1.5.7, fix for CVE-2019-13107
Archive for Fedora

Fixes bugzilla 1126076

Update to v1.15.7 (CVE-2018-1002102 kubernetes: improper validation of URL redirection in the Kubernetes API server allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints)

Release of 19.05.5. Closes security issues CVE-2019-19727, CVE-2019-19728.

Fixes bugzilla 1126076

Update to latest upstream version.

Update to latest upstream version.

Security fix for CVE-2019-19722: null pointer dereference in push notification driver

Update to latest release and include fix for CVE-2019-19630

Upgrade to upstream 3.5.2, still using golang-1.11 on epel8 —- Upgrade to upstream 3.5.1, use golang-1.11 on epel8 —- Upgrade to upstream 3.5.0

– https://www.drupal.org/project/l10n_update/releases/7.x-2.3 – https://www.drupal.org/sa-contrib-2019-072

– https://www.drupal.org/project/webform/releases/7.x-4.21 – https://www.drupal.org/sa-contrib-2019-096 – https://www.drupal.org/project/webform/releases/7.x-4.20

Update to NetHack 3.6.4 – fixes security issue with privilege escalation: http://nethack.org/security/index.html

**PHP version 7.3.13** (18 Dec 2019) **Bcmath:** * Fixed bug php#78878 (Buffer underflow in bc_shift_addsub). (**CVE-2019-11046**). (cmb) **Core:** * Fixed bug php#78862 (link() silently truncates after a null byte on Windows). (**CVE-2019-11044**). (cmb) * Fixed bug php#78863 (DirectoryIterator class silently truncates after a null byte). (**CVE-2019-11045**). (cmb) * Fixed bug

Update to new upstream version 3.0.13, which includes a fix for CVE-2019-19783 and other minor fixes. Release notes: https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.13.html

**PHP version 7.3.13** (18 Dec 2019) **Bcmath:** * Fixed bug php#78878 (Buffer underflow in bc_shift_addsub). (**CVE-2019-11046**). (cmb) **Core:** * Fixed bug php#78862 (link() silently truncates after a null byte on Windows). (**CVE-2019-11044**). (cmb) * Fixed bug php#78863 (DirectoryIterator class silently truncates after a null byte). (**CVE-2019-11045**). (cmb) * Fixed bug

Update to NetHack 3.6.4 – fixes security issue with privilege escalation: http://nethack.org/security/index.html

– Update to 1.2.8 Release notes: https://www.cacti.net/release_notes.php?version=1.2.8

– Update to 1.2.8 Release notes: https://www.cacti.net/release_notes.php?version=1.2.8

Security fix for CVE-2019-18397

– Update to 1.2.8 Release notes: https://www.cacti.net/release_notes.php?version=1.2.8

– Update to 1.2.8 Release notes: https://www.cacti.net/release_notes.php?version=1.2.8

bugfix release for CVE-2019-19118

Security fix for CVE-2019-5544

Update to Chromium 79. Fixes the usual giant pile of bugs and security issues. This time, the list is: CVE-2019-13725 CVE-2019-13726 CVE-2019-13727 CVE-2019-13728 CVE-2019-13729 CVE-2019-13730 CVE-2019-13732 CVE-2019-13734 CVE-2019-13735 CVE-2019-13764 CVE-2019-13736 CVE-2019-13737 CVE-2019-13738 CVE-2019-13739 CVE-2019-13740 CVE-2019-13741 CVE-2019-13742 CVE-2019-13743

Update to version 0.9.3 to address CVE-2019-14889

This is a security release fixing the following issues: * CVE-2019-1348: the fast-import stream command “feature export-marks=path” allows writing to arbitrary file paths. As libgit2 does not offer any interface for fast-import, it is not susceptible to this vulnerability. * CVE-2019-1349: by using NTFS 8.3 short names, backslashes or alternate filesystreams, it is possible to cause

The 5.3.16 update contains a number of important fixes across the tree

– update to upstream version 4.3.0 – fixes CVE-2019-19331 – root.keys is moved to /var/lib/knot-resolver – knot-resolver no longer requires write permission to /etc/knot-resolver/

Device quarantine for alternate pci assignment methods [XSA-306]