bind (SL7)

Synopsis: Important: bind security update Advisory ID: SLSA-2020:2344-1 Issue Date: 2020-06-01 CVE Numbers: None — Security Fix(es): * bind: BIND does not sufficiently limit the number of fetches performed when processing referrals (CVE-2020-8616) * bind: A logic error in code … Read More

freerdp (SL7)

Synopsis: Important: freerdp security update Advisory ID: SLSA-2020:2334-1 Issue Date: 2020-05-28 CVE Numbers: None — Security Fix(es): * freerdp: Out-of-bounds write in planar.c (CVE-2020-11521) * freerdp: Integer overflow in region.c (CVE-2020-11523) * freerdp: Out-of-bounds write in interleaved.c (CVE-2020-11524) — SL7 … Read More

python-virtualenv (SL7)

Synopsis: Moderate: python-virtualenv security update Advisory ID: SLSA-2020:2081-1 Issue Date: 2020-05-12 CVE Numbers: None — Security Fix(es): * python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure (CVE-2018-20060) * python-urllib3: CRLF injection due to not encoding the … Read More

python-pip (SL7)

Synopsis: Moderate: python-pip security update Advisory ID: SLSA-2020:2068-1 Issue Date: 2020-05-12 CVE Numbers: None — Security Fix(es): * python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure (CVE-2018-20060) * python-urllib3: CRLF injection due to not encoding the … Read More

git (SL7)

Synopsis: Important: git security update Advisory ID: SLSA-2020:2337-1 Issue Date: 2020-05-29 CVE Numbers: None — Security Fix(es): * git: Crafted URL containing new lines, empty host or lacks a scheme can cause credential leak (CVE-2020-11008) — SL7 x86_64 git-1.8.3.1-23.el7_8.x86_64.rpm git-daemon-1.8.3.1-23.el7_8.x86_64.rpm … Read More

kernel (SL7)

Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2020:2082-1 Issue Date: 2020-05-12 CVE Numbers: None — Security Fix(es): * kernel: double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c (CVE-2017-18595) * kernel: use-after-free in … Read More

podman (SL7)

Synopsis: Important: podman security update Advisory ID: SLSA-2020:2117-1 Issue Date: 2020-05-12 CVE Numbers: None — * buildah: Crafted input tar file may lead to local file overwrite during image build process * containers/image: Container images read entire image manifest into … Read More

buildah (SL7)

Synopsis: Important: buildah security and bug fix update Advisory ID: SLSA-2020:2116-1 Issue Date: 2020-05-12 CVE Numbers: None — * buildah: Crafted input tar file may lead to local file overwrite during image build process * containers/image: Container images read entire … Read More

kernel (SL6)

Synopsis: Important: kernel security update Advisory ID: SLSA-2020:2103-1 Issue Date: 2020-05-12 CVE Numbers: None — Security Fix(es): * Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic (CVE-2020-10711) — SL6 x86_64 kernel-2.6.32-754.29.2.el6.x86_64.rpm kernel-debug-2.6.32-754.29.2.el6.x86_64.rpm … Read More

thunderbird (SL6)

Synopsis: Critical: thunderbird security update Advisory ID: SLSA-2020:2049-1 Issue Date: 2020-05-11 CVE Numbers: None — Security Fix(es): * Mozilla: Use-after-free during worker shutdown (CVE-2020-12387) * Mozilla: Memory safety bugs fixed in Firefox 76 and Firefox ESR 68.8 (CVE-2020-12395) * usrsctp: … Read More