Scientific Essential and Critical Security Patch Updates
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Mozilla: Use-after-free while running the nsDocShell destructor (CVE-2020-6819) * Mozilla: Use-after-free when handling a ReadableStream (CVE-2020-6820) SL6 x86_64 firefox-68.6.1-1.el6_10.x86_64.rpm firefox-debuginfo-68.6.1-1.el6_10.x86_64.rpm firefox-68.6.1-1.el6_10.i686.rpm firefox-debuginfo-68.6.1-1.el6_10.i686.rpm i386 firefox-68.6.1-1.el6_10.i686.rpm firefox- [More...]
ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) SL6 x86_64 ipmitool-1.8.15-3.el6_10.x86_64.rpm ipmitool-debuginfo-1.8.15-3.el6_10.x86_64.rpm i386 ipmitool-1.8.15-3.el6_10.i686.rpm ipmitool-debuginfo-1.8.15-3.el6_10.i686.rpm - Scientific Linux Development Team
telnet-server: no bounds checks in nextitem() function allows to remotely execute arbitrary code (CVE-2020-10188) SL6 x86_64 telnet-0.17-49.el6_10.x86_64.rpm telnet-debuginfo-0.17-49.el6_10.x86_64.rpm telnet-server-0.17-49.el6_10.x86_64.rpm i386 telnet-0.17-49.el6_10.i686.rpm telnet-debuginfo-0.17-49.el6_10.i686.rpm telnet-server-0.17-49.el6_10.i686.rpm - Scientif [More...]
ipmitool: Buffer overflow in read_fru_area_section function in lib/ipmi_fru.c (CVE-2020-5208) SL7 x86_64 ipmitool-1.8.18-9.el7_7.x86_64.rpm ipmitool-debuginfo-1.8.18-9.el7_7.x86_64.rpm noarch bmc-snmp-proxy-1.8.18-9.el7_7.noarch.rpm exchange-bmc-os-info-1.8.18-9.el7_7.noarch.rpm - Scientific Linux Development Team
Mozilla: Use-after-free when removing data about origins (CVE-2020-6805) * Mozilla: BodyStream::OnInputStreamReady was missing protections against state confusion (CVE-2020-6806) * Mozilla: Use-after-free in cubeb during stream destruction (CVE-2020-6807) * Mozilla: Memory safety bugs fixed in Firefox 74 and Firefox ESR 68.6 (CVE-2020-6814) * Mozilla: Out of bounds reads in sctp_load_addre [More...]
tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability (CVE-2020-1938) SL6 noarch tomcat6-6.0.24-114.el6_10.noarch.rpm tomcat6-admin-webapps-6.0.24-114.el6_10.noarch.rpm tomcat6-docs-webapp-6.0.24-114.el6_10.noarch.rpm tomcat6-el-2.1-api-6.0.24-114.el6_10.noarch.rpm tomcat6-javadoc-6.0.24-114.el6_10.noarch.rpm tomcat6-jsp-2.1-api-6.0.24-114.el6_10.noarch.rpm [More...]
libvncserver: HandleCursorShape() integer overflow resulting in heap-based buffer overflow (CVE-2019-15690) SL7 x86_64 libvncserver-0.9.9-14.el7_7.i686.rpm libvncserver-0.9.9-14.el7_7.x86_64.rpm libvncserver-debuginfo-0.9.9-14.el7_7.i686.rpm libvncserver-debuginfo-0.9.9-14.el7_7.x86_64.rpm libvncserver-devel-0.9.9-14.el7_7.i686.rpm libvncserver-devel-0.9.9-14.el7_7.x [More...]
Mozilla: Use-after-free when removing data about origins (CVE-2020-6805) * Mozilla: BodyStream::OnInputStreamReady was missing protections against state confusion (CVE-2020-6806) * Mozilla: Use-after-free in cubeb during stream destruction (CVE-2020-6807) * Mozilla: Memory safety bugs fixed in Firefox 74 and Firefox ESR 68.6 (CVE-2020-6814) * Mozilla: Out of bounds reads in sctp_load_addre [More...]
ICU: Integer overflow in UnicodeString::doAppend() (CVE-2020-10531) SL6 x86_64 icu-debuginfo-4.2.1-15.el6_10.i686.rpm icu-debuginfo-4.2.1-15.el6_10.x86_64.rpm libicu-4.2.1-15.el6_10.i686.rpm libicu-4.2.1-15.el6_10.x86_64.rpm icu-4.2.1-15.el6_10.x86_64.rpm libicu-devel-4.2.1-15.el6_10.i686.rpm libicu-devel-4.2.1-15.el6_10.x86_64.rpm i386 icu-debuginfo-4.2.1- [More...]
python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c (CVE-2020-5312) SL6 x86_64 python-imaging-1.1.6-20.el6_10.x86_64.rpm python-imaging-debuginfo-1.1.6-20.el6_10.x86_64.rpm python-imaging-devel-1.1.6-20.el6_10.x86_64.rpm python-imaging-sane-1.1.6-20.el6_10.x86_64.rpm python-imaging-tk-1.1.6-20.el6_10.x86_64.rpm i386 python-ima [More...]
zsh: insecure dropping of privileges when unsetting PRIVILEGED option (CVE-2019-20044) SL6 x86_64 zsh-4.3.11-11.el6_10.x86_64.rpm zsh-debuginfo-4.3.11-11.el6_10.x86_64.rpm zsh-html-4.3.11-11.el6_10.x86_64.rpm i386 zsh-4.3.11-11.el6_10.i686.rpm zsh-debuginfo-4.3.11-11.el6_10.i686.rpm zsh-html-4.3.11-11.el6_10.i686.rpm - Scientific Linux Development Team
ICU: Integer overflow in UnicodeString::doAppend() (CVE-2020-10531) SL7 x86_64 icu-debuginfo-50.2-4.el7_7.i686.rpm icu-debuginfo-50.2-4.el7_7.x86_64.rpm libicu-50.2-4.el7_7.i686.rpm libicu-50.2-4.el7_7.x86_64.rpm icu-50.2-4.el7_7.x86_64.rpm libicu-devel-50.2-4.el7_7.i686.rpm libicu-devel-50.2-4.el7_7.x86_64.rpm noarch libicu-doc-50.2-4.el7_7.noarch.rpm - S [More...]
kernel: Count overflow in FUSE request leading to use-after-free issues. (CVE-2019-11487) * kernel: rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel lacks a certain upper-bound check, leading to a buffer overflow (CVE-2019-17666) * Kernel: KVM: export MSR_IA32_TSX_CTRL to guest - incomplete fix for TAA (CVE-2019-11135) (CVE-2019-19338) Bug Fix(es): * SL7.7 - [More...]
python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure (CVE-2018-20060) * python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service (CVE-2019-11236) * python-urllib3: Certification mishandle when error should be thrown (CVE-2019-11324) * python-requests: Redirect from HTTPS to HTTP do [More...]
tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability (CVE-2020-1938) SL7 noarch tomcat-servlet-3.0-api-7.0.76-11.el7_7.noarch.rpm tomcat-7.0.76-11.el7_7.noarch.rpm tomcat-admin-webapps-7.0.76-11.el7_7.noarch.rpm tomcat-docs-webapp-7.0.76-11.el7_7.noarch.rpm tomcat-el-2.2-api-7.0.76-11.el7_7.noarch.rpm tomcat-javadoc-7.0.76-11.el7_7.noarch.rpm tomcat-jsp-2. [More...]
zsh: insecure dropping of privileges when unsetting PRIVILEGED option (CVE-2019-20044) SL7 x86_64 zsh-5.0.2-34.el7_7.2.x86_64.rpm zsh-debuginfo-5.0.2-34.el7_7.2.x86_64.rpm zsh-html-5.0.2-34.el7_7.2.x86_64.rpm - Scientific Linux Development Team
python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure (CVE-2018-20060) * python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service (CVE-2019-11236) * python-requests: Redirect from HTTPS to HTTP does not remove Authorization header (CVE-2018-18074) SL7 noarch python-virtualenv- [More...]
This update upgrades Firefox to version 68.6.0 ESR. * Mozilla: Use-after-free when removing data about origins (CVE-2020-6805) * Mozilla: BodyStream::OnInputStreamReady was missing protections against state confusion (CVE-2020-6806) * Mozilla: Use-after-free in cubeb during stream destruction (CVE-2020-6807) * Mozilla: Memory safety bugs fixed in Firefox 74 and Firefox ESR 68.6 (CVE-2020-681 [More...]
This update upgrades Firefox to version 68.6.0 ESR. * Mozilla: Use-after-free when removing data about origins (CVE-2020-6805) * Mozilla: BodyStream::OnInputStreamReady was missing protections against state confusion (CVE-2020-6806) * Mozilla: Use-after-free in cubeb during stream destruction (CVE-2020-6807) * Mozilla: Memory safety bugs fixed in Firefox 74 and Firefox ESR 68.6 (CVE-2020-681 [More...]
kernel: buffer overflow in cfg80211_mgd_wext_giwessid in net/wireless /wext-sme.c (CVE-2019-17133) * kernel: unprivileged users able to create RAW sockets in AF_ISDN network protocol. (CVE-2019-17055) Bug Fix(es): * LACP bond does not function because bonding driver sees slave speed & duplex as Unknown * ixgbevf guess causes excessive interrupts in hypervisor due to get link settings SL6 [More...]