**PHP version 7.4.28** (17 Feb 2022) **Filter:** * Fixed bug php#81708: UAF due to php_filter_float() failing for ints (**CVE-2021-21708**)
Archive for February, 2022
RedHat: RHSA-2022-0557:01 Moderate: OpenShift Container Platform 4.9.22
Red Hat OpenShift Container Platform release 4.9.22 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2022-0561:01 Moderate: OpenShift Container Platform 4.9.22
Red Hat OpenShift Container Platform release 4.9.22 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Ubuntu 5302-1: Linux kernel (OEM) vulnerabilities
Several security issues were fixed in the Linux kernel.
Ubuntu 5301-2: Cyrus SASL vulnerability
Cyrus SASL could run programs if it received specially crafted network traffic.
Debian: DSA-5085-1: expat security update
Several vulnerabilities have been discovered in Expat, an XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code, if a malformed XML file is processed.
Several security issues were fixed in PHP.
WordPress 5.9.1 is now available!
**PHP version 8.0.16** (17 Feb 2022) **Core:** * Fixed bug php#81430 (Attribute instantiation leaves dangling pointer). (beberlei) * Fixed bug [GH-7896](https://github.com/php/php-src/issues/7896) (Environment vars may be mangled on Windows). (cmb) **FFI:** * Fixed bug [GH-7867](https://github.com/php/php-src/issues/7867) (FFI::cast() from pointer
The newest upstream commit Security fix for CVE-2022-0629
Ubuntu 5301-1: Cyrus SASL vulnerability
Cyrus SASL could run programs if it received specially crafted network traffic.
RedHat: RHSA-2022-0592:01 Important: kpatch-patch security update
An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
c3p0 could be made to crash if it opened a specially crafted file.
RedHat: RHSA-2022-0590:01 Important: kpatch-patch security update
An update is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Ubuntu 5299-1: Linux kernel vulnerabilities
Several security issues were fixed in the Linux kernel.
Ubuntu 5298-1: Linux kernel vulnerabilities
Several security issues were fixed in the Linux kernel.
Ubuntu 5294-2: Linux kernel vulnerabilities
Several security issues were fixed in the Linux kernel.
– update to latest upstream release (fixes CVE-2021-45444)
WP Briefing: Episode 25: Five Cents on Five for the Future
In this twenty-fifth episode of the WordPress Briefing, Executive Director, Josepha Haden Chomphosy discusses future-proofing the WordPress project with the Five for the Future pledge. Have a question you’d like answered? You can submit them to [email protected], either written or as a voice recording. Credits Editor: Dustin Hartzler Logo: Beatriz Fialho Production: Chloé Bringmann & Santana Inniss Song: […]
RedHat: RHSA-2022-0585:01 Important: Service Telemetry Framework 1.4
An update for sg-core-container is now available for Service Telemetry Framework 1.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Ubuntu 5288-1: Expat vulnerabilities
Several security issues were fixed in Expat.
RedHat: RHSA-2022-0582:01 Important: ruby:2.6 security update
An update for the ruby:2.6 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Update to 2.54.3. Cherry pick misc SELinux policy fixes. Fixes for CVE-2021-44731, CVE-2021-44730, CVE-2021-4120.
Fedora 35: phpMyAdmin 2022-e90299fabf
**phpMyAdmin 5.1.3** – 2022-02-11 This version primarily addresses a regression that caused the navigation pane to not function correctly when multiple pages of tables were shown. Version 5.1.3 includes a security hardening improvement. The issue, reported by Rafael Pedrero, could allow users to cause an error that would reveal the path on disk where phpMyAdmin is running from. We believe this
Fedora 34: cyrus-imapd 2022-d45bcc5447
New version 3.2.8 Security fix for CVE-2021-33582 Security fix for CVE-2021-32056
Update to 2.54.3. Cherry pick misc SELinux policy fixes. Fixes for CVE-2021-44731, CVE-2021-44730, CVE-2021-4120.
Debian: DSA-5084-1: wpewebkit security update
The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22589
Debian: DSA-5083-1: webkit2gtk security update
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-22589
Fedora 35: webkit2gtk3 2022-f0d84ce004
Update to 2.34.6: * Fix accessibility not working when the Bubblewrap sandbox is enabled. * Fix rendering of scrollbars when overlay scrollbars are disabled. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22620
Security fix for CVE-2021-4115