Thank you for reading the Linux Advisory Watch Security Newsletter. The purpose of this document is to provide our readers with a quick summary of each week's vendor security bulletins and pointers on methods to improve the security posture of your open source system. Vulnerabilities affect nearly every vendor virtually every week, so be sure to read through to find the updates your distributor have made available.

LinuxSecurity.com Feature Extras:

Guardian Digital Celebrates 20 Years of Revolutionizing Digital Security, Securing Email with Open Source - Pioneers of business email security for the past 20 years, Guardian Digital draws on the merits of Open Source coupled with expert engineering and unparalleled customer support.

Press Release: Guardian Digital Leverages the Power of Open Source to Combat Evolving Email Security Threats - Cloud-based email security solution utilizes the open source methodology for securing business email, recognized by many as the best approach to the problem of maintaining security in the relentlessly dynamic environment of the Internet.


  Debian: DSA-4475-1: openssl security update (Jul 1)
 

Joran Dirk Greef discovered that overly long nonces used with ChaCha20-Poly1305 were incorrectly processed and could result in nonce reuse. This doesn't affect OpenSSL-internal uses of ChaCha20-Poly1305 such as TLS.

  Debian: DSA-4474-1: firefox-esr security update (Jul 1)
 

A sandbox escape was found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code if combined with additional vulnerabilities.

  Debian: DSA-4473-1: rdesktop security update (Jun 28)
 

Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in

  Debian: DSA-4472-1: expat security update (Jun 28)
 

It was discovered that Expat, an XML parsing C library, did not properly handled XML input including XML names that contain a large number of colons, potentially resulting in denial of service.


  Fedora 29: tomcat FEDORA-2019-d66febb5df (Jul 3)
 

This update includes a rebase from 9.0.13 up to 9.0.21 which resolves two CVEs along with various other bugs/features: * rhbz#1673856 tomcat-9.0.21 is available * rhbz#1713279 CVE-2019-0221 tomcat: XSS in SSI printenv * rhbz#1693326 CVE-2019-0199 tomcat: Apache Tomcat HTTP/2 DoS

  Fedora 29: kernel-headers FEDORA-2019-69c132b061 (Jul 2)
 

Update to v5.1.15 ---- Update to v5.1.14

  Fedora 29: kernel FEDORA-2019-69c132b061 (Jul 2)
 

Update to v5.1.15 ---- Update to v5.1.14

  Fedora 29: glpi FEDORA-2019-169f1eec7c (Jul 1)
 

Includes security fix backported from 9.4.3 * [security] Prevent execution of XSS on rich text, * [security] Prevent xss attack on user picture,

  Fedora 29: xen FEDORA-2019-899ef6056c (Jul 1)
 

Unlimited Arm Atomics Operations [XSA-295] (#1720760)

  Fedora 30: chromium FEDORA-2019-8fb8240d14 (Jun 30)
 

Update to Chromium 75.0.3770.100. The usual pile of bugs and CVE fixes. vaapi support disabled, just too broken. :( Fixes CVE-2019-5805 CVE-2019-5806 CVE-2019-5807 CVE-2019-5808 CVE-2019-5809 CVE-2019-5810 CVE-2019-5811 CVE-2019-5813 CVE-2019-5814 CVE-2019-5815 CVE-2019-5818 CVE-2019-5819 CVE-2019-5820 CVE-2019-5821 CVE-2019-5822 CVE-2019-5824 CVE-2019-5825

  Fedora 30: xen FEDORA-2019-aeda234b68 (Jun 30)
 

Unlimited Arm Atomics Operations [XSA-295] (#1720760)

  Fedora 29: pdns FEDORA-2019-08b1477c9d (Jun 29)
 

- Update to 4.1.10 Release notes: https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.10 Security Advisory: advisory-2019-04.html

  Fedora 30: pdns FEDORA-2019-2ed768623e (Jun 29)
 

- Update to 4.1.10 Release notes: https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.10 Security Advisory: advisory-2019-04.html

  Fedora 30: GraphicsMagick FEDORA-2019-da4c20882c (Jun 29)
 

New bug and security fix release, see http://www.graphicsmagick.org/NEWS.html#june-15-2019

  Fedora 30: kernel FEDORA-2019-6817686c4d (Jun 28)
 

Update to v5.1.15 ---- Update to v5.1.14

  Fedora 30: kernel-headers FEDORA-2019-6817686c4d (Jun 28)
 

Update to v5.1.15 ---- Update to v5.1.14

  Fedora 29: drupal7-uuid FEDORA-2019-a872068cd3 (Jun 28)
 

- https://www.drupal.org/project/uuid/releases/7.x-1.3 - https://www.drupal.org/sa-contrib-2019-052

  Fedora 29: php-typo3-phar-stream-wrapper2 FEDORA-2019-af7bef7165 (Jun 28)
 

## php-typo3-phar-stream-wrapper2 ### v2.1.2 Handling mime-type & Windows paths #### Resolved Issues - \#34: Normalize resolved Windows path to Unix-style - \#42: Avoid analysing non-phar files on alias resolving - \#40: Add Windows tests using AppVeyor - \#33: Add alternative mime-type resolving (without ext- fileinfo) ### v2.1.1 Phar Alias Handling & Performance Releases v3.1.1 and

  Fedora 29: php-brumann-polyfill-unserialize FEDORA-2019-af7bef7165 (Jun 28)
 

## php-typo3-phar-stream-wrapper2 ### v2.1.2 Handling mime-type & Windows paths #### Resolved Issues - \#34: Normalize resolved Windows path to Unix-style - \#42: Avoid analysing non-phar files on alias resolving - \#40: Add Windows tests using AppVeyor - \#33: Add alternative mime-type resolving (without ext- fileinfo) ### v2.1.1 Phar Alias Handling & Performance Releases v3.1.1 and


  RedHat: RHSA-2019-1636:01 Important: OpenShift Container Platform 4.1 (Jul 3)
 

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-1669:01 Important: openstack-ironic-inspector security (Jul 2)
 

An update for openstack-ironic-inspector is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-1667:01 Important: qemu-kvm-rhev security update (Jul 2)
 

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-1683:01 Moderate: openstack-tripleo-common security and (Jul 2)
 

An update for openstack-tripleo-common is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-1661:01 Low: spacewalk-backend security update (Jul 2)
 

An update for spacewalk-backend is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-1663:01 Important: spacewalk-backend and spacewalk-proxy (Jul 2)
 

An update for spacewalk-backend and spacewalk-proxy is now available for Red Hat Satellite Proxy v 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2019-1652:01 Important: libssh2 security update (Jul 2)
 

An update for libssh2 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1650:01 Low: qemu-kvm security update (Jul 2)
 

An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2019-1633:01 Moderate: Red Hat OpenShift Container Platform (Jun 27)
 

An update for atomic-openshift is now available for OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-1632:01 Moderate: Red Hat OpenShift Container Platform (Jun 27)
 

An update for atomic-openshift is now available for OpenShift Container Platform. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2019-1626:01 Important: thunderbird security update (Jun 27)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1624:01 Important: thunderbird security update (Jun 27)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1623:01 Important: thunderbird security update (Jun 27)
 

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2019-1619:01 Important: vim security update (Jun 27)
 

An update for vim is now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,


  Slackware: 2019-180-01: irssi Security Update (Jun 29)
 

New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.


  SUSE: 2019:1749-1 moderate: libu2f-host (Jul 4)
 

An update that fixes four vulnerabilities is now available.

  SUSE: 2019:1750-1 moderate: libu2f-host, pam_u2f (Jul 4)
 

An update that fixes three vulnerabilities is now available.

  SUSE: 2019:14114-1 moderate: MozillaFirefox, mozilla-nss, mozilla-nspr (Jul 4)
 

An update that contains security fixes can now be installed.

  SUSE: 2019:0048-2 moderate: helm-mirror (Jul 4)
 

An update that solves three vulnerabilities and has two fixes is now available.

  SUSE: 2019:1744-1 important: the Linux Kernel (Jul 4)
 

An update that solves three vulnerabilities and has 26 fixes is now available.

  SUSE: 2019:1744-1 important: the Linux Kernel (Jul 4)
 

An update that solves three vulnerabilities and has 26 fixes is now available.

  SUSE: 2019:1746-1 moderate: php5 (Jul 4)
 

An update that fixes three vulnerabilities is now available.

  SUSE: 2019:1733-1 elfutils (Jul 3)
 

An update that fixes 15 vulnerabilities is now available.

  SUSE: 2019:1389-2 cronie (Jul 3)
 

An update that solves two vulnerabilities and has two fixes is now available.

  SUSE: 2019:1372-2 moderate: libtasn1 (Jul 3)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1206-2 bzip2 (Jul 3)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1290-2 moderate: nmap (Jul 3)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2019:1731-1 moderate: python-Twisted (Jul 3)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1724-1 moderate: php72 (Jul 2)
 

An update that fixes two vulnerabilities is now available.

  SUSE: 2019:1725-1 moderate: php7 (Jul 2)
 

An update that solves two vulnerabilities and has one errata is now available.

  SUSE: 2019:14111-1 important: dbus-1 (Jul 2)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1722-1 important: glib2 (Jul 2)
 

An update that solves three vulnerabilities and has one errata is now available.

  SUSE: 2019:1266-2 moderate: evolution (Jul 2)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1267-2 moderate: graphviz (Jul 2)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1721-1 moderate: dnsmasq (Jul 2)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2019:1207-2 important: 389-ds (Jul 1)
 

An update that fixes 5 vulnerabilities is now available.

  SUSE: 2019:1357-2 important: curl (Jul 1)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1221-2 moderate: libxslt (Jul 1)
 

An update that fixes one vulnerability is now available.

  SUSE: 2019:1351-2 important: gnutls (Jul 1)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2019:1211-2 important: java-1_8_0-openjdk (Jul 1)
 

An update that fixes four vulnerabilities is now available.

  SUSE: 2019:1717-1 important: gvfs (Jul 1)
 

An update that solves four vulnerabilities and has one errata is now available.

  SUSE: 2019:1716-1 moderate: glibc (Jun 27)
 

An update that solves one vulnerability and has two fixes is now available.

  SUSE: 2019:1308-2 important: java-1_8_0-ibm (Jun 27)
 

An update that fixes 5 vulnerabilities is now available.


  Ubuntu: Ubuntu 18.10 (Cosmic Cuttlefish) reaches End of Life on July 18 2019 (Jul 4)
 

  Ubuntu 4046-1: Irssi vulnerabilities (Jul 4)
 

Several security issues were fixed in Irssi.

  Ubuntu 4038-4: bzip2 regression (Jul 4)
 

USN-4038-1 introduced a regression in bzip2.

  Ubuntu 4038-3: bzip2 regression (Jul 4)
 

USN-4038-1 introduced a regression in bzip2.

  Ubuntu 4044-1: ZNC vulnerability (Jul 2)
 

znc could be made to crash or run programs as an administrator if it opened a specially crafted file.

  Ubuntu 4045-1: Thunderbird vulnerabilities (Jul 2)
 

Several security issues were fixed in Thunderbird.

  Ubuntu 4043-1: Django vulnerabilities (Jul 1)
 

Several security issues were fixed in Django.

  Ubuntu 4041-2: Linux kernel (HWE) update (Jun 29)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 4041-1: Linux kernel update (Jun 29)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 4042-1: poppler vulnerabilities (Jun 27)
 

Several security issues were fixed in poppler.


  Debian LTS: DLA-1844-1: lemonldap-ng security update (Jul 4)
 

It was discovered that there was a XML external entity vulnerability in the lemonldap-ng single-sign on system. This may have led to the disclosure of confidential data, denial of service, server side request forgery, port scanning, etc.

  Debian LTS: DLA-1843-1: pdns security update (Jul 3)
 

Two vulnerabilities have been discovered in pdns, an authoritative DNS server which may result in denial of service via malformed zone records and excessive NOTIFY packets in a master/slave setup.

  Debian LTS: DLA-1842-1: python-django security update (Jul 1)
 

It was discovered that the Django Python web development framework did not correct identify HTTP connections when a reverse proxy connected via HTTPS.

  Debian LTS: DLA-1837-2: rdesktop regression update (Jul 1)
 

The update for rdesktop released as 1.8.6-0+deb8u1 introduced a regression which broke RDP protocol negotiation. Updated rdesktop packages are now available to correct this issue.

  Debian LTS: DLA-1841-1: gpac security update (Jun 30)
 

Three issues have been found for gpac, an Open Source multimedia framework. Two of them are NULL pointer dereferences and one of them is a heap-based

  Debian LTS: DLA-1840-1: golang-go.crypto security update (Jun 30)
 

A flaw was found in the amd64 implementation of salsa20. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream.

  Debian LTS: DLA-1839-1: expat security update (Jun 29)
 

It was discovered that Expat, an XML parsing C library, did not properly handle XML input including XML names that contain a large number of colons, potentially resulting in denial of service.

  Debian LTS: DLA-1838-1: mupdf security update (Jun 28)
 

Several minor issues have been fixed in mupdf, a lightweight PDF viewer tailored for display of high quality anti-aliased graphics.


  ArchLinux: 201906-22: vlc: arbitrary code execution (Jul 1)
 

The package vlc before version 3.0.7.1-1 is vulnerable to arbitrary code execution.

  ArchLinux: 201906-21: libarchive: multiple issues (Jul 1)
 

The package libarchive before version 3.4.0-1 is vulnerable to multiple issues including arbitrary code execution, denial of service and information disclosure.

  ArchLinux: 201906-20: firefox: sandbox escape (Jul 1)
 

The package firefox before version 67.0.4-1 is vulnerable to sandbox escape.

  ArchLinux: 201906-19: firefox-developer-edition: arbitrary code execution (Jul 1)
 

The package firefox-developer-edition before version 68.0b11-1 is vulnerable to arbitrary code execution.


  CentOS: CESA-2019-1650: Low CentOS 6 qemu-kvm (Jul 3)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1650

  CentOS: CESA-2019-1652: Important CentOS 6 libssh2 (Jul 3)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1652

  CentOS: CESA-2019-1624: Important CentOS 6 thunderbird (Jul 1)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1624

  CentOS: CESA-2019-1604: Critical CentOS 6 firefox (Jul 1)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1604

  CentOS: CESA-2019-1619: Important CentOS 7 vim (Jul 1)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1619

  CentOS: CESA-2019-1626: Important CentOS 7 thunderbird (Jul 1)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1626

  CentOS: CESA-2019-1603: Critical CentOS 7 firefox (Jul 1)
 

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1603


  SciLinux: SLSA-2019-1652-1 Important: libssh2 on SL6.x i386/x86_64 (Jul 2)
 

libssh2: Integer overflow in transport read resulting in out of bounds write (CVE-2019-3855) * libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856) * libssh2: Integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857) * libssh2: Integer overflow in user authenticate keyboard interactive allows out [More...]

  SciLinux: SLSA-2019-1650-1 Low: qemu-kvm on SL6.x i386/x86_64 (Jul 2)
 

QEMU: Slirp: information leakage in tcp_emu() due to uninitialized stack variables (CVE-2019-9824) SL6 x86_64 qemu-guest-agent-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-img-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-kvm-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-kvm-debuginfo-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-kvm-tools-0.12.1.2-2.506.el6_10.4.x86_64.rpm i386 qemu-gue [More...]

  SciLinux: SLSA-2019-1619-1 Important: vim on SL7.x x86_64 (Jul 1)
 

vim/neovim: ':source!' command allows arbitrary command execution via modelines (CVE-2019-12735) SL7 x86_64 vim-X11-7.4.160-6.el7_6.x86_64.rpm vim-common-7.4.160-6.el7_6.x86_64.rpm vim-debuginfo-7.4.160-6.el7_6.x86_64.rpm vim-enhanced-7.4.160-6.el7_6.x86_64.rpm vim-filesystem-7.4.160-6.el7_6.x86_64.rpm vim-minimal-7.4.160-6.el7_6.x86_64.rpm - Scientific Linux Develo [More...]

  SciLinux: SLSA-2019-1626-1 Important: thunderbird on SL7.x x86_64 (Jul 1)
 

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * thunderbird: Stack buffer overflow in icalrecur_add_bydayrules in icalrecur.c (CVE-2019-11705) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) * thunderbird: Heap buffer over read in icalparser.c parser_get_next_char (CVE-2019-11703) * thunderbird: Heap buffer overflow in icalmemory_strdup_and_dequote function in icalvalu [More...]

  SciLinux: SLSA-2019-1603-1 Critical: firefox on SL7.x x86_64 (Jul 1)
 

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) SL7 x86_64 firefox-60.7.2-1.el7_6.x86_64.rpm firefox-debuginfo-60.7.2-1.el7_6.x86_64.rpm firefox-60.7.2-1.el7_6.i686.rpm firefox-debuginfo-60.7.2-1.el7_6.i686.rpm - Scientific Linux Development Team

  SciLinux: SLSA-2019-1624-1 Important: thunderbird on SL6.x i386/x86_64 (Jun 28)
 

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * thunderbird: Stack buffer overflow in icalrecur_add_bydayrules in icalrecur.c (CVE-2019-11705) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) * thunderbird: Heap buffer over read in icalparser.c parser_get_next_char (CVE-2019-11703) * thunderbird: Heap buffer overflow in icalmemory_strdup_and_dequote function in icalvalu [More...]


  openSUSE: 2019:1689-1: moderate: phpMyAdmin (Jul 2)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2019:1690-1: moderate: irssi (Jul 2)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1689-1: moderate: phpMyAdmin (Jul 2)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2019:1690-1: moderate: irssi (Jul 2)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1688-1: moderate: libheimdal (Jul 1)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2019:1682-1: moderate: libheimdal (Jul 1)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2019:1683-1: moderate: ImageMagick (Jul 1)
 

An update that solves 9 vulnerabilities and has two fixes is now available.

  openSUSE: openSUSE Leap 42.3 has reached end of SUSE support (Jul 1)
 

openSUSE: openSUSE Leap 42.3 has reached end of SUSE support

  openSUSE: 2019:1671-1: important: dbus-1 (Jun 30)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1672-1: important: libvirt (Jun 30)
 

An update that solves three vulnerabilities and has one errata is now available.

  openSUSE: 2019:1673-1: moderate: tomcat (Jun 30)
 

An update that solves two vulnerabilities and has one errata is now available.

  openSUSE: 2019:1667-1: moderate: Recommended evince (Jun 30)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2019:1668-1: moderate: postgresql96 (Jun 30)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1669-1: moderate: wireshark (Jun 30)
 

An update that contains security fixes can now be installed.

  openSUSE: 2019:1666-1: important: chromium (Jun 28)
 

An update that fixes 53 vulnerabilities is now available.

  openSUSE: 2019:1666-1: important: chromium (Jun 28)
 

An update that fixes 53 vulnerabilities is now available.

  openSUSE: 2019:1664-1: important: MozillaThunderbird (Jun 28)
 

An update that fixes 22 vulnerabilities is now available.

  openSUSE: 2019:1658-1: moderate: libmediainfo (Jun 27)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2019:1638-1: important: gstreamer-0_10-plugins-base (Jun 27)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1632-1: moderate: SDL2 (Jun 27)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2019:1637-1: moderate: compat-openssl098 (Jun 27)
 

An update that solves one vulnerability and has two fixes is now available.

  openSUSE: 2019:1635-1: moderate: ansible (Jun 27)
 

An update that fixes four vulnerabilities is now available.

  openSUSE: 2019:1639-1: important: gstreamer-plugins-base (Jun 27)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1635-1: moderate: ansible (Jun 27)
 

An update that fixes four vulnerabilities is now available.

  openSUSE: 2019:1650-1: important: glib2 (Jun 27)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2019:1649-1: moderate: exempi (Jun 27)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1645-1: important: sqlite3 (Jun 27)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2019:1646-1: moderate: wireshark (Jun 27)
 

An update that contains security fixes can now be installed.

  openSUSE: 2019:1640-1: moderate: libssh2_org (Jun 27)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2019:1633-1: moderate: SDL2 (Jun 27)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2019:1657-1: moderate: exempi (Jun 27)
 

An update that fixes one vulnerability is now available.


  Mageia 2019-0203: cgit security update (Jul 2)
 

A specially crafted URL in can potentially cause cgit to excessively use CPU and network resources, resulting in a Denial-of-Service. This update resolves that issue

  Mageia 2019-0202: firefox security update (Jul 2)
 

Updated firefox packages fix a security vulnerability thats being exploited in the wild: sandbox escape using Prompt:Open. (CVE-2019-11708)

  Mageia 2019-0201: thunderbird security update (Jul 2)
 

Updated thunderbird packages fix security vulnerabilities: Type confusion in Array.pop. (CVE-2019-11707) Sandbox escape using Prompt:Open. (CVE-2019-11708)