Scientific Essential and Critical Security Patch Updates
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
OpenJDK: Incorrect bounds checks in NIO Buffers (Libraries, 8234841) (CVE-2020-2803) * OpenJDK: Incorrect type checks in MethodType.readObject() (Libraries, 8235274) (CVE-2020-2805) * OpenJDK: Application data accepted before TLS handshake completion (JSSE, 8235691) (CVE-2020-2816) * OpenJDK: Incorrect handling of Certificate messages during TLS handshake (JSSE, 8232581) (CVE-2020-2767) * [More...]
OpenJDK: Incorrect bounds checks in NIO Buffers (Libraries, 8234841) (CVE-2020-2803) * OpenJDK: Incorrect type checks in MethodType.readObject() (Libraries, 8235274) (CVE-2020-2805) * OpenJDK: Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory (Security, 8231415) (CVE-2020-2773) * OpenJDK: Re-use of single TLS session for new connections (JSSE, 8234408) (CVE-2020-2 [More...]
OpenJDK: Incorrect bounds checks in NIO Buffers (Libraries, 8234841) (CVE-2020-2803) * OpenJDK: Incorrect type checks in MethodType.readObject() (Libraries, 8235274) (CVE-2020-2805) * OpenJDK: Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory (Security, 8231415) (CVE-2020-2773) * OpenJDK: Re-use of single TLS session for new connections (JSSE, 8234408) (CVE-2020-2 [More...]
git: Crafted URL containing new lines can cause credential leak (CVE-2020-5260) SL7 x86_64 git-1.8.3.1-22.el7_8.x86_64.rpm git-daemon-1.8.3.1-22.el7_8.x86_64.rpm git-debuginfo-1.8.3.1-22.el7_8.x86_64.rpm git-gnome-keyring-1.8.3.1-22.el7_8.x86_64.rpm git-svn-1.8.3.1-22.el7_8.x86_64.rpm noarch emacs-git-1.8.3.1-22.el7_8.noarch.rpm emacs-git-el-1.8.3.1-22.el7_8.no [More...]
OpenJDK: Incorrect bounds checks in NIO Buffers (Libraries, 8234841) (CVE-2020-2803) * OpenJDK: Incorrect type checks in MethodType.readObject() (Libraries, 8235274) (CVE-2020-2805) * OpenJDK: Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory (Security, 8231415) (CVE-2020-2773) * OpenJDK: Re-use of single TLS session for new connections (JSSE, 8234408) (CVE-2020-2 [More...]
OpenJDK: Incorrect bounds checks in NIO Buffers (Libraries, 8234841) (CVE-2020-2803) * OpenJDK: Incorrect type checks in MethodType.readObject() (Libraries, 8235274) (CVE-2020-2805) * OpenJDK: Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory (Security, 8231415) (CVE-2020-2773) * OpenJDK: Re-use of single TLS session for new connections (JSSE, 8234408) (CVE-2020-2 [More...]
mod_auth_mellon: Open Redirect via the login?ReturnTo= substring which could facilitate information theft SL7 x86_64 mod_auth_mellon-diagnostics-0.14.0-8.el7.x86_64.rpm mod_auth_mellon-0.14.0-8.el7.x86_64.rpm mod_auth_mellon-debuginfo-0.14.0-8.el7.x86_64.rpm - Scientific Linux Development Team
QEMU: Slirp: potential OOB access due to unsafe snprintf() usages SL7 x86_64 qemu-img-1.5.3-173.el7_8.1.x86_64.rpm qemu-kvm-common-1.5.3-173.el7_8.1.x86_64.rpm qemu-kvm-tools-1.5.3-173.el7_8.1.x86_64.rpm qemu-kvm-1.5.3-173.el7_8.1.x86_64.rpm qemu-kvm-debuginfo-1.5.3-173.el7_8.1.x86_64.rpm - Scientific Linux Development Team
lftp: particular remote file names may lead to current working directory erased SL7 x86_64 lftp-4.4.8-12.el7.x86_64.rpm lftp-4.4.8-12.el7.i686.rpm lftp-debuginfo-4.4.8-12.el7.i686.rpm lftp-debuginfo-4.4.8-12.el7.x86_64.rpm noarch lftp-scripts-4.4.8-12.el7.noarch.rpm - Scientific Linux Development Team
unzip: overlapping of files in ZIP container leads to denial of service SL7 x86_64 unzip-6.0-21.el7.x86_64.rpm unzip-debuginfo-6.0-21.el7.x86_64.rpm - Scientific Linux Development Team
okular: Directory traversal in function unpackDocumentArchive() in core/document.cpp SL7 x86_64 okular-part-4.10.5-8.el7.x86_64.rpm okular-devel-4.10.5-8.el7.i686.rpm okular-libs-4.10.5-8.el7.x86_64.rpm okular-libs-4.10.5-8.el7.i686.rpm okular-devel-4.10.5-8.el7.x86_64.rpm okular-4.10.5-8.el7.x86_64.rpm okular-debuginfo-4.10.5-8.el7.i686.rpm okular-debugin [More...]
telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code
Mozilla: Use-after-free while running the nsDocShell destructor * Mozilla: Use-after-free when handling a ReadableStream SL7 x86_64 firefox-68.6.1-1.el7_8.x86_64.rpm firefox-debuginfo-68.6.1-1.el7_8.x86_64.rpm firefox-68.6.1-1.el7_8.i686.rpm firefox-debuginfo-68.6.1-1.el7_8.i686.rpm - Scientific Linux Development Team
python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods SL7 x86_64 python-twisted-web-12.1.0-6.el7.x86_64.rpm - Scientific Linux Development Team
advancecomp: integer overflow in png_compress in pngex.cc SL7 x86_64 advancecomp-1.15-22.el7.x86_64.rpm advancecomp-debuginfo-1.15-22.el7.x86_64.rpm - Scientific Linux Development Team
mailman: Cross-site scripting vulnerability allows malicious listowners to inject scripts into listinfo pages * mailman: Mishandled URLs in Utils.py:GetPathPieces() allows attackers to display arbitrary text on trusted sites SL7 x86_64 mailman-2.1.15-30.el7.x86_64.rpm mailman-debuginfo-2.1.15-30.el7.x86_64.rpm - Scientific Linux Development Team
mutt: IMAP header caching path traversal vulnerability SL7 x86_64 mutt-1.5.21-29.el7.x86_64.rpm mutt-debuginfo-1.5.21-29.el7.x86_64.rpm - Scientific Linux Development Team
nbdkit: denial of service due to premature opening of back-end connection SL7 x86_64 nbdkit-plugin-python-common-1.8.0-3.el7.x86_64.rpm nbdkit-1.8.0-3.el7.x86_64.rpm nbdkit-plugin-vddk-1.8.0-3.el7.x86_64.rpm nbdkit-plugin-python2-1.8.0-3.el7.x86_64.rpm nbdkit-debuginfo-1.8.0-3.el7.x86_64.rpm - Scientific Linux Development Team
bash: BASH_CMD is writable in restricted bash shells SL7 x86_64 bash-4.2.46-34.el7.x86_64.rpm bash-debuginfo-4.2.46-34.el7.x86_64.rpm bash-doc-4.2.46-34.el7.x86_64.rpm - Scientific Linux Development Team
doxygen: cross-site scripting in templates/html/search_opensearch.php SL7 x86_64 doxygen-1.8.5-4.el7.x86_64.rpm doxygen-debuginfo-1.8.5-4.el7.x86_64.rpm doxygen-doxywizard-1.8.5-4.el7.x86_64.rpm doxygen-latex-1.8.5-4.el7.x86_64.rpm - Scientific Linux Development Team