VARIoT IoT vulnerabilities database
| VAR-202006-1814 | CVE-2020-3208 | Cisco IOS Software permission management vulnerabilities |
CVSS V2: 7.2 CVSS V3: 6.7 Severity: MEDIUM |
A vulnerability in the image verification feature of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) could allow an authenticated, local attacker to boot a malicious software image on an affected device. The vulnerability is due to insufficient access restrictions on the area of code that manages the image verification feature. An attacker could exploit this vulnerability by first authenticating to the targeted device and then logging in to the Virtual Device Server (VDS) of an affected device. The attacker could then, from the VDS shell, disable Cisco IOS Software integrity (image) verification. A successful exploit could allow the attacker to boot a malicious Cisco IOS Software image on the targeted device. To exploit this vulnerability, the attacker must have valid user credentials at privilege level 15. Cisco IOS The software contains a vulnerability in privilege management.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state
| VAR-202006-1102 | CVE-2020-3235 | Cisco IOS and IOS XE Input verification vulnerabilities in software |
CVSS V2: 6.3 CVSS V3: 7.7 Severity: HIGH |
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the software processes specific SNMP object identifiers. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: To exploit this vulnerability by using SNMPv2c or earlier, the attacker must know the SNMP read-only community string for an affected system. To exploit this vulnerability by using SNMPv3, the attacker must know the user credentials for the affected system
| VAR-202006-1135 | CVE-2020-3322 | Microsoft Windows for Cisco Webex Network Recording Player and Cisco Webex Player Input verification vulnerability in |
CVSS V2: 4.3 CVSS V3: 3.3 Severity: LOW |
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file
| VAR-202006-1134 | CVE-2020-3321 | Windows for Cisco Webex Network Recording Player and Cisco Webex Player Input verification vulnerability in |
CVSS V2: 4.3 CVSS V3: 3.3 Severity: LOW |
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file
| VAR-202006-1121 | CVE-2020-3281 | Cisco Digital Network Architecture Center Vulnerability regarding information leakage from log files in |
CVSS V2: 4.0 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices. (DoS) It may be put into a state
| VAR-202006-1133 | CVE-2020-3319 | Microsoft Windows for Cisco Webex Network Recording Player and Webex Player Input verification vulnerability in |
CVSS V2: 4.3 CVSS V3: 3.3 Severity: LOW |
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file. This vulnerability affects Cisco Webex Network Recording Player and Webex Player releases earlier than Release 3.0 MR3 Security Patch 2 and 4.0 MR3
| VAR-202006-1083 | CVE-2020-3216 | Cisco IOS XE SD-WAN Authentication vulnerabilities in software |
CVSS V2: 7.2 CVSS V3: 6.8 Severity: MEDIUM |
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication mechanisms for certain commands. An attacker could exploit this vulnerability by stopping the boot initialization of an affected device. A successful exploit could allow the attacker to bypass authentication and gain unrestricted access to the root shell of the affected device. Cisco IOS XE SD-WAN The software contains an authentication vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. Both Cisco IOS and IOS XE are products of Cisco (Cisco). CLI is one of those command line interfaces. SD-WAN Software is one of the software-defined WAN software
| VAR-202006-1060 | CVE-2020-1883 | plural Huawei Vulnerability in lack of release of resources after valid lifetime in product |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability can cause service abnormal. NIP6800 , Secospace USG6600 , USG9500 Is vulnerable to a lack of resource release after a valid lifetime.Service operation interruption (DoS) It may be put into a state
| VAR-202006-1878 | CVE-2020-1819 | plural Huawei Product out-of-bounds read vulnerability |
CVSS V2: - CVSS V3: 3.7 Severity: LOW |
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. IPS Module firmware, NGFW Module firmware, NIP6300 firmware etc. Huawei The product contains an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202006-1877 | CVE-2020-1818 | plural Huawei Product out-of-bounds read vulnerability |
CVSS V2: - CVSS V3: 3.7 Severity: LOW |
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. IPS Module firmware, NGFW Module firmware, NIP6300 firmware etc. Huawei The product contains an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202006-1881 | CVE-2020-1821 | plural Huawei Product out-of-bounds read vulnerability |
CVSS V2: - CVSS V3: 3.7 Severity: LOW |
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. IPS Module firmware, NGFW Module firmware, NIP6300 firmware etc. Huawei The product contains an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202006-1879 | CVE-2020-1824 | plural Huawei Product out-of-bounds read vulnerability |
CVSS V2: - CVSS V3: 3.7 Severity: LOW |
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. IPS Module firmware, NGFW Module firmware, NIP6300 firmware etc. Huawei The product contains an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202006-1876 | CVE-2020-1823 | plural Huawei Product out-of-bounds read vulnerability |
CVSS V2: - CVSS V3: 3.7 Severity: LOW |
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. IPS Module firmware, NGFW Module firmware, NIP6300 firmware etc. Huawei The product contains an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202006-1874 | CVE-2020-1820 | plural Huawei Product out-of-bounds read vulnerability |
CVSS V2: - CVSS V3: 3.7 Severity: LOW |
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. IPS Module firmware, NGFW Module firmware, NIP6300 firmware etc. Huawei The product contains an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202006-1873 | CVE-2020-1822 | plural Huawei Product out-of-bounds read vulnerability |
CVSS V2: - CVSS V3: 3.7 Severity: LOW |
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. IPS Module firmware, NGFW Module firmware, NIP6300 firmware etc. Huawei The product contains an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202006-0115 | CVE-2020-13227 | Codeorigin Sysax Multi Server Path Traversal Vulnerability |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fakepath protection mechanism. Codeorigin Sysax Multi Server is an FTP (File Transfer Protocol) server and Shell server for Windows system of American Codeorigin company. The vulnerability stems from network systems or products failing to properly filter special elements in resources or file paths. An attacker could use the vulnerability to access a location outside the restricted directory
| VAR-202006-1806 | CVE-2020-12723 | Perl Classic buffer overflow vulnerability in |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. A security vulnerability exists in the regcomp.c file in versions prior to Perl 5.30.3. An attacker could exploit this vulnerability to cause a denial of service or potentially execute code. Description:
Security Fix(es):
* Addressed a security issue which can allow a malicious playbook author to
elevate to the awx user from outside the isolated environment:
CVE-2021-20253
* Upgraded to a more recent version of Django to address CVE-2021-3281.
* Upgraded to a more recent version of autobahn to address CVE-2020-35678.
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* Upgraded to the latest oVirt inventory plugin to resolve a number of
inventory syncing issues that can occur on RHEL7.
* Upgraded to the latest theforeman.foreman inventory plugin to resolve a
few bugs and performance regressions.
* Fixed several issues related to how Tower rotates its log files.
* Fixed a bug which can prevent Tower from installing on RHEL8 with certain
non-en_US.UTF-8 locales.
* Fixed a bug which can cause unanticipated delays in certain playbook
output.
* Fixed a bug which can cause job runs to fail for playbooks that print
certain types of raw binary data.
* Fixed a bug which can cause unnecessary records in the Activity Stream
when Automation Analytics data is collected.
* Fixed a bug which can cause Tower PostgreSQL backups to fail when a
non-default PostgreSQL username is specified.
* Fixed a bug which can intermittently cause access to encrypted Tower
settings to fail, resulting in failed job launches.
* Fixed a bug which can cause certain long-running jobs running on isolated
nodes to unexpectedly fail. Solution:
For information on upgrading Ansible Tower, reference the Ansible Tower
Upgrade and Migration Guide:
https://docs.ansible.com/ansible-tower/latest/html/upgrade-migration-guide/
index.html
4. Bugs fixed (https://bugzilla.redhat.com/):
1911314 - CVE-2020-35678 python-autobahn: allows redirect header injection
1919969 - CVE-2021-3281 django: Potential directory-traversal via archive.extract()
1928847 - CVE-2021-20253 ansible-tower: Privilege escalation via job isolation escape
5. Description:
Red Hat 3scale API Management delivers centralized API management features
through a distributed, cloud-hosted layer. It includes built-in features to
help in building a more successful API program, including access control,
rate limits, payment gateway integration, and developer experience tools. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied. Bugs fixed (https://bugzilla.redhat.com/):
1804533 - CVE-2020-9283 golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic
1853652 - CVE-2020-14040 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash
5. 8) - aarch64, noarch, ppc64le, s390x, x86_64
3. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: perl security update
Advisory ID: RHSA-2021:0343-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:0343
Issue date: 2021-02-02
CVE Names: CVE-2020-10543 CVE-2020-10878 CVE-2020-12723
====================================================================
1. Summary:
An update for perl is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3. Description:
Perl is a high-level programming language that is commonly used for system
administration utilities and web programming.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Package List:
Red Hat Enterprise Linux Client (v. 7):
Source:
perl-5.16.3-299.el7_9.src.rpm
noarch:
perl-CPAN-1.9800-299.el7_9.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-299.el7_9.noarch.rpm
perl-ExtUtils-Embed-1.30-299.el7_9.noarch.rpm
perl-ExtUtils-Install-1.58-299.el7_9.noarch.rpm
perl-IO-Zlib-1.10-299.el7_9.noarch.rpm
perl-Locale-Maketext-Simple-0.21-299.el7_9.noarch.rpm
perl-Module-CoreList-2.76.02-299.el7_9.noarch.rpm
perl-Module-Loaded-0.08-299.el7_9.noarch.rpm
perl-Object-Accessor-0.42-299.el7_9.noarch.rpm
perl-Package-Constants-0.02-299.el7_9.noarch.rpm
perl-Pod-Escapes-1.04-299.el7_9.noarch.rpm
x86_64:
perl-5.16.3-299.el7_9.x86_64.rpm
perl-Time-Piece-1.20.1-299.el7_9.x86_64.rpm
perl-core-5.16.3-299.el7_9.x86_64.rpm
perl-debuginfo-5.16.3-299.el7_9.i686.rpm
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-devel-5.16.3-299.el7_9.i686.rpm
perl-devel-5.16.3-299.el7_9.x86_64.rpm
perl-libs-5.16.3-299.el7_9.i686.rpm
perl-libs-5.16.3-299.el7_9.x86_64.rpm
perl-macros-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-tests-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
perl-5.16.3-299.el7_9.src.rpm
noarch:
perl-CPAN-1.9800-299.el7_9.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-299.el7_9.noarch.rpm
perl-ExtUtils-Embed-1.30-299.el7_9.noarch.rpm
perl-ExtUtils-Install-1.58-299.el7_9.noarch.rpm
perl-IO-Zlib-1.10-299.el7_9.noarch.rpm
perl-Locale-Maketext-Simple-0.21-299.el7_9.noarch.rpm
perl-Module-CoreList-2.76.02-299.el7_9.noarch.rpm
perl-Module-Loaded-0.08-299.el7_9.noarch.rpm
perl-Object-Accessor-0.42-299.el7_9.noarch.rpm
perl-Package-Constants-0.02-299.el7_9.noarch.rpm
perl-Pod-Escapes-1.04-299.el7_9.noarch.rpm
x86_64:
perl-5.16.3-299.el7_9.x86_64.rpm
perl-Time-Piece-1.20.1-299.el7_9.x86_64.rpm
perl-core-5.16.3-299.el7_9.x86_64.rpm
perl-debuginfo-5.16.3-299.el7_9.i686.rpm
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-devel-5.16.3-299.el7_9.i686.rpm
perl-devel-5.16.3-299.el7_9.x86_64.rpm
perl-libs-5.16.3-299.el7_9.i686.rpm
perl-libs-5.16.3-299.el7_9.x86_64.rpm
perl-macros-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-tests-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
perl-5.16.3-299.el7_9.src.rpm
noarch:
perl-CPAN-1.9800-299.el7_9.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-299.el7_9.noarch.rpm
perl-ExtUtils-Embed-1.30-299.el7_9.noarch.rpm
perl-ExtUtils-Install-1.58-299.el7_9.noarch.rpm
perl-IO-Zlib-1.10-299.el7_9.noarch.rpm
perl-Locale-Maketext-Simple-0.21-299.el7_9.noarch.rpm
perl-Module-CoreList-2.76.02-299.el7_9.noarch.rpm
perl-Module-Loaded-0.08-299.el7_9.noarch.rpm
perl-Object-Accessor-0.42-299.el7_9.noarch.rpm
perl-Package-Constants-0.02-299.el7_9.noarch.rpm
perl-Pod-Escapes-1.04-299.el7_9.noarch.rpm
ppc64:
perl-5.16.3-299.el7_9.ppc64.rpm
perl-Time-Piece-1.20.1-299.el7_9.ppc64.rpm
perl-core-5.16.3-299.el7_9.ppc64.rpm
perl-debuginfo-5.16.3-299.el7_9.ppc.rpm
perl-debuginfo-5.16.3-299.el7_9.ppc64.rpm
perl-devel-5.16.3-299.el7_9.ppc.rpm
perl-devel-5.16.3-299.el7_9.ppc64.rpm
perl-libs-5.16.3-299.el7_9.ppc.rpm
perl-libs-5.16.3-299.el7_9.ppc64.rpm
perl-macros-5.16.3-299.el7_9.ppc64.rpm
ppc64le:
perl-5.16.3-299.el7_9.ppc64le.rpm
perl-Time-Piece-1.20.1-299.el7_9.ppc64le.rpm
perl-core-5.16.3-299.el7_9.ppc64le.rpm
perl-debuginfo-5.16.3-299.el7_9.ppc64le.rpm
perl-devel-5.16.3-299.el7_9.ppc64le.rpm
perl-libs-5.16.3-299.el7_9.ppc64le.rpm
perl-macros-5.16.3-299.el7_9.ppc64le.rpm
s390x:
perl-5.16.3-299.el7_9.s390x.rpm
perl-Time-Piece-1.20.1-299.el7_9.s390x.rpm
perl-core-5.16.3-299.el7_9.s390x.rpm
perl-debuginfo-5.16.3-299.el7_9.s390.rpm
perl-debuginfo-5.16.3-299.el7_9.s390x.rpm
perl-devel-5.16.3-299.el7_9.s390.rpm
perl-devel-5.16.3-299.el7_9.s390x.rpm
perl-libs-5.16.3-299.el7_9.s390.rpm
perl-libs-5.16.3-299.el7_9.s390x.rpm
perl-macros-5.16.3-299.el7_9.s390x.rpm
x86_64:
perl-5.16.3-299.el7_9.x86_64.rpm
perl-Time-Piece-1.20.1-299.el7_9.x86_64.rpm
perl-core-5.16.3-299.el7_9.x86_64.rpm
perl-debuginfo-5.16.3-299.el7_9.i686.rpm
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-devel-5.16.3-299.el7_9.i686.rpm
perl-devel-5.16.3-299.el7_9.x86_64.rpm
perl-libs-5.16.3-299.el7_9.i686.rpm
perl-libs-5.16.3-299.el7_9.x86_64.rpm
perl-macros-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
perl-debuginfo-5.16.3-299.el7_9.ppc64.rpm
perl-tests-5.16.3-299.el7_9.ppc64.rpm
ppc64le:
perl-debuginfo-5.16.3-299.el7_9.ppc64le.rpm
perl-tests-5.16.3-299.el7_9.ppc64le.rpm
s390x:
perl-debuginfo-5.16.3-299.el7_9.s390x.rpm
perl-tests-5.16.3-299.el7_9.s390x.rpm
x86_64:
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-tests-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
perl-5.16.3-299.el7_9.src.rpm
noarch:
perl-CPAN-1.9800-299.el7_9.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-299.el7_9.noarch.rpm
perl-ExtUtils-Embed-1.30-299.el7_9.noarch.rpm
perl-ExtUtils-Install-1.58-299.el7_9.noarch.rpm
perl-IO-Zlib-1.10-299.el7_9.noarch.rpm
perl-Locale-Maketext-Simple-0.21-299.el7_9.noarch.rpm
perl-Module-CoreList-2.76.02-299.el7_9.noarch.rpm
perl-Module-Loaded-0.08-299.el7_9.noarch.rpm
perl-Object-Accessor-0.42-299.el7_9.noarch.rpm
perl-Package-Constants-0.02-299.el7_9.noarch.rpm
perl-Pod-Escapes-1.04-299.el7_9.noarch.rpm
x86_64:
perl-5.16.3-299.el7_9.x86_64.rpm
perl-Time-Piece-1.20.1-299.el7_9.x86_64.rpm
perl-core-5.16.3-299.el7_9.x86_64.rpm
perl-debuginfo-5.16.3-299.el7_9.i686.rpm
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-devel-5.16.3-299.el7_9.i686.rpm
perl-devel-5.16.3-299.el7_9.x86_64.rpm
perl-libs-5.16.3-299.el7_9.i686.rpm
perl-libs-5.16.3-299.el7_9.x86_64.rpm
perl-macros-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-tests-5.16.3-299.el7_9.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2020-10543
https://access.redhat.com/security/cve/CVE-2020-10878
https://access.redhat.com/security/cve/CVE-2020-12723
https://access.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYBlBRdzjgjWX9erEAQgfWQ/+Pzq//upZZVPBq5+myRLRJCef7277Y+9k
54oh8wOTwtwEMs9ye5Y1FDmAxVd4fWX3JgAss1KE86Hhm5OoCX/FJ0/RGguMR1l2
qwmWtfGuZjrn1SmjdHlf8B/bC0f20IadUUbY/8clpFiMxe5V1g8s9ZgbHv/MBWnm
Awac/6LPc7Eb24OnIuTKLYEcQRxuBG1KdikM1NN1uJU5WHkbhZfKWFMnjKihsPGp
42vnomd0P7RdXNc4FbuNlkm2iw04woJyz1AYPdScswWJqawQSbre6+3wpnHlWs4K
RerhKZiJLJsC0XmSpma62I4kYbVlniYPcbrF4Zfo1j1vIIvjmOL26B/3JsUVtwfm
AKVuAu8DbNIkdSo2CS2gauLWsykukprPx16X8n8Xlb9Kr9iL/r2/sI/jUGce+50S
aoe2Hb40VIX6sHPLiEmWP0ufuoDxJZ2mY9mhqAMGt/xCPrZ/Pst0y4hewJVo2AIf
/LG758/KJWYBx2ILfBwA07O829irVDnbw5blT47fS3qiqAzXRTp56xkCCnLQ0BGQ
Ip3DFIwNVxznKYOgubXJBGl3xYHI+P/bu8tcCAYMaN4hAHdFrqJbPMNLLGf37L73
N83csDc07k/WsKua5atl3suUuYRWxSq6CnV9KNU4aUaKEmu+de+D2k34vn2+le0S
HB63T1smQXA=Oj1P
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
. 7) - aarch64, ppc64le, s390x
3
| VAR-202006-1807 | CVE-2020-10878 | Perl Input validation error vulnerability |
CVSS V2: 7.5 CVSS V3: 8.6 Severity: HIGH |
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. An input validation error vulnerability exists in Perl versions prior to 5.30.3. The vulnerability is caused by the program's incorrect handling of the \"PL_regkind[OP(n)] == NOTHING\" case. 8) - aarch64, noarch, ppc64le, s390x, x86_64
3.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.4 Release Notes linked from the References section.
Bug fix:
* RHACM 2.0.8 images (BZ #1915461)
3. Bugs fixed (https://bugzilla.redhat.com/):
1915461 - RHACM 2.0.8 images
1921650 - CVE-2021-3121 gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation
5. Description:
Red Hat Advanced Cluster Management for Kubernetes 2.2.4 images
Red Hat Advanced Cluster Management for Kubernetes provides the
capabilities to address common challenges that administrators and site
reliability
engineers face as they work across a range of public and private cloud
environments.
Clusters and applications are all visible and managed from a single
console—with security policy built in. See
the following Release Notes documentation, which will be updated shortly
for
this release, for additional details about this release:
https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_mana
gement_for_kubernetes/2.2/html/release_notes/
Security fixes:
* redisgraph-tls: redis: integer overflow when configurable limit for
maximum supported bulk input size is too big on 32-bit platforms
(CVE-2021-21309)
* console-header-container: nodejs-netmask: improper input validation of
octal input data (CVE-2021-28092)
* console-container: nodejs-is-svg: ReDoS via malicious string
(CVE-2021-28918)
Bug fixes:
* RHACM 2.2.4 images (BZ# 1957254)
* Enabling observability for OpenShift Container Storage with RHACM 2.2 on
OCP 4.7 (BZ#1950832)
* ACM Operator should support using the default route TLS (BZ# 1955270)
* The scrolling bar for search filter does not work properly (BZ# 1956852)
* Limits on Length of MultiClusterObservability Resource Name (BZ# 1959426)
* The proxy setup in install-config.yaml is not worked when IPI installing
with RHACM (BZ# 1960181)
* Unable to make SSH connection to a Bitbucket server (BZ# 1966513)
* Observability Thanos store shard crashing - cannot unmarshall DNS message
(BZ# 1967890)
3. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied. Bugs fixed (https://bugzilla.redhat.com/):
1932634 - CVE-2021-21309 redis: integer overflow when configurable limit for maximum supported bulk input size is too big on 32-bit platforms
1939103 - CVE-2021-28092 nodejs-is-svg: ReDoS via malicious string
1944827 - CVE-2021-28918 nodejs-netmask: improper input validation of octal input data
1950832 - Enabling observability for OpenShift Container Storage with RHACM 2.2 on OCP 4.7
1952150 - [DDF] It would be great to see all the options available for the bucket configuration and which attributes are mandatory
1954506 - [DDF] Table does not contain data about 20 clusters. Now it's difficult to estimate CPU usage with larger clusters
1954535 - Reinstall Submariner - No endpoints found on one cluster
1955270 - ACM Operator should support using the default route TLS
1956852 - The scrolling bar for search filter does not work properly
1957254 - RHACM 2.2.4 images
1959426 - Limits on Length of MultiClusterObservability Resource Name
1960181 - The proxy setup in install-config.yaml is not worked when IPI installing with RHACM.
1963128 - [DDF] Please rename this to "Amazon Elastic Kubernetes Service"
1966513 - Unable to make SSH connection to a Bitbucket server
1967357 - [DDF] When I clicked on this yaml, I get a HTTP 404 error.
1967890 - Observability Thanos store shard crashing - cannot unmarshal DNS message
5. Description:
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.7.13. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHSA-2021:2122
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-rel
ease-notes.html
This update fixes the following bug among others:
* Previously, resources for the ClusterOperator were being created early in
the update process, which led to update failures when the ClusterOperator
had no status condition while Operators were updating. This bug fix changes
the timing of when these resources are created. As a result, updates can
take place without errors. (BZ#1959238)
Security Fix(es):
* gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index
validation (CVE-2021-3121)
You may download the oc tool and use it to inspect release image metadata
as follows:
(For x86_64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.7.13-x86_64
The image digest is
sha256:783a2c963f35ccab38e82e6a8c7fa954c3a4551e07d2f43c06098828dd986ed4
(For s390x architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.7.13-s390x
The image digest is
sha256:4cf44e68413acad063203e1ee8982fd01d8b9c1f8643a5b31cd7ff341b3199cd
(For ppc64le architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.7.13-ppc64le
The image digest is
sha256:d47ce972f87f14f1f3c5d50428d2255d1256dae3f45c938ace88547478643e36
All OpenShift Container Platform 4.7 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster
- -between-minor.html#understanding-upgrade-channels_updating-cluster-between
- -minor
3. Solution:
For OpenShift Container Platform 4.7 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-rel
ease-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster
- -cli.html
4. Bugs fixed (https://bugzilla.redhat.com/):
1921650 - CVE-2021-3121 gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation
1923268 - [Assisted-4.7] [Staging] Using two both spelling "canceled" "cancelled"
1947216 - [AWS] Missing iam:ListAttachedRolePolicies permission in permissions.go
1953963 - Enable/Disable host operations returns cluster resource with incomplete hosts list
1957749 - ovn-kubernetes pod should have CPU and memory requests set but not limits
1959238 - CVO creating cloud-controller-manager too early causing upgrade failures
1960103 - SR-IOV obliviously reboot the node
1961941 - Local Storage Operator using LocalVolume CR fails to create PV's when backend storage failure is simulated
1962302 - packageserver clusteroperator does not set reason or message for Available condition
1962312 - Deployment considered unhealthy despite being available and at latest generation
1962435 - Public DNS records were not deleted when destroying a cluster which is using byo private hosted zone
1963115 - Test verify /run filesystem contents failing
5. JIRA issues fixed (https://issues.jboss.org/):
LOG-1328 - Port fix to 5.0.z for BZ-1945168
6. Description:
Security Fix(es):
* Addressed a security issue which can allow a malicious playbook author to
elevate to the awx user from outside the isolated environment:
CVE-2021-20253
* Upgraded to a more recent version of autobahn to address CVE-2020-35678.
* Upgraded to a more recent version of nginx to address CVE-2019-20372.
Bug Fix(es):
* Fixed a bug which can intermittently cause access to encrypted Tower
settings to fail, resulting in failed job launches.
* Improved analytics collection to collect the playbook status for all
hosts in a playbook run
3. Solution:
For information on upgrading Ansible Tower, reference the Ansible Tower
Upgrade and Migration Guide:
https://docs.ansible.com/ansible-tower/latest/html/upgrade-migration-guide/
index.html
4. Bugs fixed (https://bugzilla.redhat.com/):
1790277 - CVE-2019-20372 nginx: HTTP request smuggling in configurations with URL redirect used as error_page
1911314 - CVE-2020-35678 python-autobahn: allows redirect header injection
1928847 - CVE-2021-20253 ansible-tower: Privilege escalation via job isolation escape
5. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Moderate: perl security update
Advisory ID: RHSA-2021:1266-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:1266
Issue date: 2021-04-20
CVE Names: CVE-2020-10543 CVE-2020-10878 CVE-2020-12723
=====================================================================
1. Summary:
An update for perl is now available for Red Hat Enterprise Linux 7.4
Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update
Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP
Solutions.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Server AUS (v. 7.4) - noarch, x86_64
Red Hat Enterprise Linux Server E4S (v. 7.4) - noarch, ppc64le, x86_64
Red Hat Enterprise Linux Server Optional AUS (v. 7.4) - x86_64
Red Hat Enterprise Linux Server Optional E4S (v. 7.4) - ppc64le, x86_64
Red Hat Enterprise Linux Server Optional TUS (v. 7.4) - x86_64
Red Hat Enterprise Linux Server TUS (v. 7.4) - noarch, x86_64
3. Description:
Perl is a high-level programming language that is commonly used for system
administration utilities and web programming.
Security Fix(es):
* perl: heap-based buffer overflow in regular expression compiler leads to
DoS (CVE-2020-10543)
* perl: corruption of intermediate language state of compiled regular
expression due to integer overflow leads to DoS (CVE-2020-10878)
* perl: corruption of intermediate language state of compiled regular
expression due to recursive S_study_chunk() calls leads to DoS
(CVE-2020-12723)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
1837975 - CVE-2020-10543 perl: heap-based buffer overflow in regular expression compiler leads to DoS
1837988 - CVE-2020-10878 perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS
1838000 - CVE-2020-12723 perl: corruption of intermediate language state of compiled regular expression due to recursive S_study_chunk() calls leads to DoS
1938673 - perl-5.26.3-416.el8 FTBFS: ../cpan/Time-Local/t/Local.t test fails in year 2020 [rhel-7.4.z]
6. Package List:
Red Hat Enterprise Linux Server AUS (v. 7.4):
Source:
perl-5.16.3-292.el7_4.2.src.rpm
noarch:
perl-CPAN-1.9800-292.el7_4.2.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-292.el7_4.2.noarch.rpm
perl-ExtUtils-Embed-1.30-292.el7_4.2.noarch.rpm
perl-ExtUtils-Install-1.58-292.el7_4.2.noarch.rpm
perl-IO-Zlib-1.10-292.el7_4.2.noarch.rpm
perl-Locale-Maketext-Simple-0.21-292.el7_4.2.noarch.rpm
perl-Module-CoreList-2.76.02-292.el7_4.2.noarch.rpm
perl-Module-Loaded-0.08-292.el7_4.2.noarch.rpm
perl-Object-Accessor-0.42-292.el7_4.2.noarch.rpm
perl-Package-Constants-0.02-292.el7_4.2.noarch.rpm
perl-Pod-Escapes-1.04-292.el7_4.2.noarch.rpm
x86_64:
perl-5.16.3-292.el7_4.2.x86_64.rpm
perl-Time-Piece-1.20.1-292.el7_4.2.x86_64.rpm
perl-core-5.16.3-292.el7_4.2.x86_64.rpm
perl-debuginfo-5.16.3-292.el7_4.2.i686.rpm
perl-debuginfo-5.16.3-292.el7_4.2.x86_64.rpm
perl-devel-5.16.3-292.el7_4.2.i686.rpm
perl-devel-5.16.3-292.el7_4.2.x86_64.rpm
perl-libs-5.16.3-292.el7_4.2.i686.rpm
perl-libs-5.16.3-292.el7_4.2.x86_64.rpm
perl-macros-5.16.3-292.el7_4.2.x86_64.rpm
Red Hat Enterprise Linux Server E4S (v. 7.4):
Source:
perl-5.16.3-292.el7_4.2.src.rpm
noarch:
perl-CPAN-1.9800-292.el7_4.2.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-292.el7_4.2.noarch.rpm
perl-ExtUtils-Embed-1.30-292.el7_4.2.noarch.rpm
perl-ExtUtils-Install-1.58-292.el7_4.2.noarch.rpm
perl-IO-Zlib-1.10-292.el7_4.2.noarch.rpm
perl-Locale-Maketext-Simple-0.21-292.el7_4.2.noarch.rpm
perl-Module-CoreList-2.76.02-292.el7_4.2.noarch.rpm
perl-Module-Loaded-0.08-292.el7_4.2.noarch.rpm
perl-Object-Accessor-0.42-292.el7_4.2.noarch.rpm
perl-Package-Constants-0.02-292.el7_4.2.noarch.rpm
perl-Pod-Escapes-1.04-292.el7_4.2.noarch.rpm
ppc64le:
perl-5.16.3-292.el7_4.2.ppc64le.rpm
perl-Time-Piece-1.20.1-292.el7_4.2.ppc64le.rpm
perl-core-5.16.3-292.el7_4.2.ppc64le.rpm
perl-debuginfo-5.16.3-292.el7_4.2.ppc64le.rpm
perl-devel-5.16.3-292.el7_4.2.ppc64le.rpm
perl-libs-5.16.3-292.el7_4.2.ppc64le.rpm
perl-macros-5.16.3-292.el7_4.2.ppc64le.rpm
x86_64:
perl-5.16.3-292.el7_4.2.x86_64.rpm
perl-Time-Piece-1.20.1-292.el7_4.2.x86_64.rpm
perl-core-5.16.3-292.el7_4.2.x86_64.rpm
perl-debuginfo-5.16.3-292.el7_4.2.i686.rpm
perl-debuginfo-5.16.3-292.el7_4.2.x86_64.rpm
perl-devel-5.16.3-292.el7_4.2.i686.rpm
perl-devel-5.16.3-292.el7_4.2.x86_64.rpm
perl-libs-5.16.3-292.el7_4.2.i686.rpm
perl-libs-5.16.3-292.el7_4.2.x86_64.rpm
perl-macros-5.16.3-292.el7_4.2.x86_64.rpm
Red Hat Enterprise Linux Server TUS (v. 7.4):
Source:
perl-5.16.3-292.el7_4.2.src.rpm
noarch:
perl-CPAN-1.9800-292.el7_4.2.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-292.el7_4.2.noarch.rpm
perl-ExtUtils-Embed-1.30-292.el7_4.2.noarch.rpm
perl-ExtUtils-Install-1.58-292.el7_4.2.noarch.rpm
perl-IO-Zlib-1.10-292.el7_4.2.noarch.rpm
perl-Locale-Maketext-Simple-0.21-292.el7_4.2.noarch.rpm
perl-Module-CoreList-2.76.02-292.el7_4.2.noarch.rpm
perl-Module-Loaded-0.08-292.el7_4.2.noarch.rpm
perl-Object-Accessor-0.42-292.el7_4.2.noarch.rpm
perl-Package-Constants-0.02-292.el7_4.2.noarch.rpm
perl-Pod-Escapes-1.04-292.el7_4.2.noarch.rpm
x86_64:
perl-5.16.3-292.el7_4.2.x86_64.rpm
perl-Time-Piece-1.20.1-292.el7_4.2.x86_64.rpm
perl-core-5.16.3-292.el7_4.2.x86_64.rpm
perl-debuginfo-5.16.3-292.el7_4.2.i686.rpm
perl-debuginfo-5.16.3-292.el7_4.2.x86_64.rpm
perl-devel-5.16.3-292.el7_4.2.i686.rpm
perl-devel-5.16.3-292.el7_4.2.x86_64.rpm
perl-libs-5.16.3-292.el7_4.2.i686.rpm
perl-libs-5.16.3-292.el7_4.2.x86_64.rpm
perl-macros-5.16.3-292.el7_4.2.x86_64.rpm
Red Hat Enterprise Linux Server Optional AUS (v. 7.4):
x86_64:
perl-debuginfo-5.16.3-292.el7_4.2.x86_64.rpm
perl-tests-5.16.3-292.el7_4.2.x86_64.rpm
Red Hat Enterprise Linux Server Optional E4S (v. 7.4):
ppc64le:
perl-debuginfo-5.16.3-292.el7_4.2.ppc64le.rpm
perl-tests-5.16.3-292.el7_4.2.ppc64le.rpm
x86_64:
perl-debuginfo-5.16.3-292.el7_4.2.x86_64.rpm
perl-tests-5.16.3-292.el7_4.2.x86_64.rpm
Red Hat Enterprise Linux Server Optional TUS (v. 7.4):
x86_64:
perl-debuginfo-5.16.3-292.el7_4.2.x86_64.rpm
perl-tests-5.16.3-292.el7_4.2.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2020-10543
https://access.redhat.com/security/cve/CVE-2020-10878
https://access.redhat.com/security/cve/CVE-2020-12723
https://access.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYH7PTtzjgjWX9erEAQg5Rg//XzoyzGoFRn5v3JT/1ZxNTBxZ+2SbVWnf
MVMm5qt1Lkk8s/0DQnvJPKQaHc5yISwGIZChNZe4FxaxSfsn7nvH88d38Xpwht8q
QsmKGPEyYmb9qvMbCpjFV6+T1ggaMvfikeFTCe49Kx3H/dDMKPXYvZqL9VtjbKKc
Bf0G2fJkhCaEFeFksHZShu2tofoVaHeN/RkwoQrK2HWqb8emlEY5aTtdx3znzSwV
Vg3l3sGJ4eDKLz8sWvUJtkkljM/uTM0klbbseyl6duBdFzzSegnn6dMcWLsntADr
PgmyL5WMI7lLfJoBwK0m7D45HfCaVMVMp9dQdr5RE+IO+DXUQf9plEhKCIuPBiii
aMugog1BamqQUHSYBwyhUOGjyT51SJHg+uVbvYzrQRM8v9YFDgYyliCiqJQmlik7
kq6Jmytn3AkrGQWCJy5TALvNnM59TDTM9IiBNHZ2iA3g59U2a6KZvYFgyT6JZ7rJ
FEdgxtMdCLGXIS/aAeq9kiU+Jg4a3RN8gPhGiE39WACtvQ8QWs3GrYDVxlSF6eXg
rzXOA6UYyTICfhT4JKb54bkH1MzR7hRaMX0UqnAF4gsPgduEmMdwSpB+5e1q/XIr
tRH/FrGPdB/aTo19Pk6u3SQxgpYXQf+SpFiSpxvwsVaSNKGgm3eh3soNuXCCKfpf
qTMMs3KSLLM=
=1/yn
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
| VAR-202006-1838 | CVE-2020-10543 | Perl Out-of-bounds write vulnerability in |
CVSS V2: 6.4 CVSS V3: 8.2 Severity: HIGH |
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. Perl Is vulnerable to out-of-bounds writes.Information is tampered with and service operation is interrupted (DoS) It may be put into a state. An attacker could exploit this vulnerability to cause a denial of service. 7.7) - ppc64, ppc64le, s390x, x86_64
3. Summary:
Red Hat Advanced Cluster Management for Kubernetes 2.0.8 General
Availability release, which fixes bugs and security issues.
Red Hat Advanced Cluster Management for Kubernetes provides the
capabilities to address common challenges that administrators and site
reliability engineers face as they work across a range of public and
private cloud environments. Clusters and applications are all visible and
managed from a single console—with security policy built in.
Bug fix:
* RHACM 2.0.8 images (BZ #1915461)
3. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied. Bugs fixed (https://bugzilla.redhat.com/):
1915461 - RHACM 2.0.8 images
1921650 - CVE-2021-3121 gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation
5. 8.2) - aarch64, noarch, ppc64le, s390x, x86_64
3.
Bug Fix(es):
* [perl-net-ping] wrong return value on failing DNS name lookup
(BZ#1973177)
4. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202006-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: Perl: Multiple vulnerabilities
Date: June 12, 2020
Bugs: #723792
ID: 202006-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been found in Perl, the worst of which
could result in a Denial of Service condition.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-lang/perl < 5.30.3 >= 5.30.3
Description
===========
Multiple vulnerabilities have been discovered in Perl. Please review
the CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All Perl users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/perl-5.30.3"
References
==========
[ 1 ] CVE-2020-10543
https://nvd.nist.gov/vuln/detail/CVE-2020-10543
[ 2 ] CVE-2020-10878
https://nvd.nist.gov/vuln/detail/CVE-2020-10878
[ 3 ] CVE-2020-12723
https://nvd.nist.gov/vuln/detail/CVE-2020-12723
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202006-03
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2020 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
. Description:
Security Fix(es):
* Addressed a security issue which can allow a malicious playbook author to
elevate to the awx user from outside the isolated environment:
CVE-2021-20253
* Upgraded to a more recent version of autobahn to address CVE-2020-35678.
* Upgraded to a more recent version of nginx to address CVE-2019-20372.
Bug Fix(es):
* Fixed a bug which can intermittently cause access to encrypted Tower
settings to fail, resulting in failed job launches.
* Improved analytics collection to collect the playbook status for all
hosts in a playbook run
3. Solution:
For information on upgrading Ansible Tower, reference the Ansible Tower
Upgrade and Migration Guide:
https://docs.ansible.com/ansible-tower/latest/html/upgrade-migration-guide/
index.html
4. Bugs fixed (https://bugzilla.redhat.com/):
1790277 - CVE-2019-20372 nginx: HTTP request smuggling in configurations with URL redirect used as error_page
1911314 - CVE-2020-35678 python-autobahn: allows redirect header injection
1928847 - CVE-2021-20253 ansible-tower: Privilege escalation via job isolation escape
5. 7.4) - noarch, x86_64
3. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: perl security update
Advisory ID: RHSA-2021:0343-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:0343
Issue date: 2021-02-02
CVE Names: CVE-2020-10543 CVE-2020-10878 CVE-2020-12723
====================================================================
1. Summary:
An update for perl is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3. Description:
Perl is a high-level programming language that is commonly used for system
administration utilities and web programming.
Security Fix(es):
* perl: heap-based buffer overflow in regular expression compiler leads to
DoS (CVE-2020-10543)
* perl: corruption of intermediate language state of compiled regular
expression due to integer overflow leads to DoS (CVE-2020-10878)
* perl: corruption of intermediate language state of compiled regular
expression due to recursive S_study_chunk() calls leads to DoS
(CVE-2020-12723)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Package List:
Red Hat Enterprise Linux Client (v. 7):
Source:
perl-5.16.3-299.el7_9.src.rpm
noarch:
perl-CPAN-1.9800-299.el7_9.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-299.el7_9.noarch.rpm
perl-ExtUtils-Embed-1.30-299.el7_9.noarch.rpm
perl-ExtUtils-Install-1.58-299.el7_9.noarch.rpm
perl-IO-Zlib-1.10-299.el7_9.noarch.rpm
perl-Locale-Maketext-Simple-0.21-299.el7_9.noarch.rpm
perl-Module-CoreList-2.76.02-299.el7_9.noarch.rpm
perl-Module-Loaded-0.08-299.el7_9.noarch.rpm
perl-Object-Accessor-0.42-299.el7_9.noarch.rpm
perl-Package-Constants-0.02-299.el7_9.noarch.rpm
perl-Pod-Escapes-1.04-299.el7_9.noarch.rpm
x86_64:
perl-5.16.3-299.el7_9.x86_64.rpm
perl-Time-Piece-1.20.1-299.el7_9.x86_64.rpm
perl-core-5.16.3-299.el7_9.x86_64.rpm
perl-debuginfo-5.16.3-299.el7_9.i686.rpm
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-devel-5.16.3-299.el7_9.i686.rpm
perl-devel-5.16.3-299.el7_9.x86_64.rpm
perl-libs-5.16.3-299.el7_9.i686.rpm
perl-libs-5.16.3-299.el7_9.x86_64.rpm
perl-macros-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-tests-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
perl-5.16.3-299.el7_9.src.rpm
noarch:
perl-CPAN-1.9800-299.el7_9.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-299.el7_9.noarch.rpm
perl-ExtUtils-Embed-1.30-299.el7_9.noarch.rpm
perl-ExtUtils-Install-1.58-299.el7_9.noarch.rpm
perl-IO-Zlib-1.10-299.el7_9.noarch.rpm
perl-Locale-Maketext-Simple-0.21-299.el7_9.noarch.rpm
perl-Module-CoreList-2.76.02-299.el7_9.noarch.rpm
perl-Module-Loaded-0.08-299.el7_9.noarch.rpm
perl-Object-Accessor-0.42-299.el7_9.noarch.rpm
perl-Package-Constants-0.02-299.el7_9.noarch.rpm
perl-Pod-Escapes-1.04-299.el7_9.noarch.rpm
x86_64:
perl-5.16.3-299.el7_9.x86_64.rpm
perl-Time-Piece-1.20.1-299.el7_9.x86_64.rpm
perl-core-5.16.3-299.el7_9.x86_64.rpm
perl-debuginfo-5.16.3-299.el7_9.i686.rpm
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-devel-5.16.3-299.el7_9.i686.rpm
perl-devel-5.16.3-299.el7_9.x86_64.rpm
perl-libs-5.16.3-299.el7_9.i686.rpm
perl-libs-5.16.3-299.el7_9.x86_64.rpm
perl-macros-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-tests-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
perl-5.16.3-299.el7_9.src.rpm
noarch:
perl-CPAN-1.9800-299.el7_9.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-299.el7_9.noarch.rpm
perl-ExtUtils-Embed-1.30-299.el7_9.noarch.rpm
perl-ExtUtils-Install-1.58-299.el7_9.noarch.rpm
perl-IO-Zlib-1.10-299.el7_9.noarch.rpm
perl-Locale-Maketext-Simple-0.21-299.el7_9.noarch.rpm
perl-Module-CoreList-2.76.02-299.el7_9.noarch.rpm
perl-Module-Loaded-0.08-299.el7_9.noarch.rpm
perl-Object-Accessor-0.42-299.el7_9.noarch.rpm
perl-Package-Constants-0.02-299.el7_9.noarch.rpm
perl-Pod-Escapes-1.04-299.el7_9.noarch.rpm
ppc64:
perl-5.16.3-299.el7_9.ppc64.rpm
perl-Time-Piece-1.20.1-299.el7_9.ppc64.rpm
perl-core-5.16.3-299.el7_9.ppc64.rpm
perl-debuginfo-5.16.3-299.el7_9.ppc.rpm
perl-debuginfo-5.16.3-299.el7_9.ppc64.rpm
perl-devel-5.16.3-299.el7_9.ppc.rpm
perl-devel-5.16.3-299.el7_9.ppc64.rpm
perl-libs-5.16.3-299.el7_9.ppc.rpm
perl-libs-5.16.3-299.el7_9.ppc64.rpm
perl-macros-5.16.3-299.el7_9.ppc64.rpm
ppc64le:
perl-5.16.3-299.el7_9.ppc64le.rpm
perl-Time-Piece-1.20.1-299.el7_9.ppc64le.rpm
perl-core-5.16.3-299.el7_9.ppc64le.rpm
perl-debuginfo-5.16.3-299.el7_9.ppc64le.rpm
perl-devel-5.16.3-299.el7_9.ppc64le.rpm
perl-libs-5.16.3-299.el7_9.ppc64le.rpm
perl-macros-5.16.3-299.el7_9.ppc64le.rpm
s390x:
perl-5.16.3-299.el7_9.s390x.rpm
perl-Time-Piece-1.20.1-299.el7_9.s390x.rpm
perl-core-5.16.3-299.el7_9.s390x.rpm
perl-debuginfo-5.16.3-299.el7_9.s390.rpm
perl-debuginfo-5.16.3-299.el7_9.s390x.rpm
perl-devel-5.16.3-299.el7_9.s390.rpm
perl-devel-5.16.3-299.el7_9.s390x.rpm
perl-libs-5.16.3-299.el7_9.s390.rpm
perl-libs-5.16.3-299.el7_9.s390x.rpm
perl-macros-5.16.3-299.el7_9.s390x.rpm
x86_64:
perl-5.16.3-299.el7_9.x86_64.rpm
perl-Time-Piece-1.20.1-299.el7_9.x86_64.rpm
perl-core-5.16.3-299.el7_9.x86_64.rpm
perl-debuginfo-5.16.3-299.el7_9.i686.rpm
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-devel-5.16.3-299.el7_9.i686.rpm
perl-devel-5.16.3-299.el7_9.x86_64.rpm
perl-libs-5.16.3-299.el7_9.i686.rpm
perl-libs-5.16.3-299.el7_9.x86_64.rpm
perl-macros-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
perl-debuginfo-5.16.3-299.el7_9.ppc64.rpm
perl-tests-5.16.3-299.el7_9.ppc64.rpm
ppc64le:
perl-debuginfo-5.16.3-299.el7_9.ppc64le.rpm
perl-tests-5.16.3-299.el7_9.ppc64le.rpm
s390x:
perl-debuginfo-5.16.3-299.el7_9.s390x.rpm
perl-tests-5.16.3-299.el7_9.s390x.rpm
x86_64:
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-tests-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
perl-5.16.3-299.el7_9.src.rpm
noarch:
perl-CPAN-1.9800-299.el7_9.noarch.rpm
perl-ExtUtils-CBuilder-0.28.2.6-299.el7_9.noarch.rpm
perl-ExtUtils-Embed-1.30-299.el7_9.noarch.rpm
perl-ExtUtils-Install-1.58-299.el7_9.noarch.rpm
perl-IO-Zlib-1.10-299.el7_9.noarch.rpm
perl-Locale-Maketext-Simple-0.21-299.el7_9.noarch.rpm
perl-Module-CoreList-2.76.02-299.el7_9.noarch.rpm
perl-Module-Loaded-0.08-299.el7_9.noarch.rpm
perl-Object-Accessor-0.42-299.el7_9.noarch.rpm
perl-Package-Constants-0.02-299.el7_9.noarch.rpm
perl-Pod-Escapes-1.04-299.el7_9.noarch.rpm
x86_64:
perl-5.16.3-299.el7_9.x86_64.rpm
perl-Time-Piece-1.20.1-299.el7_9.x86_64.rpm
perl-core-5.16.3-299.el7_9.x86_64.rpm
perl-debuginfo-5.16.3-299.el7_9.i686.rpm
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-devel-5.16.3-299.el7_9.i686.rpm
perl-devel-5.16.3-299.el7_9.x86_64.rpm
perl-libs-5.16.3-299.el7_9.i686.rpm
perl-libs-5.16.3-299.el7_9.x86_64.rpm
perl-macros-5.16.3-299.el7_9.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
perl-debuginfo-5.16.3-299.el7_9.x86_64.rpm
perl-tests-5.16.3-299.el7_9.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2020-10543
https://access.redhat.com/security/cve/CVE-2020-10878
https://access.redhat.com/security/cve/CVE-2020-12723
https://access.redhat.com/security/updates/classification/#moderate
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYBlBRdzjgjWX9erEAQgfWQ/+Pzq//upZZVPBq5+myRLRJCef7277Y+9k
54oh8wOTwtwEMs9ye5Y1FDmAxVd4fWX3JgAss1KE86Hhm5OoCX/FJ0/RGguMR1l2
qwmWtfGuZjrn1SmjdHlf8B/bC0f20IadUUbY/8clpFiMxe5V1g8s9ZgbHv/MBWnm
Awac/6LPc7Eb24OnIuTKLYEcQRxuBG1KdikM1NN1uJU5WHkbhZfKWFMnjKihsPGp
42vnomd0P7RdXNc4FbuNlkm2iw04woJyz1AYPdScswWJqawQSbre6+3wpnHlWs4K
RerhKZiJLJsC0XmSpma62I4kYbVlniYPcbrF4Zfo1j1vIIvjmOL26B/3JsUVtwfm
AKVuAu8DbNIkdSo2CS2gauLWsykukprPx16X8n8Xlb9Kr9iL/r2/sI/jUGce+50S
aoe2Hb40VIX6sHPLiEmWP0ufuoDxJZ2mY9mhqAMGt/xCPrZ/Pst0y4hewJVo2AIf
/LG758/KJWYBx2ILfBwA07O829irVDnbw5blT47fS3qiqAzXRTp56xkCCnLQ0BGQ
Ip3DFIwNVxznKYOgubXJBGl3xYHI+P/bu8tcCAYMaN4hAHdFrqJbPMNLLGf37L73
N83csDc07k/WsKua5atl3suUuYRWxSq6CnV9KNU4aUaKEmu+de+D2k34vn2+le0S
HB63T1smQXA=Oj1P
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
| VAR-202006-0750 | CVE-2019-16150 | Windows for FortiClient Vulnerability in using hard-coded credentials in |
CVSS V2: 5.0 CVSS V3: 5.5 Severity: MEDIUM |
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via knowledge of the hard-coded key. Windows for FortiClient Contains a vulnerability in the use of hard-coded credentials.Information may be obtained. Fortinet FortiClient is a mobile terminal security solution developed by Fortinet. The solution provides IPsec and SSL encryption, WAN optimization, endpoint compliance, and two-factor authentication when connected to FortiGate firewall appliances. There is a security vulnerability in Fortinet FortiClient versions earlier than 6.4.0 based on the Windows platform. An attacker could exploit this vulnerability to decrypt sensitive information