update for http-parser is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2336:01 Moderate: unixODBC security update (Aug 6)
 

An update for unixODBC is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2298:01 Moderate: libarchive security update (Aug 6)
 

An update for libarchive is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2075:01 Moderate: binutils security and bug fix update (Aug 6)
 

An update for binutils is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2077:01 Low: ntp security, bug fix, and enhancement update (Aug 6)
 

An update for ntp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-2145:01 Moderate: gvfs security and bug fix update (Aug 6)
 

An update for gvfs is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

 
  Slackware: 2019-220-01: kdelibs Security Update (Aug 8)
 

New kdelibs packages are available for Slackware 14.2 and -current to fix a security issue.

 
  SUSE: 2019:14142-1 important: python (Aug 8)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:2091-1 important: python (Aug 8)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:2092-1 moderate: squid (Aug 8)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2089-1 moderate: squid (Aug 8)
 

An update that fixes three vulnerabilities is now available.

  SUSE: 2019:2087-1 moderate: tcpdump (Aug 7)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:2088-1 moderate: tcpdump (Aug 7)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:2081-1 important: nodejs10 (Aug 7)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2019:2080-1 important: evince (Aug 7)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:14141-1 important: evince (Aug 7)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:2078-1 important: nodejs4 (Aug 7)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2072-1 important: the Linux Kernel (Aug 7)
 

An update that solves 7 vulnerabilities and has 70 fixes is now available.

  SUSE: 2019:2071-1 important: the Linux Kernel (Aug 7)
 

An update that solves 7 vulnerabilities and has 48 fixes is now available.

  SUSE: 2019:2071-1 important: the Linux Kernel (Aug 7)
 

An update that solves 7 vulnerabilities and has 48 fixes is now available.

  SUSE: 2019:2072-1 important: the Linux Kernel (Aug 7)
 

An update that solves 7 vulnerabilities and has 70 fixes is now available.

  SUSE: 2019:2067-1 important: osc (Aug 6)
 

An update that solves one vulnerability and has 5 fixes is now available.

  SUSE: 2019:2066-1 moderate: python-Twisted (Aug 6)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2064-1 important: python (Aug 6)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2050-1 important: python3 (Aug 6)
 

An update that solves two vulnerabilities and has one errata is now available.

  SUSE: 2019:14139-1 important: bzip2 (Aug 6)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2053-1 important: python3 (Aug 6)
 

An update that fixes three vulnerabilities is now available.

  SUSE: 2019:2052-1 important: evince (Aug 6)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2055-1 important: nodejs8 (Aug 6)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2019:2050-1 important: python3 (Aug 6)
 

An update that solves two vulnerabilities and has one errata is now available.

  SUSE: 2019:1783-2 important: postgresql10 (Aug 5)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2048-1 important: mariadb (Aug 5)
 

An update that solves 12 vulnerabilities and has two fixes is now available.

  SUSE: 2019:2049-1 important: ceph (Aug 5)
 

An update that solves two vulnerabilities and has 12 fixes is now available.

  SUSE: 2019:2047-1 moderate: python-requests (Aug 5)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2043-1 moderate: openexr (Aug 2)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2042-1 moderate: python-Django (Aug 2)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2034-1 moderate: python-Django1 (Aug 1)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2035-1 important: polkit (Aug 1)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:2036-1 important: java-1_8_0-openjdk (Aug 1)
 

An update that solves 8 vulnerabilities and has one errata is now available.

 
  Ubuntu 4090-1: PostgreSQL vulnerabilities (Aug 8)
 

Several security issues were fixed in PostgreSQL.

  Ubuntu 4089-1: Rack vulnerability (Aug 7)
 

Rack could allow cross-site scripting (XSS) attacks.

  Ubuntu 4088-1: PHP vulnerability (Aug 7)
 

PHP could be made to denial of service, expose sensitive information or execute arbitrary code if it received a specially crafted regular expression.

  Ubuntu 4087-1: BWA vulnerability (Aug 6)
 

BWA could be made to crash or run programs as your login if it opened a specially crafted file.

  Ubuntu 4086-1: Mercurial vulnerability (Aug 6)
 

Mercurial could be made to overwrite files.

  Ubuntu 4049-4: GLib regression (Aug 6)
 

USN-4049-1 introduced a regression in GLib.

  Ubuntu 4049-3: GLib regression (Aug 5)
 

USN-4049-1 introduced a regression in GLib.

  Ubuntu 4058-2: Bash vulnerability (Aug 5)
 

A system hardening measure could be bypassed.

  Ubuntu 4079-2: SoX vulnerabilities (Aug 1)
 

SoX could be made to crash if it received a specially crafted MP3 file.

  Ubuntu 4085-1: Sigil vulnerability (Aug 1)
 

Sigil could be made to overwrite files.

  Ubuntu 4084-1: Django vulnerabilities (Aug 1)
 

Several security issues were fixed in Django.

  Ubuntu 4069-2: Linux kernel (HWE) vulnerabilities (Aug 1)
 

Several security issues were fixed in the Linux kernel.

 
  Debian LTS: DLA-1874-1: postgresql-9.4 security update (Aug 9)
 

* CVE-2019-10208: `TYPE` in `pg_temp` executes arbitrary SQL during `SECURITY DEFINER` execution Versions Affected: 9.4 - 11

  Debian LTS: DLA-1873-1: proftpd-dfsg security update (Aug 7)
 

Tobias Maedel discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands.

  Debian LTS: DLA-1872-1: python-django security update (Aug 6)
 

It was discovered that there were two vulnerabilities in the Django web development framework: * CVE-2019-14232: Prevent a possible denial-of-service in

  Debian LTS: DLA-1866-2: glib2.0 regression update (Aug 5)
 

Simon McVittie spotted a memory leak regression in the way CVE-2019-13012 had been resolved for glib2.0 in Debian jessie.

  Debian LTS: DLA-1871-1: vim security update (Aug 3)
 

Several minor issues have been fixed in vim, a highly configurable text editor.

  Debian LTS: DLA-1868-1: squirrelmail security update (Aug 1)
 

A XSS vulnerability was discovered in SquirrelMail. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mails can be executed within the application context via

 
  ArchLinux: 201908-5: sdl2: arbitrary code execution (Aug 7)
 

The package sdl2 before version 2.0.10-1 is vulnerable to arbitrary code execution.

  ArchLinux: 201908-4: exim: arbitrary code execution (Aug 7)
 

The package exim before version 4.92.1-1 is vulnerable to arbitrary code execution.

  ArchLinux: 201908-3: python2-django: multiple issues (Aug 7)
 

The package python2-django before version 1.11.23-1 is vulnerable to multiple issues including denial of service and sql injection.

  ArchLinux: 201908-2: python-django: multiple issues (Aug 7)
 

The package python-django before version 2.2.4-1 is vulnerable to multiple issues including denial of service and sql injection.

  ArchLinux: 201908-1: chromium: multiple issues (Aug 5)
 

The package chromium before version 76.0.3809.87-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, content spoofing, denial of service and insufficient validation.

 
  openSUSE: 2019:1839-1: moderate: python-Django (Aug 8)
 

An update that fixes 7 vulnerabilities is now available.

  openSUSE: 2019:1840-1: important: vlc (Aug 8)
 

An update that fixes 7 vulnerabilities is now available.

  openSUSE: 2019:1836-1: important: proftpd (Aug 8)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2019:1834-1: moderate: aubio (Aug 6)
 

An update that fixes four vulnerabilities is now available.

  openSUSE: 2019:1831-1: moderate: spamassassin (Aug 6)
 

An update that solves four vulnerabilities and has three fixes is now available.

  openSUSE: 2019:1824-1: important: rmt-server (Aug 1)
 

An update that solves two vulnerabilities and has 10 fixes is now available.

  openSUSE: 2019:1826-1: moderate: openexr (Aug 1)
 

An update that fixes three vulnerabilities is now available.

 
  Mageia 2019-0217: kernel security update (Aug 3)
 

This kernel update is based on the upstream 5.1.20 and fixes atleast the following security issue: With Xen, virtual device backends and device models running in domain 0, or other backend driver domains, need to be able to map guest memory