Scientific Essential and Critical Security Patch Updates

Find the information you need for your favorite open source distribution .

SciLinux: SLSA-2019-2181-1 Low: curl on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

curl: Heap-based buffer over-read in the curl tool warning formatting (CVE-2018-16842) SL7 x86_64 curl-7.29.0-54.el7.x86_64.rpm libcurl-7.29.0-54.el7.x86_64.rpm libcurl-7.29.0-54.el7.i686.rpm libcurl-devel-7.29.0-54.el7.x86_64.rpm libcurl-devel-7.29.0-54.el7.i686.rpm curl-debuginfo-7.29.0-54.el7.i686.rpm curl-debuginfo-7.29.0-54.el7.x86_64.rpm - Scientific Linux [More...]

SciLinux: SLSA-2019-2077-1 Low: ntp on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

ntp: Stack-based buffer overflow in ntpq and ntpdc allows denial of service or code execution (CVE-2018-12327) SL7 x86_64 ntpdate-4.2.6p5-29.el7.x86_64.rpm ntp-4.2.6p5-29.el7.x86_64.rpm ntp-doc-4.2.6p5-29.el7.noarch.rpm sntp-4.2.6p5-29.el7.x86_64.rpm ntp-perl-4.2.6p5-29.el7.noarch.rpm ntp-debuginfo-4.2.6p5-29.el7.x86_64.rpm noarch ntp-doc-4.2.6p5-29.el7.noarch. [More...]

SciLinux: SLSA-2019-2272-1 Moderate: python-urllib3 on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure (CVE-2018-20060) * python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service (CVE-2019-11236) SL7 x86_64 python-urllib3-1.10.2-7.el7.noarch.rpm noarch python-urllib3-1.10.2-7.el7.noarch.rpm - Scientific Linux Developme [More...]

SciLinux: SLSA-2019-2283-1 Low: sox on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

sox: NULL pointer dereference in startread function in xa.c (CVE-2017-18189) SL7 x86_64 sox-14.4.1-7.el7.x86_64.rpm sox-14.4.1-7.el7.i686.rpm sox-devel-14.4.1-7.el7.i686.rpm sox-devel-14.4.1-7.el7.x86_64.rpm sox-debuginfo-14.4.1-7.el7.i686.rpm sox-debuginfo-14.4.1-7.el7.x86_64.rpm - Scientific Linux Development Team

SciLinux: SLSA-2019-2046-1 Moderate: polkit on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

polkit: Improper handling of user with uid > INT_MAX leading to authentication bypass (CVE-2018-19788) SL7 x86_64 polkit-devel-0.112-22.el7.x86_64.rpm polkit-docs-0.112-22.el7.noarch.rpm polkit-0.112-22.el7.x86_64.rpm polkit-0.112-22.el7.i686.rpm polkit-devel-0.112-22.el7.i686.rpm polkit-debuginfo-0.112-22.el7.i686.rpm polkit-debuginfo-0.112-22.el7.x86_64.rpm n [More...]

SciLinux: SLSA-2019-2276-1 Moderate: mercurial on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

mercurial: Buffer underflow in mpatch.c:mpatch_apply() (CVE-2018-13347) * mercurial: HTTP server permissions bypass (CVE-2018-1000132) * mercurial: Missing check for fragment start position in mpatch.c:mpatch_apply() (CVE-2018-13346) SL7 x86_64 mercurial-2.6.2-10.el7.x86_64.rpm emacs-mercurial-el-2.6.2-10.el7.x86_64.rpm emacs-mercurial-2.6.2-10.el7.x86_64.rpm mercurial-hgk [More...]

SciLinux: SLSA-2019-2336-1 Moderate: unixODBC on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

unixODBC: Buffer overflow in unicode_to_ansi_copy() can lead to crash or other unspecified impact (CVE-2018-7409) * unixODBC: Insecure buffer copy in SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c (CVE-2018-7485) SL7 x86_64 unixODBC-devel-2.3.1-14.el7.x86_64.rpm unixODBC-2.3.1-14.el7.i686.rpm unixODBC-devel-2.3.1-14.el7.i686.rpm unixODBC-2.3.1-14.el7.x86_64.rpm [More...]

SciLinux: SLSA-2019-2126-1 Low: libwpd on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

libwpd: NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp (CVE-2018-19208) SL7 x86_64 libwpd-0.10.0-2.el7.i686.rpm libwpd-0.10.0-2.el7.x86_64.rpm libwpd-doc-0.10.0-2.el7.noarch.rpm libwpd-devel-0.10.0-2.el7.i686.rpm libwpd-tools-0.10.0-2.el7.x86_64.rpm libwpd-devel-0.10.0-2.el7.x86_64.rpm libwpd-debuginfo-0.10.0-2. [More...]

SciLinux: SLSA-2019-2471-1 Moderate: openssl on SL6.x i386/x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

openssl: 0-byte record padding oracle (CVE-2019-1559) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. SL6 x86_64 openssl-1.0.1e-58.el6_10.i686.rpm openssl-1.0.1e-58.el6_10.x86_64.rpm openssl-debuginfo-1.0.1e-58.el6_10.i686.rpm openssl- [More...]

SciLinux: SLSA-2019-2473-1 Important: kernel on SL6.x i386/x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Kernel: page cache side channel attacks (CVE-2019-5489) * kernel: Salsa20 encryption algorithm does not correctly handle zero-length inputs allowing local attackers to cause denial-of-service (CVE-2017-17805) * kernel: Unprivileged users able to inspect kernel stacks of arbitrary tasks (CVE-2018-17972) * kernel: hw: Spectre SWAPGS gadget vulnerability (CVE-2019-1125) For more d [More...]

SciLinux: SLSA-2019-2003-1 Important: icedtea-web on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

icedtea-web: path traversal while processing elements of JNLP files results in arbitrary file overwrite (CVE-2019-10182) * icedtea-web: directory traversal in the nested jar auto-extraction leading to arbitrary file overwrite (CVE-2019-10185) * icedtea-web: unsigned code injection in a signed JAR file (CVE-2019-10181) SL7 x86_64 icedtea-web-1.7.1-2.el7_6.x86_64.rpm icedtea- [More...]

SciLinux: SLSA-2019-1873-1 Important: kernel on SL7.x x86_64

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

kernel: nfs: use-after-free in svc_process_common() (CVE-2018-16884) * kernel: insufficient input validation in kernel mode driver in Intel i915 graphics leads to privilege escalation (CVE-2019-11085) * kernel: nfs: NULL pointer dereference due to an anomalized NFS message sequence (CVE-2018-16871) * kernel: use-after-free in drivers/char/ipmi/ipmi_si_intf.c, ipmi_si_mem_io.c, ipmi_si_port_ [More...]