Thank you for subscribing to the LinuxSecurity Linux Advisory Watch newsletter! Staying on top of the latest security advisories issued by the distro(s) you use is essential in maintaining an updated, secure Linux system. Our weekly newsletter is an easy, convenient way to track distribution security advisories - helping you keep your Linux environment safe from malware and other exploits.


Important advisories issued this week include warnings from Scientific Linux and Slackware of vulnerabilities in Mozilla Firefox and Mozilla Thunderbird and critical dovecot updates released by CentOS and Scientific Linux. Continue reading to learn about other significant advisories issued this week. Stay healthy, safe and secure - both on and offline!


LinuxSecurity.com Feature Extras:

TANSTAAFL! The Tragedy of the Commons Meets Open-Source Software - Open-source projects can become victims of their own success. What can developers do to secure their open-source software?

Securing a Linux Web Server: A Primer - Over the next couple of weeks and months, LinuxSecurity editors and contributors will be writing a series on Linux Web Server Security. This week, were summarizing the risks Linux administrators face when trying to secure their systems, as well as outlining the first steps that should be taken toward ensuring that your systems are secure. This series will dive deeper into topics including preventing information leakage, firewall considerations, protecting file and directory permissions, securely running PHP applications, monitoring logs and how to verify the security of a Linux server.


  Debian: DSA-4766-1: rails security update (Sep 24)
 

Multiple security issues were discovered in the Rails web framework which could result in cross-site scripting, information leaks, code execution, cross-site request forgery or bypass of upload limits.

  Debian: DSA-4765-1: modsecurity security update (Sep 18)
 

Ervin Hegedues discovered that ModSecurity v3 enabled global regular expression matching which could result in denial of service. For additional information please refer to https://coreruleset.org/20200914/cve-2020-15598/

  Debian: DSA-4764-1: inspircd security update (Sep 18)
 

Two security issues were discovered in the pgsql and mysql modules of the InspIRCd IRC daemon, which could result in denial of service. For the stable distribution (buster), these problems have been fixed in

  Fedora 32: firefox 2020-bb7ff551ce (Sep 23)
 

- New upstream version (81.0)

  Fedora 32: samba 2020-0be2776ed3 (Sep 23)
 

Security fixes for CVE-2020-1472

  Fedora 32: libproxy 2020-2407cb0512 (Sep 23)
 

Fix CVE-2020-25219

  Fedora 32: zeromq 2020-08402f4071 (Sep 23)
 

Fix for #1876738 and #1876689

  Fedora 32: mbedtls 2020-8b0d59bac6 (Sep 23)
 

- Update to 2.16.8

  Fedora 31: seamonkey 2020-3813e1317b (Sep 20)
 

Update to 2.53.4 Lightning, Chatzilla and DOM Inspector are now provided in the same way as for themes and language packs (ie. as "application global" addons). Previously, they were copied into the user profile on each update, which led to some issues. The old copies of those addons are automatically deleted from the user profile at update time (except a case when it was copied by hand, or has

  Fedora 31: mingw-libxml2 2020-7dd29dacad (Sep 19)
 

Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789).

  Fedora 31: gnutls 2020-30cd8d9ad6 (Sep 19)
 

Update to the new upstream 3.6.15 release. ---- - Fix memory leak when serializing iovec_t (#1845083) - Fix automatic libraries sonames detection (#1845806)

  Fedora 31: cryptsetup 2020-5ed5af6275 (Sep 19)
 

Update to cryptsetup 2.3.4. Security fix for CVE-2020-14382

  Fedora 32: chromium 2020-9b9e8e5306 (Sep 19)
 

Update Chromium to 85.0.4183.102. Fix issue where unpackaged components prevented hardware accelerated rendering from working. Also fixes the following security issues: CVE-2020-6573 CVE-2020-6574 CVE-2020-6575 CVE-2020-6576 CVE-2020-15959

  Fedora 32: mingw-libxml2 2020-b60dbdd538 (Sep 19)
 

Add fix for CVE-2020-24977 (RHBZ#1877788, RHBZ#1877789).

  Fedora 32: seamonkey 2020-15999f707a (Sep 18)
 

Update to 2.53.4 Lightning, Chatzilla and DOM Inspector are now provided in the same way as for themes and language packs (ie. as "application global" addons). Previously, they were copied into the user profile on each update, which led to some issues. The old copies of those addons are automatically deleted from the user profile at update time (except a case when it was copied by hand, or has

  RedHat: RHSA-2020-3835:01 Important: firefox security update (Sep 24)
 

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-3832:01 Important: firefox security update (Sep 24)
 

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-3833:01 Important: firefox security update (Sep 24)
 

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-3836:01 Important: kernel security update (Sep 24)
 

An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-3834:01 Important: firefox security update (Sep 24)
 

An update for firefox is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-3806:01 Important: Red Hat support for Spring Boot (Sep 23)
 

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-3807:01 Moderate: Red Hat Virtualization security, bug fix, (Sep 23)
 

An update is now available for Red Hat Virtualization Engine 4.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2020-3809:01 Moderate: OpenShift Container Platform 4.3.38 (Sep 23)
 

An update for openshift-enterprise-hyperkube-container and sriov-dp-admission-controller-container is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact

  RedHat: RHSA-2020-3808:01 Important: OpenShift Container Platform 4.3.38 (Sep 23)
 

An update for jenkins and openshift is now available for Red Hat OpenShift Container Platform 4.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

  RedHat: RHSA-2020-3817:01 Moderate: AMQ Clients 2.8.0 Release (Sep 23)
 

An update is now available for Red Hat AMQ Clients 2.8.0. Red Hat Product Security has rated this update as having a Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  RedHat: RHSA-2020-3810:01 Moderate: kernel-rt security and bug fix update (Sep 22)
 

An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

  RedHat: RHSA-2020-3803:01 Moderate: bash security update (Sep 22)
 

An update for bash is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

  RedHat: RHSA-2020-3804:01 Moderate: kernel security and bug fix update (Sep 22)
 

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.

  RedHat: RHSA-2020-3783:01 Moderate: OpenShift Container Platform 4.4.23 (Sep 22)
 

An update for cluster-network-operator-container is now available for Red Hat OpenShift Container Platform 4.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2020-3780:01 Moderate: OpenShift Container Platform 4.5.11 (Sep 21)
 

An update for ose-cluster-svcat-apiserver-operator-container is now available for Red Hat OpenShift Container Platform 4.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

  RedHat: RHSA-2020-3779:01 Important: Red Hat Data Grid 7.3.7 security update (Sep 17)
 

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

  Slackware: 2020-266-01: seamonkey Security Update (Sep 22)
 

New seamonkey packages are available for Slackware 14.2 and -current to fix security issues.

  SUSE: 2020:2743-1 important: qemu (Sep 24)
 

An update that fixes four vulnerabilities is now available.

  SUSE: 2020:2744-1 moderate: tiff (Sep 24)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2742-1 important: libqt5-qtbase (Sep 24)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2020:2741-1 important: libqt5-qtbase (Sep 24)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2020:2733-1 moderate: bcm43xx-firmware (Sep 24)
 

An update that contains security fixes can now be installed.

  SUSE: 2020:2731-1 moderate: conmon, fuse-overlayfs, libcontainers-common, podman (Sep 24)
 

An update that solves one vulnerability, contains one feature and has 6 fixes is now available.

  SUSE: 2020:2728-1 moderate: cifs-utils (Sep 23)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2726-1 moderate: python-pip (Sep 23)
 

An update that fixes one vulnerability, contains one feature is now available.

  SUSE: 2020:14498-1 libcdio (Sep 23)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2729-1 moderate: cifs-utils (Sep 23)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2020:2727-1 moderate: wavpack (Sep 23)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2730-1 important: samba (Sep 23)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2720-1 important: samba (Sep 23)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2718-1 moderate: pdns (Sep 23)
 

An update that fixes one vulnerability, contains one feature is now available.

  SUSE: 2020:2724-1 important: samba (Sep 23)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2722-1 important: samba (Sep 23)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2719-1 important: samba (Sep 23)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2020:2721-1 important: samba (Sep 23)
 

An update that solves one vulnerability and has two fixes is now available.

  SUSE: 2020:2713-1 moderate: ovmf (Sep 22)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2020:2712-1 moderate: openldap2 (Sep 22)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2710-1 important: rubygem-actionpack-5_1 (Sep 22)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2714-1 moderate: ovmf (Sep 22)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2020:2715-1 moderate: grafana (Sep 22)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2711-1 moderate: libmspack (Sep 22)
 

An update that solves three vulnerabilities and has one errata is now available.

  SUSE: 2020:2699-1 important: python3 (Sep 21)
 

An update that solves 7 vulnerabilities and has three fixes is now available.

  SUSE: 2020:2698-1 moderate: python-pip (Sep 21)
 

An update that fixes one vulnerability, contains one feature is now available.

  SUSE: 2020:2689-1 moderate: jasper (Sep 21)
 

An update that fixes 14 vulnerabilities is now available.

  SUSE: 2020:2686-1 important: rubygem-actionview-4_2 (Sep 21)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2687-1 moderate: less (Sep 21)
 

An update that fixes one vulnerability is now available.

  SUSE: 2020:2691-1 moderate: ovmf (Sep 21)
 

An update that solves one vulnerability and has one errata is now available.

  SUSE: 2020:2690-1 jasper (Sep 21)
 

An update that fixes 17 vulnerabilities is now available.

  SUSE: 2020:2650-1 important: SUSE Manager Server 4.0 (Sep 18)
 

An update that solves three vulnerabilities and has 26 fixes is now available.

  SUSE: 2020:2678-1 moderate: rubygem-rack (Sep 18)
 

An update that fixes three vulnerabilities is now available.

  SUSE: 2020:2673-1 important: samba (Sep 17)
 

An update that fixes 15 vulnerabilities is now available.

  Ubuntu 4540-1: atftpd vulnerabilities (Sep 24)
 

Several security issues were fixed in atftpd.

  Ubuntu 4539-1: AWL vulnerability (Sep 24)
 

DAViCal Andrew's Web Libraries could be made to run programs as your login if it received specially crafted input.

  Ubuntu 4536-1: SPIP vulnerabilities (Sep 24)
 

Several security issues were fixed in SPIP.

  Ubuntu 4538-1: PackageKit vulnerabilities (Sep 24)
 

Several security issues were fixed in PackageKit.

  Ubuntu 4537-1: Aptdaemon vulnerability (Sep 24)
 

Aptdaemon could be made to expose sensitive information.

  Ubuntu 4535-1: RDFLib vulnerability (Sep 23)
 

RDFLib could be made to made to execute arbitrary code if it were running in a directory with a specially crafted file.

  Ubuntu 4534-1: Perl DBI module vulnerability (Sep 23)
 

Perl DBI module could be made to crash or expose sensitive information if it received a specially crafted input.

  Ubuntu 4533-1: LTSP Display Manager vulnerabilities (Sep 22)
 

LTSP Display Manager could be made to escalate user privileges.

  Ubuntu 4532-1: Netty vulnerabilities (Sep 22)
 

Several security issues were fixed in Netty.

  Ubuntu 4530-1: Debian-LAN vulnerabilities (Sep 22)
 

Debian-LAN could be made to change Kerberos user passwords or run programs as an administrator.

  Ubuntu 4531-1: BusyBox vulnerability (Sep 22)
 

Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.

  Ubuntu 4529-1: FreeImage vulnerabilities (Sep 22)
 

Several security issues were fixed in FreeImage.

  Ubuntu 4528-1: Ceph vulnerabilities (Sep 22)
 

Several security issues were fixed in Ceph.

  Ubuntu 4527-1: Linux kernel vulnerabilities (Sep 22)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 4526-1: Linux kernel vulnerabilities (Sep 22)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 4525-1: Linux kernel vulnerabilities (Sep 22)
 

Several security issues were fixed in the Linux kernel.

  Ubuntu 4524-1: TNEF vulnerabilities (Sep 21)
 

TNEF could be made to crash or write arbitrary files to the filesystem.

  Ubuntu 4523-1: LibOFX vulnerability (Sep 21)
 

LibOFX could be made to crash.

  Ubuntu 4522-1: noVNC vulnerability (Sep 21)
 

noVNC could be made to execute arbitrary code.

  Ubuntu 4521-1: pam_tacplus vulnerability (Sep 21)
 

pam_tacplus could be made to expose sensitive information.

  Ubuntu 4520-1: Exim SpamAssassin vulnerability (Sep 18)
 

Exim SpamAssassin could be made to execute aribitrary code if it received crafted .cf files/rules.

  Ubuntu: USN-4517-1 Email-Address-List vulnerability (Sep 18)
 

Email-Address-List could be made to remotely exhaust resources if it received specially crafted email data.

  Ubuntu 4519-1: PulseAudio vulnerability (Sep 17)
 

PulseAudio could be made to crash or run programs as your login if it received specially crafted input.

  Ubuntu: USN-4518-1 USN-4518-1] xawtv vulnerability (Sep 17)
 

xawtv could be made to expose sensitive information and escalate user privileges if it received specially crafted input.

  Ubuntu 4516-1: GnuPG vulnerability (Sep 17)
 

GnuPG could be made to expose sensitive information.

  Ubuntu 4515-1: Pure-FTPd vulnerability (Sep 17)
 

Pure-FTPd could be made to expose sensitive information if it recieved specially crafted input.

  Ubuntu 4514-1: libproxy vulnerability (Sep 17)
 

libproxy could be made to crash if it received a specially crafted PAC file.

  Ubuntu 4513-1: apng2gif vulnerability (Sep 17)
 

apng2gif could be made to expose sensitive information if it opened a specifically crafted APNG file.

  Ubuntu 4510-2: Samba vulnerability (Sep 17)
 

Samba would allow unintended access to files over the network.

  Ubuntu 4512-1: util-linux vulnerability (Sep 17)
 

util-linux could be made to run programs when performing bash completion.

  Ubuntu 4511-1: QEMU vulnerability (Sep 17)
 

QEMU could be made to crash or run programs.

  Ubuntu 4510-1: Samba vulnerability (Sep 17)
 

Samba would allow unintended access to files over the network.

  Debian LTS: DLA-2375-1: inspircd security update (Sep 20)
 

Two security issues were discovered in the modules of the InspIRCd IRC daemon, which could result in denial of service. CVE-2019-20917

  ArchLinux: 202009-7: netbeans: arbitrary code execution (Sep 17)
 

The package netbeans before version 12.0_u1-1 is vulnerable to arbitrary code execution.

  ArchLinux: 202009-6: chromium: multiple issues (Sep 17)
 

The package chromium before version 85.0.4183.102-1 is vulnerable to multiple issues including access restriction bypass and arbitrary code execution.

  openSUSE: 2020:1523-1: moderate: jasper (Sep 25)
 

An update that fixes 14 vulnerabilities is now available.

  openSUSE: 2020:1525-1: moderate: ovmf (Sep 25)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2020:1516-1: moderate: roundcubemail (Sep 24)
 

An update that solves 6 vulnerabilities and has two fixes is now available.

  openSUSE: 2020:1517-1: moderate: jasper (Sep 24)
 

An update that fixes 14 vulnerabilities is now available.

  openSUSE: 2020:1514-1: important: chromium (Sep 24)
 

An update that fixes 19 vulnerabilities is now available.

  openSUSE: 2020:1513-1: important: samba (Sep 24)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1511-1: important: virtualbox (Sep 24)
 

An update that fixes 25 vulnerabilities is now available.

  openSUSE: 2020:1510-1: important: chromium (Sep 23)
 

An update that fixes 19 vulnerabilities is now available.

  openSUSE: 2020:1509-1: moderate: Recommended otrs (Sep 23)
 

An update that fixes 18 vulnerabilities is now available.

  openSUSE: 2020:1506-1: moderate: lilypond (Sep 22)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1505-1: moderate: libetpan (Sep 22)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1502-1: important: perl-DBI (Sep 22)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2020:1501-1: moderate: libqt4 (Sep 22)
 

An update that solves four vulnerabilities and has one errata is now available.

  openSUSE: 2020:1499-1: important: chromium (Sep 22)
 

An update that fixes 19 vulnerabilities is now available.

  openSUSE: 2020:1500-1: moderate: libqt4 (Sep 22)
 

An update that solves four vulnerabilities and has one errata is now available.

  openSUSE: 2020:1497-1: moderate: singularity (Sep 21)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2020:1494-1: moderate: curl (Sep 21)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1486-1: moderate: virtualbox (Sep 20)
 

An update that fixes 25 vulnerabilities is now available.

  openSUSE: 2020:1483-1: important: perl-DBI (Sep 20)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2020:1478-1: important: fossil (Sep 20)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2020:1453-1: moderate: lilypond (Sep 19)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1468-1: moderate: slurm_18_08 (Sep 19)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1458-1: moderate: libjpeg-turbo (Sep 19)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1465-1: moderate: libxml2 (Sep 19)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1454-1: moderate: libetpan (Sep 19)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1459-1: moderate: openldap2 (Sep 19)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1455-1: important: libvirt (Sep 19)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2020:1452-1: moderate: libqt4 (Sep 18)
 

An update that solves four vulnerabilities and has one errata is now available.

  openSUSE: 2020:1215-1: important: chromium (Sep 18)
 

An update that fixes 14 vulnerabilities is now available.

  openSUSE: 2020:1428-1: important: librepo (Sep 18)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1438-1: moderate: hylafax+ (Sep 18)
 

An update that fixes two vulnerabilities is now available.

  openSUSE: 2020:1100-1: important: singularity (Sep 18)
 

An update that fixes three vulnerabilities is now available.

  openSUSE: 2020:1181-1: Security update of chromium (Sep 18)
 

An update that fixes 6 vulnerabilities is now available.

  openSUSE: 2020:1192-1: moderate: claws-mail (Sep 18)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1322-1: important: chromium (Sep 18)
 

An update that fixes 14 vulnerabilities is now available.

  openSUSE: 2020:1232-1: moderate: knot (Sep 18)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1446-1: moderate: python-Flask-Cors (Sep 18)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1433-1: moderate: docker-distribution (Sep 18)
 

An update that solves one vulnerability and has one errata is now available.

  openSUSE: 2020:1310-2: moderate: ark (Sep 18)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1183-2: moderate: ark (Sep 18)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1101-1: moderate: pdns-recursor (Sep 18)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1439-2: moderate: mumble (Sep 18)
 

An update that contains security fixes can now be installed.

  openSUSE: 2020:1055-1: moderate: pdns-recursor (Sep 18)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1048-1: important: chromium (Sep 18)
 

An update that fixes 26 vulnerabilities is now available.

  openSUSE: 2020:1032-1: important: chromium (Sep 18)
 

An update that solves one vulnerability and has 5 fixes is now available.

  openSUSE: 2020:1423-1: moderate: python-Flask-Cors (Sep 18)
 

An update that fixes one vulnerability is now available.

  openSUSE: 2020:1427-1: moderate: inn (Sep 18)
 

An update that fixes one vulnerability is now available.

  Mageia 2020-0369: mysql-connector-java security update (Sep 21)
 

A flaw was found in the mysql-connector-java package. A complicated attack against the mysql Connector/J allows attackers on the local network to interfere with a user's connection and insert unauthorized SQL commands (CVE-2020-2934).

  Mageia 2020-0368: libraw security update (Sep 17)
 

LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength. (CVE-2020-15503)