<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/osv_almalinux/10</id>
  <title>Most recent entries from osv_almalinux</title>
  <updated>2026-10-02T11:57:06.425622+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:0975</id>
    <title>ALSA-2019:0975 — Important: container-tools:rhel8 security and bug fix update</title>
    <updated>2019-05-07T03:39:02+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: oci-systemd-hook, AlmaLinux:8: oci-umount</p>
<p>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.</p>
<p>Security Fix(es):</p>
<p>* A flaw was found in the way runc handled system file descriptors when running containers. A malicious container could use this flaw to overwrite contents of the runc binary and consequently run arbitrary commands on the container host system. (CVE-2019-5736)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* [stream rhel8] rebase container-selinux to 2.94 (BZ#1693675)</p>
<p>* [stream rhel8] unable to mount disk at `/var/lib/containers` via `systemd` unit when `container-selinux` policy installed (BZ#1695669)</p>
<p>* [stream rhel8] don't allow a container to connect to random services (BZ#1695689)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:0975"/>
    <published>2019-05-07T03:39:11+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:0981</id>
    <title>ALSA-2019:0981 — Important: python27:2.7 security update</title>
    <updated>2019-05-07T03:39:54+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-chardet, AlmaLinux:8: python2-coverage, AlmaLinux:8: python2-docutils, AlmaLinux:8: python2-funcsigs, AlmaLinux:8: python2-idna, AlmaLinux:8: python2-ipaddress and 14 more</p>
<p>Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing.</p>
<p>SQLAlchemy is an Object Relational Mapper (ORM) that provides a flexible, high-level interface to SQL databases.</p>
<p>Security Fix(es):</p>
<p>* python: Information Disclosure due to urlsplit improper NFKC normalization (CVE-2019-9636)</p>
<p>* python-sqlalchemy: SQL Injection when the order_by parameter can be controlled (CVE-2019-7164)</p>
<p>* python-sqlalchemy: SQL Injection when the group_by parameter can be controlled (CVE-2019-7548)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:0981"/>
    <published>2019-05-07T03:40:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:0984</id>
    <title>ALSA-2019:0984 — Moderate: python36:3.6 security update</title>
    <updated>2019-05-07T03:40:21+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python3-docs, AlmaLinux:8: python3-docutils</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>SQLAlchemy is an Object Relational Mapper (ORM) that provides a flexible, high-level interface to SQL databases.</p>
<p>Security Fix(es):</p>
<p>* python-sqlalchemy: SQL Injection when the order_by parameter can be controlled (CVE-2019-7164)</p>
<p>* python-sqlalchemy: SQL Injection when the group_by parameter can be controlled (CVE-2019-7548)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:0984"/>
    <published>2019-05-07T03:40:33+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:1529</id>
    <title>ALSA-2019:1529 — Important: pki-deps:10.6 security update</title>
    <updated>2019-06-18T16:36:09+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-module-jaxb-annotations, AlmaLinux:8: jakarta-commons-httpclient and 15 more</p>
<p>The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.</p>
<p>Security Fix(es):</p>
<p>* tomcat: Due to a mishandling of close in NIO/NIO2 connectors user sessions can get mixed up (CVE-2018-8037)</p>
<p>* tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins (CVE-2018-8014)</p>
<p>* tomcat: Open redirect in default servlet (CVE-2018-11784)</p>
<p>* tomcat: Host name verification missing in WebSocket client (CVE-2018-8034)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:1529"/>
    <published>2019-06-18T16:36:21+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:1972</id>
    <title>ALSA-2019:1972 — Important: ruby:2.5 security update</title>
    <updated>2019-07-30T15:56:05+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bson, AlmaLinux:8: rubygem-bson-doc, AlmaLinux:8: rubygem-mongo, AlmaLinux:8: rubygem-mongo-doc, AlmaLinux:8: rubygem-mysql2, AlmaLinux:8: rubygem-mysql2-doc, AlmaLinux:8: rubygem-pg, AlmaLinux:8: rubygem-pg-doc</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:1972"/>
    <published>2019-07-30T11:16:25+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:2511</id>
    <title>ALSA-2019:2511 — Important: mysql:8.0 security update</title>
    <updated>2019-08-15T17:31:05+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: mecab, AlmaLinux:8: mecab-ipadic, AlmaLinux:8: mecab-ipadic-EUCJP</p>
<p>MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon, mysqld, and many client programs.</p>
<p>The following packages have been upgraded to a later upstream version: mysql (8.0.17).</p>
<p>Security Fix(es):</p>
<p>* mysql: Server: Replication multiple unspecified vulnerabilities (CVE-2019-2800, CVE-2019-2436, CVE-2019-2531, CVE-2019-2534, CVE-2019-2614, CVE-2019-2617, CVE-2019-2630, CVE-2019-2634, CVE-2019-2635, CVE-2019-2755)</p>
<p>* mysql: Server: Optimizer multiple unspecified vulnerabilities (CVE-2019-2420, CVE-2019-2481, CVE-2019-2507, CVE-2019-2529, CVE-2019-2530, CVE-2019-2581, CVE-2019-2596, CVE-2019-2607, CVE-2019-2625, CVE-2019-2681, CVE-2019-2685, CVE-2019-2686, CVE-2019-2687, CVE-2019-2688, CVE-2019-2689, CVE-2019-2693, CVE-2019-2694, CVE-2019-2695, CVE-2019-2757, CVE-2019-2774, CVE-2019-2796, CVE-2019-2802, CVE-2019-2803, CVE-2019-2808, CVE-2019-2810, CVE-2019-2812, CVE-2019-2815, CVE-2019-2830, CVE-2019-2834)</p>
<p>* mysql: Server: Parser multiple unspecified vulnerabilities (CVE-2019-2434, CVE-2019-2455, CVE-2019-2805)</p>
<p>* mysql: Server: PS multiple unspecified vulnerabilities (CVE-2019-2482, CVE-2019-2592)</p>
<p>* mysql: Server: Security: Privileges multiple unspecified vulnerabilities (CVE-2019-2486, CVE-2019-2532, CVE-2019-2533, CVE-2019-2584, CVE-2019-2589, CVE-2019-2606, CVE-2019-2620, CVE-2019-2627, CVE-2019-2739, CVE-2019-2778, CVE-2019-2811, CVE-2019-2789)</p>
<p>* mysql: Server: DDL multiple unspecified vulnerabilities (CVE-2019-2494, CVE-2019-24…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:2511"/>
    <published>2019-08-15T17:31:05+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:2512</id>
    <title>ALSA-2019:2512 — Important: subversion:1.10 security update</title>
    <updated>2019-08-15T17:34:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libserf, AlmaLinux:8: utf8proc</p>
<p>Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes.</p>
<p>Security Fix(es):</p>
<p>* subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS (CVE-2019-0203)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:2512"/>
    <published>2019-08-15T17:34:10+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:2593</id>
    <title>ALSA-2019:2593 — Important: squid:4 security update</title>
    <updated>2019-09-02T10:22:04+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libecap, AlmaLinux:8: libecap-devel</p>
<p>Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.</p>
<p>Security Fix(es):</p>
<p>* squid: heap-based buffer overflow in HttpHeader::getAuth (CVE-2019-12527)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:2593"/>
    <published>2019-09-02T10:22:04+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:2720</id>
    <title>ALSA-2019:2720 — Important: pki-deps:10.6 security update</title>
    <updated>2019-09-10T15:32:43+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: apache-commons-collections, AlmaLinux:8: apache-commons-lang, AlmaLinux:8: bea-stax-api, AlmaLinux:8: glassfish-fastinfoset, AlmaLinux:8: glassfish-jaxb-api, AlmaLinux:8: glassfish-jaxb-core, AlmaLinux:8: glassfish-jaxb-runtime, AlmaLinux:8: glassfish-jaxb-txw2, AlmaLinux:8: jackson-jaxrs-json-provider, AlmaLinux:8: jackson-jaxrs-providers and 17 more</p>
<p>The Public Key Infrastructure (PKI) Deps module contains fundamental packages required as dependencies for the pki-core module by AlmaLinux Certificate System.</p>
<p>Security Fix(es):</p>
<p>* jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution (CVE-2019-12384)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:2720"/>
    <published>2019-09-10T15:32:49+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:2722</id>
    <title>ALSA-2019:2722 — Low: libwmf security update</title>
    <updated>2021-11-12T10:20:55+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: libwmf, AlmaLinux:8: libwmf-devel, AlmaLinux:8: libwmf-lite</p>
<p>The libwmf packages provide a library for reading and converting Windows Metafile Format (WMF) vector graphics. The library is used by applications such as GIMP and ImageMagick.</p>
<p>Security Fix(es):</p>
<p>* gd: double free in the gdImage*Ptr in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c (CVE-2019-6978)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:2722"/>
    <published>2019-09-10T15:32:59+00:00</published>
  </entry>
</feed>
