(May 1) Several security issues were fixed in WavPackXXX-APP-XXX.
Archive for Other
(Apr 30) Several security issues were fixed in Ghostscript.
(Apr 29) Updated Boost libraries are available that fix compatibility with CUDA 9.x compilers and fix a possible integer overflow in Boost.Regex.
(Apr 28) It has been discovered that Tor, a connection-based low-latency anonymous communication system, contains a protocol-list handling bug that could be used to remotely crash directory authorities with a null-pointer exception (TROVE-2018-001).
(Apr 29) Security fix for [CVE-2018-10194](https://access.redhat.com/security/cve/cve-2018-10194).
Debian: DSA-4184-1: sdl-image1.2 security update
(Apr 28) Multiple vulnerabilities have been discovered in the image loading library for Simple DirectMedia Layer 1.2, which could result in denial of service or the execution of arbitrary code if malformed image files are opened.
RedHat: RHSA-2018-1243:01 Critical: OpenShift Container Platform 3.1
(Apr 29) An update is now available for Red Hat OpenShift Container Platform 3.1. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2018-1241:01 Critical: OpenShift Container Platform 3.2
(Apr 29) An update is now available for Red Hat OpenShift Container Platform 3.2. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Debian: DSA-4186-1: gunicorn security update
(Apr 28) It was discovered that gunicorn, an event-based HTTP/WSGI server was susceptible to HTTP Response splitting. For the oldstable distribution (jessie), this problem has been fixed
Debian: DSA-4185-1: openjdk-8 security update
(Apr 28) Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, execution of arbitrary code or bypass of JAR signature validation.
(Apr 27) New upstream release – This release fixes CVE-2018-1106 which is a moderate security issue.
(Apr 27) Update to newer release of Tika including security fixes for CVE-2016-4434 and CVE-2016-6809.
RedHat: RHSA-2018-1229:01 Critical: OpenShift Container Platform 3.8
(Apr 28) An update is now available for Red Hat OpenShift Container Platform 3.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2018-1227:01 Critical: OpenShift Container Platform 3.9
(Apr 28) An update is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Debian: DSA-4079-2: poppler regression update
(Apr 12) It was discovered that the poppler upload for the oldstable distribution (jessie), released as DSA-4079-1, did not correctly address CVE-2017-9776 and additionally caused regressions when rendering PDFs embedding JBIG2 streams. Updated packages are now available to correct
Debian: DSA-4172-1: perl security update
(Apr 14) Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:
(Apr 27) The v4.16.4 update contains fixes across the tree
(Apr 27) This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. — https://www.genivia.com/advisory.html
(Apr 16) Several security issues were fixed in Patch.
RedHat: RHSA-2018-1249:01 Important: jboss-ec2-eap package for EAP 7.1.2
(Apr 25) An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.1.2 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.1.2 for Red Hat Enterprise Linux 7.
RedHat: RHSA-2018-1248:01 Important: JBoss Enterprise Application Platform
(Apr 25) Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact
(Apr 16) Several security issues were fixed in Ruby.
Debian: DSA-4173-1: r-cran-readxl security update
(Apr 16) Marcin Noga discovered multiple vulnerabilities in readxl, a GNU R package to read Excel files (via the integrated libxls library), which could result in the execution of arbitrary code if a malformed spreadsheet is processed.
Debian: DSA-4174-1: corosync security update
(Apr 17) The Citrix Security Response Team discovered that corosync, a cluster engine implementation, allowed an unauthenticated user to cause a denial-of-service by application crash.
(Apr 25) **Version 1.6.4** – 2018-04-13 * Security fixes in some edge case scenarios, recommended update for all users * Fixed regression in version guessing of path repositories * Fixed removing aliased packages from the repository, which might resolve some odd update bugs * Fixed updating of package URLs for GitLab * Fixed run-script –list failing when script handlers were defined * Fixed
(Apr 27) Updated Boost libraries are available that fix compatibility with CUDA 9.x compilers and fix a possible integer overflow in Boost.Regex.
(Apr 17) Several security issues were fixed in Perl.
RedHat: RHSA-2018-1254:01 Moderate: rh-mysql56-mysql security update
(Apr 26) An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Ubuntu 3630-1: Linux kernel vulnerability
(Apr 24) The system could be made to crash under certain conditions.
RedHat: RHSA-2018-1253:01 Important: apr security update
(Apr 26) An update for apr is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, Red Hat Enterprise