xstream (SL7)

Synopsis: Important: xstream security update Advisory ID: SLSA-2021:3956-1 Issue Date: 2021-10-25 CVE Numbers: CVE-2021-39139 CVE-2021-39140 CVE-2021-39141 CVE-2021-39144 CVE-2021-39145 CVE-2021-39146 CVE-2021-39147 CVE-2021-39148 CVE-2021-39149 CVE-2021-39150 CVE-2021-39151 CVE-2021-39152 CVE-2021-39153 CVE-2021-39154 — Security Fix(es): * xstream: Arbitrary code execution via unsafe deserialization of Xalan … Read More

java-1.8.0-openjdk (SL7)

Synopsis: Important: java-1.8.0-openjdk security and bug fix update Advisory ID: SLSA-2021:3889-1 Issue Date: 2021-10-20 CVE Numbers: CVE-2021-35565 CVE-2021-35556 CVE-2021-35559 CVE-2021-35561 CVE-2021-35564 CVE-2021-35586 CVE-2021-35603 CVE-2021-35550 CVE-2021-35578 CVE-2021-35567 CVE-2021-35588 — Security Fix(es): * OpenJDK: Loop in HttpsServer triggered during TLS session close … Read More

java-11-openjdk (SL7)

Synopsis: Important: java-11-openjdk security and bug fix update Advisory ID: SLSA-2021:3892-1 Issue Date: 2021-10-20 CVE Numbers: CVE-2021-35565 CVE-2021-35556 CVE-2021-35559 CVE-2021-35561 CVE-2021-35564 CVE-2021-35586 CVE-2021-35603 CVE-2021-35550 CVE-2021-35578 CVE-2021-35567 — Security Fix(es): * OpenJDK: Loop in HttpsServer triggered during TLS session close (JSSE, … Read More

thunderbird (SL7)

Synopsis: Important: thunderbird security update Advisory ID: SLSA-2021:3841-1 Issue Date: 2021-10-18 CVE Numbers: CVE-2021-32810 CVE-2021-38496 CVE-2021-38497 CVE-2021-38498 CVE-2021-38500 CVE-2021-38501 CVE-2021-38502 — This update upgrades Thunderbird to version 91.2.0. Security Fix(es): * Mozilla: Use-after-free in MessageTask (CVE-2021-38496) * Mozilla: Memory safety … Read More

firefox (SL7)

Synopsis: Important: firefox security update Advisory ID: SLSA-2021:3791-1 Issue Date: 2021-10-12 CVE Numbers: CVE-2021-32810 CVE-2021-38496 CVE-2021-38497 CVE-2021-38498 CVE-2021-38500 CVE-2021-38501 — This update upgrades Firefox to version 91.2.0 ESR. Security Fix(es): * Mozilla: Use-after-free in MessageTask (CVE-2021-38496) * Mozilla: Memory safety … Read More

kernel (SL7)

Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2021:3801-1 Issue Date: 2021-10-12 CVE Numbers: CVE-2021-22543 CVE-2021-3653 CVE-2021-3656 CVE-2021-37576 — Security Fix(es): * kernel: Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks (CVE-2021-22543) * kernel: powerpc: … Read More

libxml2 (SL7)

Synopsis: Moderate: libxml2 security update Advisory ID: SLSA-2021:3810-1 Issue Date: 2021-10-12 CVE Numbers: CVE-2016-4658 — Security Fix(es): * libxml2: Use after free via namespace node in XPointer ranges (CVE-2016-4658) For more details about the security issue(s), including the impact, a … Read More

openssl (SL7)

Synopsis: Moderate: openssl security update Advisory ID: SLSA-2021:3798-1 Issue Date: 2021-10-12 CVE Numbers: CVE-2021-23841 CVE-2021-23840 — Security Fix(es): * openssl: integer overflow in CipherUpdate (CVE-2021-23840) * openssl: NULL pointer dereference in X509_issuer_and_serial_hash() (CVE-2021-23841) For more details about the security issue(s), … Read More

389-ds-base (SL7)

Synopsis: Low: 389-ds-base security and bug fix update Advisory ID: SLSA-2021:3807-1 Issue Date: 2021-10-12 CVE Numbers: CVE-2021-3652 — Security Fix(es): * 389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed (CVE-2021-3652) For more details about the security … Read More

thunderbird (SL7)

Synopsis: Important: thunderbird security update Advisory ID: SLSA-2021:3494-1 Issue Date: 2021-09-13 CVE Numbers: CVE-2021-38493 — This update upgrades Thunderbird to version 78.14.0. Security Fix(es): * Mozilla: Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 … Read More