(Dec 17) **PHP version 7.2.13** (06 Dec 2018) **ftp:** * Fixed bug php#77151 (ftp_close(): SSL_read on shutdown). (Remi) **CLI:** * Fixed bug php#77111 (php-win.exe corrupts unicode symbols from cli parameters). (Anatol) **Fileinfo:** * Fixed bug php#77095 (slowness regression in 7.2/7.3 (compared to 7.1)). (Anatol) **iconv:** * Fixed bug php#77147 (Fixing 60494 ignored
Archive for Other
Debian: DSA-4356-1: netatalk security update
(Dec 20) Jacob Baines discovered a flaw in the handling of the DSI Opensession command in Netatalk, an implementation of the AppleTalk Protocol Suite, allowing an unauthenticated user to execute arbitrary code with root privileges.
Ubuntu 3849-1: Linux kernel vulnerabilities
(Dec 20) Several security issues were fixed in the Linux kernel.
Ubuntu 0046-1: Linux kernel vulnerability
(Dec 20) Several security issues were fixed in the kernel.
RedHat: RHSA-2018-3837:01 Low: ansible security and bug fix update
(Dec 18) An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2018-3838:01 Low: ansible security and bug fix update
(Dec 18) An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Fedora 29: php-symfony Security Update
(Dec 17) **Version 2.8.49** (2018-12-06) * security [CVE-2018-19790](https://symfony.com/cve-2018-19790) [Security\Http] detect bad redirect targets using backslashes (@xabbuh) * security [CVE-2018-19789](https://symfony.com/cve-2018-19789) [Form] Filter file uploads out of regular form types (@nicolas-grekas)
Fedora 29: php-symfony3 Security Update
(Dec 17) **Version 3.4.20** (2018-12-06) * security [CVE-2018-19790](https://symfony.com/cve-2018-19790) [Security\Http] detect bad redirect targets using backslashes (@xabbuh) * security [CVE-2018-19789](https://symfony.com/cve-2018-19789) [Form] Filter file uploads out of regular form types (@nicolas-grekas) * bug #29436 [Cache] Fixed
Debian: DSA-4355-1: openssl1.0 security update
(Dec 19) Several local side channel attacks and a denial of service via large Diffie-Hellman parameters were discovered in OpenSSL, a Secure Sockets Layer toolkit.
RedHat: RHSA-2018-3854:01 Low: ntp security update
(Dec 19) An update for ntp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2018-3853:01 Low: ntp security update
(Dec 19) An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
Fedora 29: php-symfony4 Security Update
(Dec 17) **Version 4.1.9** (2018-12-06) * security [CVE-2018-19790](https://symfony.com/cve-2018-19790) [Security\Http] detect bad redirect targets using backslashes (@xabbuh) * security [CVE-2018-19789](https://symfony.com/cve-2018-19789) [Form] Filter file uploads out of regular form types (@nicolas-grekas) * bug #29436 [Cache] Fixed
(Dec 19) Update to 2.7.5 bugfix release. Fix for CVE-2018-16876
RedHat: RHSA-2018-3852:01 Moderate: java-1.8.0-ibm security update
(Dec 18) An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RedHat: RHSA-2018-3843:01 Moderate: kernel security and bug fix update
(Dec 18) An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
(Dec 17) – Update to 2.14.1 – CVE-2018-19608 (#1656784) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-03 —- – Update to 2.14.0 Release notes:
(Dec 18) New version 2.6.5, contains fixes for CVE-2018-19622, CVE-2018-19623, CVE-2018-19624, CVE-2018-19625, CVE-2018-19626, CVE-2018-19627, CVE-2018-19628
RedHat: RHSA-2018-3834:01 Important: ghostscript security and bug fix update
(Dec 17) An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
RedHat: RHSA-2018-3833:01 Critical: firefox security update
(Dec 17) An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Fedora 28: php-symfony3 Security Update
(Dec 17) **Version 3.4.20** (2018-12-06) * security [CVE-2018-19790](https://symfony.com/cve-2018-19790) [Security\Http] detect bad redirect targets using backslashes (@xabbuh) * security [CVE-2018-19789](https://symfony.com/cve-2018-19789) [Form] Filter file uploads out of regular form types (@nicolas-grekas) * bug #29436 [Cache] Fixed
(Dec 17) – Update to 2.14.1 – CVE-2018-19608 (#1656784) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-03 —- – Update to 2.14.0 Release notes:
RedHat: RHSA-2018-3829:01 Moderate: RHGS WA security and bug fix update
(Dec 17) Updated packages are now available for Red Hat Gluster Storage 3.4 Web Administration on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Fedora 29: pdns-recursor Security Update
(Dec 16) Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644
(Dec 16) New upstream version 1.8.2. Fix low priority security issue with TLS: https://www.redhat.com/archives/libguestfs/2018-December/msg00047.html —- New upstream version 1.8.1. —- Rebase to new stable version 1.8.0. —- nbdkit metapackage should depend on versioned -server subpackage etc. —- New upstream version 1.6.3.
(Dec 11) This stable update contains important fixes across the tree including an important fix for a bug that causes filesystem corruption in some cases.
Fedora 29: keepalived Security Update
(Dec 11) Security fix for CVE-2018-19044, CVE-2018-19045, CVE-2018-19046, CVE-2018-19115
RedHat: RHSA-2018-3800:01 Important: rh-git218-git security update
(Dec 10) An update for rh-git218-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
(Dec 12) Security fix for CVE-2018-18311, CVE-2018-18312, CVE-2018-18313 and CVE-2018-18314
Fedora 29: singularity Security Update
(Dec 13) Update to released upstream 2.6.1
(Dec 11) USN-3837-1 introduced a regression in poppler.