Moderate: gnutls security update
Moderate: ipa security update
Moderate: python3 security update
Moderate: php:8.1 security update
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.Security Fix(es): ssh: Prefix truncation attack on Binary Packet Protocol (BPP) (CVE-2023-48795) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: gnutls security update
Moderate: rpm security update
Moderate: libmaxminddb security update
Moderate: nss security update
Moderate: opensc security update
Moderate: opensc security update
Moderate: curl security update
Moderate: skopeo security update
Moderate: opencryptoki security update
Moderate: haproxy security update
Moderate: buildah security update
Moderate: mysql security update
Moderate: ruby:3.1 security, bug fix, and enhancement update
Moderate: thunderbird security update
Moderate: thunderbird security update
Expat is a C library for parsing XML documents.Security Fix(es): expat: parsing large tokens can trigger a denial of service (CVE-2023-52425) expat: XML Entity Expansion (CVE-2024-28757)
Moderate: ruby:3.1 security, bug fix, and enhancement update
Moderate: curl security and bug fix update
Moderate: opencryptoki security update
Expat is a C library for parsing XML documents.Security Fix(es): expat: parsing large tokens can trigger a denial of service (CVE-2023-52425) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: gnutls security update
Moderate: gnutls security update
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.Security Fix(es): gstreamer-plugins-bad: Integer overflow leading to heap overwrite in MXF file handling with uncompressed video (CVE-2023-40474) gstreamer-plugins-bad: Integer overflow leading to heap overwrite in MXF file handling with AES3 audio (CVE-2023-40475) gstreamer-plugins-bad: Integer overflow in H.265 video parser leading to stack overwrite (CVE-2023-40476) gstreamer-plugins-bad-free: buffer overflow vulnerability (CVE-2023-50186) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.4 Release Notes linked from the References section.
Moderate: httpd security update
Moderate: systemd security update