Moderate: ghostscript security update
Moderate: ghostscript security update
Moderate: libtiff security update
Moderate: ghostscript security update
Moderate: glibc security update
Moderate: glibc security update
Moderate: glibc security update
Moderate: kernel security update
Moderate: gcc security update
Doxygen can generate an online class browser (in HTML) and/or a reference manual (in LaTeX) from a set of documented source files. The documentation is extracted directly from the sources. Doxygen can also be configured to extract the code structure from undocumented source files. <br>Security Fix(es):<br><li> jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods (CVE-2020-11023)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Doxygen can generate an online class browser (in HTML) and/or a reference manual (in LaTeX) from a set of documented source files. The documentation is extracted directly from the sources. Doxygen can also be configured to extract the code structure from undocumented source files. Security Fix(es): jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods (CVE-2020-11023) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Doxygen can generate an online class browser (in HTML) and/or a reference manual (in LaTeX) from a set of documented source files. The documentation is extracted directly from the sources. Doxygen can also be configured to extract the code structure from undocumented source files. <br>Security Fix(es):<br><li> jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods (CVE-2020-11023)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Doxygen can generate an online class browser (in HTML) and/or a reference manual (in LaTeX) from a set of documented source files. The documentation is extracted directly from the sources. Doxygen can also be configured to extract the code structure from undocumented source files. <br>Security Fix(es):<br><li> jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods (CVE-2020-11023)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: java-17-openjdk security update for RHEL 8.6, 8.8, 8.10, 9.4 and 9.5
Moderate: java-17-openjdk security update for RHEL 9.0 and 9.2
Moderate: java-21-openjdk security update for RHEL 8.10, 9.4 and 9.5
Moderate: Security and bug fixes for NetworkManager
Moderate: Bug fix of NetworkManager
Moderate: libvpx security update
Moderate: xorg-x11-server-Xwayland security update
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.<br>Security Fix(es):<br><li> freerdp: Integer Overflow leading to Heap Overflow in freerdpbitmapplanarcontextreset (CVE-2024-22211)</li> <li> freerdp: out-of-bounds read in ncrushdecompress (CVE-2024-32459)</li> <li> freerdp: OutOfBound Read in interleaveddecompress (CVE-2024-32460)</li> <li> freerdp: Integer overflow & OutOfBound Write in cleardecompressresidualdata (CVE-2024-32039)</li> <li> freerdp: integer underflow in nscrledecode (CVE-2024-32040)</li> <li> freerdp: OutOfBound Read in zgfxdecompresssegment (CVE-2024-32041)</li> <li> freerdp: OutOfBound Read in planarskipplanerle (CVE-2024-32458)</li> <li> freerdp: out-of-bounds read (CVE-2024-32662)</li> <li> FreeRDP: ExtractRunLengthRegular out of bound read (CVE-2024-32658)</li> <li> freerdp: zgfxdecompress out of memory (CVE-2024-32660)</li> <li> freerdp: freerdpimagecopy out of bound read (CVE-2024-32659)</li> <li> freerdp: rdpwritelogoninfov1 NULL access (CVE-2024-32661)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.5 Release Notes linked from the References section.
Kernel-based Virtual Machine (KVM) offers a full virtualization solution forLinux on numerous hardware platforms. The virt:rhel module contains packageswhich provide user-space components used to run virtual machines using KVM.The packages also provide APIs for managing and interacting with the virtualized systems.Security Fix(es): libvirt: Crash of virtinterfaced via virConnectListInterfaces() (CVE-2024-8235) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.5 Release Notes linked from the References section.
FontForge is a font editor for outline and bitmap fonts. It supports a range of font formats, including PostScript (ASCII and binary Type 1, some Type 3 and Type 0), TrueType, OpenType (Type2) and CID-keyed fonts. Security Fix(es): fontforge: command injection via crafted archives or compressed files (CVE-2024-25082) fontforge: command injection via crafted filenames (CVE-2024-25081) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.5 Release Notes linked from the References section.
libuv is a multi-platform support library with a focus on asynchronous I/O. Security Fix(es): libuv: Improper Domain Lookup that potentially leads to SSRF attacks (CVE-2024-24806) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: OpenIPMI security update
Moderate: OpenIPMI security update
Moderate: python3.11 security update
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. <br>Security Fix(es):<br><li> dovecot: using a large number of address headers may trigger a denial of service (CVE-2024-23184)</li> <li> dovecot: very large headers can cause resource exhaustion when parsing message (CVE-2024-23185)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): dovecot: using a large number of address headers may trigger a denial of service (CVE-2024-23184) dovecot: very large headers can cause resource exhaustion when parsing message (CVE-2024-23185) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: ghostscript security update